Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

FulcrumSec has leaked a massive amount of data, reportedly 1.3TB, stolen from Danish pharmaceutical company Novo Nordisk. The breach includes sensitive clinical records and research on artificial intelligence. This incident began on June 15, 2026, after Novo Nordisk refused to pay a ransom of $25 million demanded by the attackers. The leaked data could have serious implications for patient privacy and the integrity of ongoing clinical research, particularly given Novo Nordisk's role in producing widely used medications like Ozempic and Wegovy. This incident raises concerns about the security of healthcare data and the potential consequences of ransomware attacks on critical industries.

Read Original
Critical
15 Malicious JetBrains Plugins Caught Stealing DeepSeek, OpenAI API Keys

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Researchers have discovered 15 malicious plugins for JetBrains IDEs that masquerade as AI coding assistants. These plugins are designed to steal API keys from developers, specifically targeting keys for services like DeepSeek and OpenAI. The attack affects users who download and install these plugins, potentially compromising their projects and access to these AI platforms. This incident raises concerns about the security of third-party tools in the development environment, emphasizing the need for developers to carefully vet plugins before installation. Users are advised to review their installed plugins and remove any that seem suspicious or unverified.

Read Original

Researchers have uncovered a software supply chain attack affecting 144 npm packages linked to the Mastra namespace, which is used for building AI applications. The attack, identified by JFrog, SafeDep, Socket, and StepSecurity, involved the hijacking of a single npm account belonging to a user named 'ehindero', who then published malicious versions of these packages. This incident raises significant concerns for developers who rely on the Mastra framework, as it could lead to the introduction of vulnerabilities in their applications. Users of these compromised packages are urged to check their dependencies and update to secure versions to avoid potential risks. This event serves as a reminder of the importance of securing contributor accounts in open-source ecosystems.

Read Original
Actively Exploited

Recent vulnerabilities found in Joomla and LiteSpeed have been exploited by attackers to execute arbitrary PHP code on shared hosting servers. This means that intruders can potentially gain root access, which allows them to take complete control of affected systems. Websites running Joomla or using LiteSpeed as their web server are particularly at risk. This situation highlights the pressing need for website administrators to ensure their systems are up-to-date and to implement necessary security measures. Failure to address these vulnerabilities could lead to significant data breaches and service disruptions for users.

Read Original

A group of security experts has expressed strong opposition to the U.S. government's recent ban on exporting Anthropic's AI models, specifically Claude Fable 5 and Mythos 5. In an open letter, the experts argue that these export restrictions hinder progress in the field of artificial intelligence and could have negative implications for research and development. They believe that limiting access to these advanced models could stifle innovation and collaboration among researchers. This situation raises concerns about the balance between national security and the advancement of technology, as the ban could impact various sectors that rely on AI advancements. The experts are urging the government to reconsider these restrictions to foster a more open and collaborative environment in AI research.

Read Original

Researchers have identified at least 15 malicious plugins on the JetBrains Marketplace that are specifically designed to steal AI API keys from developers. These plugins masquerade as legitimate tools, but once installed, they can access sensitive information, putting developers' projects and data at risk. This incident affects anyone using the JetBrains development environment who may unknowingly install these harmful plugins. The theft of API keys can lead to unauthorized access to AI services, potentially resulting in financial losses and compromised projects. Developers are urged to review their installed plugins and ensure they are from trusted sources to protect their work.

Read Original
Actively Exploited

A new Android banking trojan named Rokarolla has emerged, targeting 217 banking and cryptocurrency applications. This malware operates with a sophisticated toolkit, utilizing 137 different commands to carry out its operations. Users of affected apps may be at risk of having their sensitive financial information compromised. As cybercriminals continue to develop more advanced tactics, it's crucial for users to stay vigilant and ensure they have proper security measures in place. The rise of such malware highlights the ongoing threat to mobile banking and cryptocurrency platforms, making it essential for both users and developers to prioritize security.

Read Original

iRhythm Technologies, a U.S.-based company focused on remote cardiac monitoring, has reported a cyberattack that led to the theft of sensitive patient and proprietary data. The attack was linked to vulnerabilities in third-party applications used by the company. Following the breach, the attackers demanded a ransom. This incident raises significant concerns about the security of healthcare data, particularly as cybercriminals increasingly target medical organizations for sensitive information. Patients whose data may have been compromised could face risks related to privacy and identity theft, making it crucial for companies like iRhythm to enhance their cybersecurity measures.

Read Original
Actively Exploited

Recent analysis has revealed that a malware campaign, previously known as 'Lorem Ipsum', is now distributing a tool called ClickFix through compromised WordPress sites. This campaign is suspected to be linked to the ransomware and data extortion group Vice Society. Organizations that rely on WordPress for their websites may be particularly vulnerable, as attackers exploit these compromised platforms to deliver malicious payloads. The implications of this shift are significant, as it not only demonstrates the evolving tactics of cybercriminals but also raises concerns for businesses and their data security. Companies should take precautions to secure their WordPress sites and monitor for any unusual activity.

Read Original

iRhythm, a digital health company, confirmed that it experienced a data breach after discovering the incident on June 8. The attackers demanded a ransom, indicating that sensitive information may have been accessed or stolen. While the company has not detailed the specific data affected, this incident raises concerns about the security of health-related data and the potential risks to patients and customers. Cyberattacks like this can undermine trust in digital health solutions and expose individuals to identity theft or privacy violations. Companies in the healthcare sector need to strengthen their cybersecurity measures to protect sensitive information from similar threats.

Read Original

The article discusses the growing threat of deepfake and synthetic identity attacks targeting financial institutions, including those in the crypto sector. In 2025, these types of attacks led to an estimated $17 billion in stolen cryptocurrency. This surge in identity fraud raises serious concerns about the reliability of identity verification in financial transactions, which could undermine trust in the entire crypto industry. As attackers develop more sophisticated methods, both consumers and businesses need to be increasingly vigilant about identity assurance. The implications of these attacks could extend beyond financial losses, affecting the overall stability and credibility of digital currencies.

Read Original

A recent study by the Information Systems Security Association (ISSA) reveals that a significant majority of security professionals—over two-thirds—are finding it increasingly difficult to manage cybersecurity threats. One key challenge identified is the involvement of colleagues from other departments in cybersecurity efforts, which can complicate security practices. As more employees are engaged in cybersecurity, the potential for miscommunication and inadequate training grows. This situation raises concerns about the overall effectiveness of security measures within organizations. It emphasizes the need for better collaboration and education among all staff to enhance the organization's security posture.

Read Original

California Water Service is currently investigating claims made by Iranian hackers regarding potential breaches of its water and wastewater systems. However, the company has stated that there is no evidence of any operational disruptions at this time. This situation raises concerns about the security of critical infrastructure, especially as cyber threats to public utilities continue to grow. Authorities and customers alike are watching closely to see if these claims lead to any actual security incidents that could impact water supply or safety. The investigation is ongoing, and Cal Water is taking the matter seriously to ensure the integrity of their systems.

Read Original
Critical
Flock Cameras Are Being Used for Stalking

Schneier on Security

Actively Exploited

Police departments across the United States are reportedly using Flock surveillance cameras in ways that raise serious privacy concerns. In over a dozen cases, officers have allegedly stalked individuals without legal justification, utilizing the camera system to track their movements obsessively. This misuse of technology not only breaches ethical standards but also raises alarms about the potential for abuse of surveillance tools meant to enhance public safety. The impact of these actions could undermine trust in law enforcement and lead to calls for stricter regulations on surveillance practices. Advocates for privacy rights are urging for greater oversight to prevent such incidents from occurring in the future.

Read Original

Chainguard, JPMorgan, and BNY Mellon have joined forces to create a new coalition called Athena, aimed at addressing vulnerabilities in open source software that could be exploited by artificial intelligence. This initiative seeks to identify and fix weaknesses in AI models before they can be targeted by malicious actors. The collaboration comes as the reliance on open source components in software development grows, raising concerns about security. By proactively addressing these vulnerabilities, the coalition aims to enhance the security of software that many organizations depend on. This move is particularly significant given the increasing sophistication of cyber threats related to AI technology.

Read Original
PreviousPage 149 of 370Next