Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

The Texas Parks and Wildlife Department (TPWD) has reported a significant data breach involving its license system vendor. This incident has compromised the personal information of over three million individuals, including details related to driver’s licenses. The breach raises concerns about identity theft and privacy for those affected, as their sensitive information may be exposed to malicious actors. The TPWD's announcement emphasizes the need for vigilance among residents, encouraging them to monitor their accounts for any signs of fraud. This incident highlights the ongoing risks associated with third-party vendors managing sensitive data, underscoring the importance of robust security measures in protecting personal information.

Read Original
Critical
eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

eFAQ has released an investigation into alleged scam activities linked to coordinated reputation attacks targeting various individuals and organizations. The report outlines how these scams operate, often involving misinformation and fraudulent communications designed to damage reputations and mislead potential victims. Those affected include both individuals and businesses that have been wrongly accused or misrepresented in online platforms, leading to significant reputational harm. This incident highlights the growing concern around online scams and the need for vigilance among users and companies alike. Understanding these tactics is crucial for protecting personal and organizational integrity in the digital landscape.

Read Original

The article discusses the growing challenge organizations face with AI agents, which are increasingly being treated as identities within business systems. These AI agents can perform various tasks, such as accessing sensitive data, triggering workflows, and deploying code, often without sufficient oversight. This raises concerns about governance and security, as organizations may not have adequate measures in place to manage these AI entities. The piece emphasizes the need for companies to reevaluate their identity and access management strategies to address the unique risks posed by AI agents. As these technologies continue to evolve, ensuring proper governance is crucial to protect critical business systems from potential misuse or attacks.

Read Original

As cybersecurity threats increase and the use of AI becomes more prevalent, Chief Information Security Officers (CISOs) are reporting that their roles are becoming increasingly challenging. Despite these difficulties, many companies are still seeking cybersecurity expertise, often on a part-time basis. This trend highlights the ongoing demand for skilled professionals in the field, even as the landscape becomes more complex. The reliance on AI tools in cybersecurity is both a double-edged sword, offering advanced capabilities while also introducing new vulnerabilities. This situation emphasizes the need for companies to adapt their security teams to effectively manage these evolving challenges.

Read Original

Microsoft has acknowledged a bug in the June 2026 Windows updates that disrupts the Recycle Bin's file deletion confirmation dialog. Users are reporting that incorrect filenames appear when they attempt to delete files, which can lead to confusion and potential mistakes while managing their data. This issue affects various versions of Windows, although specific versions have not been detailed. The bug is particularly concerning because it may hinder user confidence in the file deletion process, leading to accidental data loss. Microsoft has not yet provided a timeline for a fix, leaving users in a state of uncertainty regarding how to manage their files safely.

Read Original
Actively Exploited

CryptoBandits is a new type of malware that combines data theft with remote code execution capabilities. It uses a local SOCKS5 proxy to route its traffic, which allows it to operate discreetly while abusing the Tor network for anonymity. This dual functionality poses significant risks, as it can both steal sensitive information and provide attackers with a backdoor into compromised systems. Users and organizations should be vigilant, as this malware can impact various systems and potentially lead to severe data breaches. The ongoing threat of CryptoBandits highlights the need for enhanced security measures in environments where sensitive data is handled.

Read Original

On June 9th, Anthropic launched its new generative AI model named Fable. Just three days later, the U.S. government declared it a dangerous munition, using export-control laws to block foreign nationals from accessing it. As the company could not distinguish between American and foreign users, they decided to cut off access for everyone. This decision reflects a growing concern about the rapid advancement of AI capabilities and the potential risks associated with them. Experts argue that addressing these risks requires a coordinated approach, which seems unlikely given the current political climate. This situation raises important questions about the regulation of AI technology and its implications for innovation and international collaboration.

Read Original

Google has rolled out a new feature for its reCAPTCHA system that requires users to perform hand gestures as a way to verify they are human. This method is part of Google Cloud's efforts to combat automated bot activity and fraudulent behavior across various platforms, including login pages and checkout systems. By integrating hand gestures, Google aims to enhance the reliability of user verification processes, making it more difficult for bots to bypass security measures. This change could affect any organization that uses reCAPTCHA to protect its online services, as they may need to adapt to this new verification method. As online fraud continues to be a pressing issue, innovations like this are crucial for maintaining secure online environments.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a serious vulnerability in Splunk Enterprise that is currently being exploited by attackers. This flaw poses a significant risk to U.S. federal agencies and could potentially affect many organizations using this software. CISA has urged these agencies to take immediate action to secure their systems by applying the necessary patches by this Sunday. Failure to address this vulnerability could result in unauthorized access to sensitive data or system controls, making it crucial for organizations to prioritize this update. The urgency of the situation highlights the ongoing challenges in cybersecurity and the need for vigilance in maintaining software security.

Read Original

A recent operation known as Operation Endgame has successfully removed SocGholish malware from around 15,000 websites linked to the notorious Evil Corp hacking group. This malware is often used to deliver ransomware and has been a significant threat to users who visit compromised sites. The operation aims to disrupt the infrastructure that Evil Corp relies on to spread their malicious software, which is a positive step in combating cybercrime. By targeting these infected sites, authorities hope to reduce the risk of malware infections and protect users from potential data loss or financial harm. This incident highlights ongoing efforts to dismantle the operations of major ransomware gangs and improve online security for everyone.

Read Original
Critical
FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Cybersecurity experts are warning fans of the upcoming FIFA World Cup 2026 about a surge in scams targeting them. Hackers are creating fake websites that offer tickets and hotel bookings, often mimicking legitimate services. These sites may feature live chat options to further deceive users into believing they're engaging with a trusted source. As the tournament approaches, it's crucial for fans to be vigilant and verify the authenticity of any ticket or accommodation offers to avoid falling victim to these scams. This situation not only affects individuals but could tarnish the overall experience of attending the event.

Read Original

A man from New York has been charged with cyberstalking after he allegedly harassed a college student in Georgia by sharing AI-generated nude images and creating fake social media profiles to send fabricated racist messages. The harassment reportedly began when the man used these profiles to intimidate the student, causing significant distress. This case raises serious concerns about the misuse of AI technology for harassment and the challenges it presents in identifying and prosecuting offenders. The incident also highlights the need for stronger protections against online harassment, particularly for vulnerable individuals such as students. As technology continues to evolve, the implications for privacy and safety in digital spaces become increasingly critical.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to users of Fortinet devices after a significant data leak exposed around 74,000 firewall and VPN credentials, an incident referred to as 'FortiBleed.' This breach puts numerous organizations at risk as attackers could potentially exploit these exposed credentials to gain unauthorized access to sensitive networks. Fortinet customers are urged to take immediate action to secure their devices and change their passwords. The leak serves as a stark reminder of the importance of maintaining strong security practices, especially for critical infrastructure. Organizations using Fortinet products should prioritize this issue to prevent potential breaches.

Read Original

In a significant law enforcement operation dubbed Operation Endgame, authorities took down 106 command and control (C&C) servers and domains associated with the SocGholish botnet. This action has led to the cleanup of around 15,000 WordPress websites that were compromised by this malware. The SocGholish botnet is known for distributing malicious software through fake updates and compromised sites, which can lead to serious security risks for both website owners and their visitors. This takedown not only disrupts the botnet's operations but also helps protect countless users from falling victim to its deceptive tactics. The operation underscores the ongoing battle against cybercrime and the importance of proactive measures to secure online platforms.

Read Original
Actively Exploited

Researchers have discovered a massive data leak involving 24 billion stolen credentials, which were found in an unsecured Elasticsearch database. The leaked data, amounting to over 8.3 terabytes, includes sensitive information such as passwords and email addresses, potentially exposing countless users to account takeovers. This incident, identified on June 12th, raises serious concerns for individuals and organizations alike, as attackers can easily exploit this information for malicious purposes. The scale of the leak underscores the ongoing risks posed by infostealers and various online breach collections. Users are encouraged to change their passwords and enable two-factor authentication to protect their accounts from potential breaches.

Read Original
PreviousPage 145 of 370Next