Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Actively Exploited

The article discusses a ransomware group known as INC that has been effectively targeting healthcare and other critical sectors. By focusing on industries where disruptions can lead to immediate pressure to pay ransoms, INC has managed to thrive in the current cybersecurity landscape. Their tactics emphasize the exploitation of vulnerabilities in systems that are essential for operations, thus increasing the likelihood of victims complying with ransom demands. This trend is concerning as it not only affects healthcare providers but also poses risks to patient safety and data security. Organizations need to bolster their defenses and prepare for potential attacks, especially in sectors that are vital to public health.

Read Original

A French-speaking hacker targeted a small automotive company in France, where he successfully installed a keylogger to steal sensitive banking and email credentials. The attack took an interesting turn when the hacker installed OpenSSH and Tailscale on the compromised machine, creating a backdoor to maintain access even after his primary command-and-control server went offline. This method allowed him to bypass traditional C2 channels, making it harder for defenders to cut off his access. The incident serves as a reminder of the evolving tactics used by cybercriminals and the importance for businesses to secure their networks against such persistent threats. Companies should be vigilant about monitoring for unauthorized software installations and maintaining robust security measures.

Read Original
Actively Exploited

Nisos, a cybersecurity firm, has exposed a North Korean fraud operation that employs artificial intelligence for conducting fake job interviews. This operation was found to be using a network of laptops based in the United States to facilitate its activities. The fraud cell aimed to recruit IT workers under false pretenses, potentially to gather sensitive information or fund illicit activities. This situation raises concerns about the growing sophistication of cybercriminals, as they now use advanced technologies like AI to enhance their deception. The infiltration of US-based resources by foreign actors highlights vulnerabilities in cybersecurity defenses and the need for vigilance against such schemes.

Read Original
Actively Exploited

iRhythm Holdings, a medical technology company, reported a cyberattack that occurred on June 8, 2026. The breach involved third-party-hosted business applications and led to the theft of sensitive patient health information, proprietary data, and personal data. Following the discovery of unauthorized activity, iRhythm initiated an investigation with external cybersecurity experts. The situation escalated when a threat actor claimed to possess the stolen data and demanded a ransom. This incident comes shortly after a similar breach affecting Novo Nordisk, raising concerns about the security of healthcare data and the potential risks to patient privacy.

Read Original
Actively Exploited

A new phishing kit called GitBait has been discovered that specifically targets users of Mexican banks. This kit takes advantage of GitHub Pages and the SheetBest API to create fake login pages designed to capture sensitive banking credentials. Researchers have noted that this attack is particularly concerning because it leverages trusted platforms to appear legitimate, potentially tricking victims into providing their information. Users of Mexican banking services should be especially vigilant and ensure they are accessing official websites before entering any personal details. This incident serves as a reminder of the evolving tactics employed by cybercriminals to exploit unsuspecting individuals.

Read Original

A recent supply chain attack has compromised an npm account, leading to the mass publication of over 140 malicious packages under the Mastra name. This incident raises concerns for developers and organizations that rely on npm packages for their software projects, as these malicious packages could potentially introduce vulnerabilities or malware into their applications. Users who inadvertently installed these packages may face security risks, including data breaches or system compromises. This attack serves as a reminder of the ongoing risks associated with open-source software and the importance of verifying the integrity of third-party packages before use. Developers are urged to audit their dependencies to ensure they are not using any of the affected packages.

Read Original

India has imposed a ban on the messaging app Telegram until June 22 due to its use in leaking exam papers. This decision has not only affected users in India but also disrupted services in the UAE, where users reported issues connecting to the app. Telegram's CEO, Pavel Durov, claims that the telecom company Reliance engaged in BGP hijacking, which exacerbated the connectivity problems. Users seeking to bypass the ban can utilize MTProto proxies as a workaround. This incident raises concerns about the impact of government restrictions on digital communication and the broader implications for users in regions far removed from the original decision.

Read Original

A recent survey conducted by Filigran at Infosecurity Europe 2026 indicates that AI-driven attacks are now the primary concern for cybersecurity teams. The report highlights that the rise of these sophisticated attacks is compounded by issues like false positives and alert fatigue, which are overwhelming security staff. As a result, many teams find themselves bogged down by manual processes that drain their resources and effectiveness. This situation poses significant risks, as it could lead to slower responses to actual threats, ultimately compromising the security of organizations. With AI technology becoming more accessible, the need for improved detection and response strategies is more urgent than ever to protect against these evolving threats.

Read Original

During the RUSI Annual Security Lecture, Dr. Richard Horne, the CEO of the UK's National Cyber Security Centre (NCSC), revealed that hostile states are linked to approximately 75% of cyber attacks targeting the country’s critical infrastructure. This alarming statistic underscores the persistent threat faced by essential services, including energy, healthcare, and transportation systems. The NCSC is actively working to bolster defenses against these state-sponsored threats, which can have dire consequences for public safety and national security. With the increasing sophistication of cyber attacks, it is crucial for organizations to remain vigilant and implement robust cybersecurity measures to protect against these hostile actors. The information shared by Dr. Horne serves as a wake-up call for both public and private sectors to prioritize security in their operations.

Read Original

Rockwell Automation has addressed several security vulnerabilities in its products, specifically affecting the Logix, CompactLogix, Flex controllers, RSLinx, and FactoryTalk software. These vulnerabilities could potentially allow unauthorized access or manipulation of industrial control systems, which could have serious implications for manufacturing and automation processes. Users of these products are urged to apply the patches provided by Rockwell to secure their systems. The timely response from Rockwell is crucial in preventing potential exploitation of these weaknesses, especially given the critical role these systems play in various industries. Companies using these affected products should prioritize updating their systems to ensure safety and integrity.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies address a serious vulnerability in the Widget Factory Joomla Content Editor (JCE) plugin. This flaw, classified as maximum severity, is currently being exploited by attackers, which raises significant concerns about potential data breaches or unauthorized access. Federal agencies must implement patches by the end of the week to safeguard their systems. This situation underscores the importance of timely updates and vigilance in maintaining cybersecurity, especially for widely used plugins like JCE. Agencies that fail to patch this vulnerability could face serious repercussions, including compromised data integrity and system security.

Read Original
Actively Exploited

The education technology sector is currently facing a surge in cyberattacks, with groups like ShinyHunters and FulcrumSec specifically targeting schools and educational platforms. These attacks have resulted in the exposure of sensitive data and disruptions to essential services. Researchers from Resecurity have noted that the EdTech industry has become a prime target for cybercriminals, indicating a worrying trend that could threaten the privacy and security of students and staff alike. This uptick in incidents raises significant concerns about the safety of digital learning environments, as many institutions may lack the necessary defenses against such attacks. As cyber threats continue to grow, it is crucial for educational organizations to bolster their cybersecurity measures to protect against potential breaches.

Read Original
Actively Exploited

Aikido Security has found that at least 15 plugins available on the JetBrains Marketplace are stealing API keys from users. These malicious plugins disguise themselves as legitimate tools for integrated development environments (IDEs) but are designed to extract sensitive information. This situation affects developers who rely on these plugins for their work, potentially exposing their projects and personal data. The discovery raises concerns about the security of third-party plugins and the need for vigilance among users when downloading software. Developers should review their installed plugins and consider removing any that might be suspicious.

Read Original

Oracle has rolled out its June 2026 Critical Security Patch Update, addressing a total of 245 vulnerabilities across various products, including Communications, E-Business Suite (EBS), and Enterprise Manager. This update is crucial as it aims to protect users from potential exploitation of these vulnerabilities, which could lead to unauthorized access or data breaches. The large number of patches indicates a significant risk across multiple platforms, making it essential for organizations using these products to apply the updates promptly. By doing so, they can safeguard their systems against possible attacks that may target these weaknesses. Users are encouraged to review the specific patches applicable to their environments and implement them as soon as possible to enhance their security posture.

Read Original

Arch Linux users are facing a serious issue as malicious applications have been discovered in the Arch User Repository (AUR) for the second time in just one week. This repository is a popular resource for users looking to install software not found in the official Arch repositories, making it a prime target for attackers. The presence of these harmful applications poses a risk to users who may inadvertently install them, potentially leading to data breaches or system compromise. It’s essential for users to be cautious and verify applications before installation. The Arch community is urged to report any suspicious packages and follow best practices for software installation to avoid falling victim to these threats.

Read Original
PreviousPage 148 of 370Next