Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

RansomHouse Claims Data Breach at Major Apple Contractor Luxshare

Hackread – Cybersecurity News, Data Breaches, AI, and More

RansomHouse, a known cybercriminal group, claims to have breached Luxshare, a major contractor for Apple. However, as of now, there is no tangible evidence to support this claim, and the links associated with the breach are currently offline. This situation raises concerns because Luxshare plays a critical role in Apple's supply chain, and any data breach could potentially compromise sensitive information related to Apple's operations. The lack of verification means that while the claim exists, its legitimacy remains uncertain. Companies in similar sectors should remain vigilant as the situation develops, given the potential risks from such threats.

Impact: Apple's supply chain, Luxshare's systems
Remediation: N/A
Read Original

Researchers from ReliaQuest have identified a phishing campaign targeting high-profile business executives through LinkedIn messages. The attackers are using an open-source penetration testing tool to craft convincing messages that trick individuals into revealing sensitive information. This campaign is particularly concerning because it targets 'high-value individuals,' making it more likely to succeed against those with access to critical company data. Companies need to educate their employees about recognizing phishing attempts and to implement stronger security measures to protect against these types of attacks. With the rise of social engineering tactics like this, vigilance is essential for safeguarding sensitive business information.

Impact: LinkedIn, Business Executives
Remediation: Companies should train employees to recognize phishing attempts and consider implementing two-factor authentication for LinkedIn accounts.
Read Original

Researchers have discovered five malicious Chrome extensions designed to target users of Workday, NetSuite, and SuccessFactors. These extensions are capable of stealing cookies and preventing access to critical security pages on these platforms. This poses a significant risk to organizations that rely on these software solutions for their operations, as attackers can gain unauthorized access to sensitive information. Users of these platforms should be particularly vigilant about the extensions they install and ensure they are using only trusted sources. The presence of such malicious tools illustrates the ongoing challenges of keeping enterprise software environments secure.

Impact: Workday, NetSuite, SuccessFactors
Remediation: Users should uninstall any suspicious Chrome extensions and regularly monitor their browser for unauthorized additions. Additionally, organizations should educate employees about the risks of installing unverified extensions.
Read Original

According to a report by Group-IB, cybercriminals are increasingly using weaponized AI to enhance their attacks, marking a new phase in cybercrime. This so-called 'fifth wave' of cyber threats is characterized by the use of advanced AI technologies to automate and improve the efficiency of malicious activities. Researchers indicate that this trend poses significant risks to individuals and organizations alike, as attackers can now execute more sophisticated and targeted assaults. The report emphasizes the urgent need for businesses to bolster their cybersecurity measures in response to these escalating threats. As AI continues to evolve, it’s crucial for companies to stay ahead of potential attacks by investing in advanced security solutions and training their staff to recognize and respond to AI-driven threats.

Impact: N/A
Remediation: Companies should enhance their cybersecurity measures and consider investing in advanced security solutions.
Read Original

Tudou Guarantee, a well-known marketplace for scams and fraudulent activities, has reportedly shut down its public Telegram groups. This closure marks a significant step in the ongoing efforts to combat online fraud, as these groups served as platforms for scammers to communicate and coordinate their illicit activities. Users who previously relied on these groups for guidance or to connect with other scammers are now left searching for alternative channels. The disappearance of Tudou Guarantee's Telegram presence could disrupt the operations of its members, but it remains to be seen whether they will regroup elsewhere or if this will lead to a decline in their activities. The situation underscores the challenges in tackling online criminal networks that continuously adapt to enforcement measures.

Impact: Tudou Guarantee Telegram groups
Remediation: N/A
Read Original

The article discusses several key cybersecurity issues, including the MongoBleed vulnerability, which affected MongoDB databases by allowing unauthorized access to sensitive data. Researchers pointed out that this incident serves as a reminder for developers to adhere to secure coding practices. The article also references the CWE Top 25, a list of common vulnerabilities that developers should be aware of, emphasizing the importance of addressing these weaknesses in software. Additionally, it touches on secure coding benchmarks that can help prevent such vulnerabilities in the future. Overall, the piece stresses the need for ongoing education and vigilance in software development to protect against these threats.

Impact: MongoDB databases
Remediation: Implement secure coding practices, adhere to CWE Top 25 recommendations, and follow secure coding benchmarks.
Read Original

Tudou Guarantee, a prominent illicit marketplace operating on Telegram, has reportedly halted all transactions in its public groups. According to blockchain security firm Elliptic, this marketplace has facilitated over $12 billion in transactions, primarily serving users in Southeast Asia. While the public groups are no longer active, Elliptic notes that other associated services may still be operational, suggesting that the full extent of Tudou Guarantee's shutdown is yet to be determined. This development highlights ongoing challenges in combating illegal online marketplaces, which continue to pose significant risks to cybersecurity and financial systems. The cessation of transactions may impact users who relied on the platform for illicit goods and services, but it also raises questions about the future of similar marketplaces on encrypted platforms.

Impact: Tudou Guarantee marketplace on Telegram
Remediation: N/A
Read Original

The UK government's National Cyber Security Centre (NCSC) has issued a warning about ongoing Distributed Denial of Service (DDoS) attacks carried out by Russia-linked hacktivists. These attacks are targeting critical infrastructure and local government systems across the UK. The NCSC's alert, released on January 19, 2026, emphasizes the potential disruption these attacks can cause, putting essential services at risk. The government urges organizations to bolster their defenses against such incidents, highlighting that the threat remains persistent. This situation is particularly concerning as it could impact public safety and the functionality of vital services during times of crisis.

Impact: Critical infrastructure, local government systems
Remediation: Organizations should enhance their cybersecurity measures and prepare for potential DDoS attacks.
Read Original

A recent global study by ISACA reveals that privacy teams are facing significant challenges as they grapple with the risks of data breaches, the integration of new technologies like AI, and tight budgets. Although AI is increasingly being applied to privacy tasks such as data discovery and risk assessment, only a small fraction of organizations have adopted these tools effectively. The study emphasizes that the use of AI in privacy work is more about the maturity of the organization rather than an urgent necessity. This situation is concerning because it indicates that many privacy programs may struggle to keep up with evolving threats and compliance requirements. As organizations continue to navigate these pressures, the effectiveness of their privacy programs is at stake, which could lead to greater risks for personal data security.

Impact: N/A
Remediation: N/A
Read Original

The U.K. government has issued a warning about ongoing attacks from Russian-aligned hacktivist groups that are targeting the country's critical infrastructure and local government entities. These attacks primarily involve disruptive denial-of-service (DDoS) tactics, which can overwhelm systems and render them inoperable. As these groups continue their campaigns, organizations may face significant operational challenges and potential data breaches. It’s crucial for affected entities to bolster their cybersecurity measures to mitigate the risks associated with these aggressive actions. The situation highlights a growing trend of politically motivated cyberattacks that can impact essential services and public safety.

Impact: Critical infrastructure, local government organizations
Remediation: Organizations should enhance their cybersecurity protocols, including implementing DDoS mitigation strategies and monitoring network traffic for unusual activity.
Read Original

The UK's National Cyber Security Centre (NCSC) has issued a warning about an increase in disruptive cyber attacks carried out by Russian hacktivists. These attacks are primarily targeting critical infrastructure across the UK, raising concerns about the potential for significant disruptions to essential services. The NCSC has not specified the exact organizations or sectors being targeted, but the implications could be serious for public safety and national security. As these attackers become more aggressive, organizations must remain vigilant and enhance their cybersecurity measures to prevent potential breaches. This development comes amid heightened geopolitical tensions, making it crucial for all sectors to be prepared for potential cyber threats.

Impact: Critical infrastructure in the UK
Remediation: Organizations should enhance cybersecurity measures and continuously monitor for unusual activity.
Read Original

A vulnerability affecting TP-Link's VIGI cameras has been patched after a researcher identified over 2,500 devices that were exposed to potential remote hacking. This flaw allowed unauthorized access to the cameras, raising serious security concerns for users. The issue underscores the risks associated with Internet of Things (IoT) devices, which are often targeted due to their connectivity and sometimes weak security measures. Users of VIGI cameras should ensure they apply the latest updates from TP-Link to protect their devices from exploitation. This incident serves as a reminder for all IoT device owners to regularly check for firmware updates and vulnerabilities.

Impact: TP-Link VIGI cameras
Remediation: TP-Link has released a patch to address the vulnerability. Users should update their devices to the latest firmware version.
Read Original

Researchers have identified a cross-site scripting (XSS) vulnerability in the control panel of StealC malware, an infostealer that has been operating since at least 2023. This malware, which is sold as a service, targets and extracts sensitive information like cookies and passwords from victims. The flaw in the control panel has exposed important details about the attackers behind the malware, raising concerns about the ongoing threat to users' data security. Since its update to StealC v2 in 2025, the malware has continued to pose risks to individuals and organizations alike. The discovery emphasizes the need for vigilance against such malware, as the information leak could lead to further malicious activities by the attackers.

Impact: StealC malware, control panel of StealC v2
Remediation: Users should ensure their systems are protected with up-to-date security software and remain cautious of suspicious links or downloads.
Read Original
Google Gemini AI Tricked Into Leaking Calendar Data via Meeting Invites

Hackread – Cybersecurity News, Data Breaches, AI, and More

Researchers at Miggo Security discovered a vulnerability in Google Gemini that allows attackers to exploit calendar invites to extract private user data. This flaw enables a silent attack method, where the malicious actor can trick the AI into leaking sensitive information without raising alarms. The implications of this vulnerability are significant, as it could compromise users' personal schedules and confidential details stored within their calendar apps. Google users relying on Gemini for scheduling and other functions may be particularly at risk. It's crucial for users and organizations to be aware of this issue and take necessary precautions to safeguard their data.

Impact: Google Gemini, Google Calendar
Remediation: Users should review their calendar sharing settings and be cautious when accepting invites from unknown sources.
Read Original

A new information-stealing malware called 'SolyxImmortal' has emerged, which utilizes legitimate APIs and libraries to gather sensitive data. The malware sends this stolen information to Discord webhooks, making detection challenging. This type of attack can affect anyone who unwittingly downloads the malware, potentially compromising personal and financial information. As cybercriminals increasingly exploit trusted platforms and tools, users need to be vigilant about the software they install and the permissions they grant. This incident serves as a reminder of the evolving tactics used by attackers to bypass security measures.

Impact: N/A
Remediation: Users should avoid downloading unverified software and regularly monitor their systems for unusual activity. Employing security software that scans for malware and suspicious behavior can also help mitigate risks.
Read Original
PreviousPage 157 of 219Next