Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A recently disclosed vulnerability in Splunk Enterprise, identified as CVE-2026-20253, has been exploited by attackers just days after it was made public. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged federal agencies to apply patches within three days to prevent potential unauthorized remote code execution. This vulnerability poses a serious risk, allowing attackers to execute malicious code without authentication, which could lead to significant data breaches or system compromises. Organizations using affected versions of Splunk Enterprise need to act quickly to secure their systems and protect sensitive information from exploitation.

Read Original

A new malware campaign is manipulating VirusTotal, a widely used malware scanning service, to enhance the reputation of malicious software. This campaign primarily involves a clipboard hijacker, which can steal sensitive information from users' clipboards. To boost its visibility, the attackers are also using 'ghost networks' on social media, which artificially inflate engagement and spread awareness of their malicious tools. This approach not only makes the malware seem more legitimate but also complicates detection efforts. As a result, users who visit compromised sites or engage with these ghost networks may unknowingly expose their data to theft.

Read Original

A new type of cyber attack known as Agentjacking is taking advantage of artificial intelligence coding tools by using fake error reports. This method allows attackers to infiltrate systems without needing stolen credentials or direct access to networks. Instead, they exploit the coding tools that developers rely on, which could lead to unauthorized access and manipulation of sensitive data. This is particularly concerning for companies that use AI tools for software development, as it raises questions about the security of their coding environments. As this attack method evolves, organizations need to be vigilant and ensure their development tools are secure against such manipulations.

Read Original
Actively Exploited

Authorities have successfully dismantled the SocGholish botnet operated by the cybercrime group Evil Corp. This operation involved the shutdown of 106 servers and the remediation of nearly 15,000 infected websites. SocGholish is known for distributing malware that targets users by masquerading as legitimate software updates, often leading to credential theft or system compromise. The action taken by cybersecurity firms and law enforcement is significant as it disrupts a major source of cyber threats that affect both businesses and individual users online. The widespread impact of this botnet highlights the ongoing risks posed by such malware campaigns and the importance of proactive cybersecurity measures.

Read Original

Apple has released a security update to address a vulnerability in its Beats Studio Buds, identified as CVE-2025-20701. This flaw was uncovered by researchers Dennis Heinze and Frieder Steinmetz from ERNW GmbH. While the specific nature of the vulnerability has not been detailed, it poses a potential risk to users of the Beats Studio Buds, which are popular wireless earbuds. Users are encouraged to install the latest firmware update to ensure their devices are protected. Ignoring this update could leave users vulnerable to potential exploits that might compromise their audio experience or privacy.

Read Original

Congress is moving forward with the No FAKES Act, a bipartisan effort aimed at tackling the unauthorized use of deepfake technology that exploits the likeness of artists and performers. This legislation seeks to prevent third parties from profiting off AI-generated content without permission, which has raised concerns among many in the entertainment industry. However, some business and digital rights groups are pushing back against the Act, suggesting it could have unintended consequences for creativity and free expression. As this legislation progresses, it could significantly reshape how deepfake technology is regulated and could impact content creators and consumers alike. The outcome of this initiative highlights the ongoing debate over digital rights in the age of AI.

Read Original

Novo Nordisk, a major player in the pharmaceutical industry, faced a security incident when a GitHub token was leaked. This breach raises concerns about the management of sensitive information within software development environments. Experts warn that many organizations mistakenly view secrets management solely as a technical issue rather than one involving identity and access control. The implications of this breach are significant, as it exposes vulnerabilities in the software development pipeline that could be exploited by malicious actors. Companies need to reassess their security practices to better protect their development resources and sensitive data.

Read Original

A new threat group, referred to as Operation Escaneo, has emerged in Latin America, displaying a unique approach to cyberattacks. This group appears to blend opportunistic monetization with intelligence gathering, often without coordinated efforts between the two activities. This dual focus raises concerns about the potential for more disruptive attacks, as the group may exploit vulnerabilities for financial gain while simultaneously collecting valuable information. The implications of this strategy could affect various sectors in the region, particularly as attackers may target organizations without prior notice. Companies need to be vigilant and enhance their cybersecurity measures to defend against such evolving threats.

Read Original
Critical
Operation Endgame Disrupts SocGholish Malware Infrastructure

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

International law enforcement agencies recently launched Operation Endgame, targeting the infrastructure behind the SocGholish malware, associated with the threat actor TA569. This operation resulted in the takedown of over 100 command-and-control servers and addressed nearly 15,000 compromised websites that were being used to distribute the malware. SocGholish is primarily known for its role in delivering ransomware and other malicious payloads, affecting users worldwide. The dismantling of this infrastructure is significant as it disrupts the operations of cybercriminals and protects potential victims from falling prey to these malicious attacks. By targeting such extensive networks, authorities aim to reduce the overall risk of cyber threats stemming from this group.

Read Original

Nintendo of America has confirmed that data from the TinyPulse service, a third-party platform used for internal surveys, was stolen during a cyberattack. While Nintendo's own systems were not compromised, the breach affects the survey data collected through TinyPulse. This incident raises concerns over the security of third-party services that companies rely on for internal operations. Users whose data was stored on TinyPulse may be at risk, as the stolen information could be used for phishing or other malicious activities. Companies using third-party services should ensure they have robust security measures in place to protect sensitive information.

Read Original

A security vulnerability in FIFA's access control system could have allowed hackers to take over World Cup streaming services. The issue stems from FIFA's failure to enforce its Entra access controls, which could have been exploited to manipulate live streams. This situation raises concerns about the security of high-profile events, as attackers could disrupt broadcasts or inject malicious content. The potential for such a breach underscores the need for organizations to prioritize robust security measures, especially during major global events. As millions tune in to watch the World Cup, the implications of this vulnerability could have been significant, affecting viewers and FIFA's reputation alike.

Read Original
Actively Exploited

A recent analysis has revealed that a majority of REDCap servers accessible via the internet are outdated and vulnerable. These servers, which are widely used in research and healthcare for data collection, are currently being targeted by a hacking group linked to China, known as UNC6508. Researchers found that these attackers use these vulnerabilities for initial access and to deploy backdoors, making it easier for them to exploit the systems further. The situation raises serious concerns for organizations relying on REDCap for sensitive data management, as outdated servers can lead to data breaches and compromise patient confidentiality. It's crucial for administrators to update their systems to defend against these ongoing attacks.

Read Original

Accenture has made a significant move in the cybersecurity sector by investing $4.18 billion to acquire a majority stake in Dragos, along with the companies runZero and NetRise. This marks Accenture's first major entry into operational technology software at a time when threats to critical infrastructure are on the rise, particularly those driven by artificial intelligence. The acquisitions aim to bolster Accenture's capabilities in protecting industrial systems from cyberattacks, which are becoming increasingly sophisticated. As organizations rely more on connected technologies, ensuring the security of these systems is crucial for preventing potential disruptions. This strategic investment highlights the growing emphasis on safeguarding operational technology in various industries.

Read Original
Actively Exploited

Researchers have discovered a new Rust-based crypto clipper that uses fake GitHub stars and AI-generated YouTube videos to attract victims. This malware secretly steals cryptocurrency by intercepting clipboard data, making it particularly dangerous for users engaging in crypto transactions. The clipper disguises itself as a legitimate tool, misleading users into downloading it. This incident is concerning as it highlights how attackers are increasingly using social engineering tactics to gain trust and spread malware. Users are advised to be cautious about the tools they download and to verify sources before installation.

Read Original

A healthcare worker has been cautioned by the Information Commissioner's Office (ICO) after attempting to sell the medical records of the Princess of Wales. The incident occurred at a hospital where the insider tried to profit from sensitive information regarding the royal's health. Although the ICO decided not to pursue criminal charges, the case raises significant concerns about data privacy and the protection of personal health information in the healthcare sector. This event underscores the continuous need for stringent data protection measures, especially in environments that handle sensitive information. The potential for misuse of such data could undermine public trust in healthcare systems.

Read Original
PreviousPage 146 of 370Next