Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Ingram Micro, a major player in the information technology sector, experienced a ransomware attack in July 2025 that compromised the personal data of over 42,000 individuals. The breach raises serious concerns about data security and the potential misuse of sensitive information, as attackers often seek to exploit such data for financial gain or identity theft. The scale of the incident highlights the ongoing risks that companies face from cyber threats, particularly in the IT sector, which is often targeted due to its critical role in global infrastructure. Affected individuals should remain vigilant for signs of identity theft and consider monitoring their accounts for unusual activity. Organizations must strengthen their cybersecurity measures to prevent similar incidents in the future.

Impact: Personal data of over 42,000 individuals
Remediation: N/A
Read Original

This week, several significant cybersecurity incidents have emerged, showcasing the vulnerabilities within various systems. Notably, flaws in Fortinet products have come to light, potentially exposing users to exploitation. Additionally, researchers have identified the RedLine Clipjack malware, which can hijack browser sessions, affecting users who may not realize their data is being compromised. The discovery of a method to crack NTLM authentication raises concerns for organizations relying on this protocol, as it could lead to unauthorized access. Furthermore, a new attack targeting AI tools like Copilot illustrates how these advancements can be manipulated, posing risks to users and their data. These incidents emphasize the need for robust security measures as technology continues to evolve rapidly.

Impact: Fortinet products, NTLM authentication, AI tools like Copilot
Remediation: Users should apply the latest security updates from Fortinet, review authentication protocols, and implement additional security measures for AI tools.
Read Original
Hackers Exploiting PDF24 App to Deploy Stealthy PDFSIDER Backdoor

Hackread – Cybersecurity News, Data Breaches, AI, and More

Actively Exploited

Researchers from Resecurity have uncovered a new malware called PDFSIDER that takes advantage of the legitimate PDF24 application to steal sensitive data and provide attackers with remote access to compromised systems. This malware is part of a sophisticated campaign targeting corporate networks, utilizing spear-phishing tactics to lure victims and encrypted communications to evade detection. Companies using PDF24 should be particularly vigilant as this attack leverages a trusted application, making it easier for attackers to bypass security measures. The implications are serious, as this could lead to significant data breaches and unauthorized access to sensitive corporate information.

Impact: PDF24 App, corporate networks
Remediation: Users should monitor for unusual activity in their networks, implement strong email filtering to block spear-phishing attempts, and ensure that all software, including PDF24, is kept up to date with the latest security patches.
Read Original

Ukrainian authorities recently conducted a raid targeting individuals linked to the Black Basta ransomware group, a notorious criminal organization responsible for various cyberattacks. Among those arrested was Oleg Evgenievich Nefedov, who is believed to be one of the group's founders and has been placed on both Europol’s and Interpol’s Most Wanted lists. Black Basta has gained notoriety for deploying ransomware that encrypts victims' files and demands a ransom for their release. The group's activities have affected numerous businesses and organizations worldwide, raising concerns about the growing threat posed by such cybercriminals. This operation underscores the ongoing efforts by law enforcement to combat ransomware and bring perpetrators to justice.

Impact: Businesses and organizations targeted by Black Basta ransomware
Remediation: Organizations should implement robust backup solutions, regularly update software, and train employees on recognizing phishing attempts to mitigate risks from ransomware attacks.
Read Original

Ingram Micro, a major IT distribution company, recently suffered a ransomware attack that has affected approximately 42,000 individuals. The breach compromised sensitive personal information, including names, dates of birth, Social Security numbers, and employment-related data. This incident raises significant concerns about data security and the potential misuse of personal information. It highlights the ongoing risks that companies face from cyberattacks and the importance of robust security measures to protect sensitive data. Affected individuals may face identity theft and other consequences stemming from this data exposure.

Impact: Personal information including names, dates of birth, Social Security numbers, employment-related data
Remediation: N/A
Read Original

The British Army is investing £279 million to establish a permanent base for its cyber regiment at Duke of Gloucester Barracks in Gloucestershire. This base will be home to the 13 Signal Regiment, which plays a key role in protecting Army networks and conducting cyber operations. The new facilities will enhance training and intelligence capabilities, as well as house the Army's Cyber, Information and Security Operations Centre. This move emphasizes the Army's commitment to strengthening its cybersecurity posture and preparing for future cyber threats. Given the increasing reliance on digital systems, this investment is crucial for maintaining operational security and effectiveness.

Impact: British Army networks, 13 Signal Regiment
Remediation: N/A
Read Original

A recent report by Nardello & Co highlights the growing concerns for UK companies regarding cyber breaches, compliance issues, and reputational damage as they head into 2026. The report outlines that businesses are increasingly worried about the convergence of cyber risks, which can lead to significant financial losses and undermine consumer trust. Companies of all sizes are urged to reassess their cybersecurity strategies and ensure they meet regulatory compliance to mitigate these risks. With cyber threats evolving rapidly, businesses need to prioritize their defenses and be proactive in their approach to security. The findings serve as a wake-up call for organizations to strengthen their cybersecurity measures and protect their reputations.

Impact: N/A
Remediation: Companies should reassess cybersecurity strategies and ensure regulatory compliance.
Read Original

CyberArk has reported that it successfully exploited a vulnerability in the StealC infostealer malware to gather intelligence. This malware is known for stealing sensitive information from infected systems, which can include login credentials, financial data, and personal information. By exploiting the flaw, researchers were able to collect evidence that can help understand how the malware operates and how it might be mitigated. This incident underscores the ongoing challenges posed by infostealers and the need for organizations to remain vigilant against such threats. Users and companies should ensure their systems are updated and monitor for signs of compromise, as infostealers like StealC can have serious implications for data security.

Impact: StealC infostealer malware
Remediation: Users should update their systems and implement security measures to monitor for infections.
Read Original

Researchers have identified a cross-site scripting (XSS) vulnerability in the control panel of StealC, a malware used for stealing information. This flaw allowed the researchers to monitor the activities of the threat actor behind the malware, including capturing system fingerprints and tracking active sessions. The discovery is significant as it provides a rare glimpse into the operations of cybercriminals who utilize this malware. Understanding how these operators function can aid in developing better defenses against such threats. As StealC continues to be a tool for attackers, this vulnerability highlights the ongoing risks associated with information-stealing malware.

Impact: StealC information stealer malware control panel
Remediation: N/A
Read Original

A recent study by Palo Alto Networks warns that the upcoming Milan Cortina 2026 Winter Olympic Games could attract cyber attackers looking to exploit the event's extensive digital infrastructure. With the Olympics featuring increased network traffic, new systems, and temporary partnerships, the risk of cyber incidents rises significantly. Attackers are likely to target various components of the event's digital ecosystem, including ticketing platforms and telecommunications infrastructure. This situation poses a threat not only to the event organizers but also to attendees and stakeholders who rely on these digital services. As the event approaches, it’s crucial for companies involved in the Olympics to enhance their cybersecurity measures to mitigate potential attacks.

Impact: Ticketing platforms, telecommunications infrastructure, digital services used during the Olympics
Remediation: Companies involved should enhance cybersecurity measures and prepare for potential attacks as the event approaches.
Read Original

A recent survey by Allianz shows that cyber risk is still the top concern for businesses around the world, marking its fifth consecutive year at the top of the list. The survey highlights that threats like ransomware, data breaches, service outages, and regulatory issues are major challenges that impact companies' revenues and customer trust. As businesses increasingly adopt AI technologies, they are also having to rethink their strategies for resilience and recovery in light of these ongoing cyber threats. This situation emphasizes the need for organizations to prioritize their cybersecurity measures to protect against these persistent risks.

Impact: Ransomware, data theft, service outages, regulatory compliance issues
Remediation: Prioritize cybersecurity measures, enhance resilience and recovery strategies
Read Original

Microsoft has rolled out emergency updates for Windows 10, Windows 11, and Windows Server to address issues that arose from the January Patch Tuesday updates. These out-of-band updates specifically target problems related to system shutdowns and Cloud PC functionality. Users of these operating systems may experience disruptions due to these bugs, which could impact productivity and system reliability. It's crucial for users to apply these updates promptly to ensure their systems operate smoothly and to mitigate any potential security risks that may arise from unresolved bugs.

Impact: Windows 10, Windows 11, Windows Server
Remediation: Users should apply the emergency updates provided by Microsoft to resolve the shutdown and Cloud PC issues.
Read Original

Researchers have discovered 17 malicious browser extensions associated with the GhostPoster campaign that have been installed over 840,000 times across Chrome, Firefox, and Edge stores. These extensions are designed to hijack users' browsing sessions and can potentially lead to data theft or other malicious activities. The widespread installation indicates that many users may have unknowingly compromised their security by downloading these harmful extensions. It's crucial for users to regularly check their installed extensions and remove any that seem suspicious. The incident raises concerns about the security measures in place within browser extension stores and the need for more stringent vetting processes to protect users from such threats.

Impact: Chrome, Firefox, Edge browsers
Remediation: Users should uninstall any suspicious browser extensions and regularly review their installed extensions for potential threats.
Read Original

A recent report from Infosecurity Magazine indicates that industrial technology environments are facing a significant surge in cyberattacks. The number of incidents has doubled, particularly targeting vulnerabilities in industrial control systems. This increase poses serious risks for industries reliant on these systems, as attackers may exploit weaknesses to disrupt operations or compromise sensitive data. Companies operating in sectors such as manufacturing, energy, and transportation should be particularly vigilant, as the implications of these attacks could lead to operational downtime and financial losses. The trend highlights the urgency for organizations to enhance their cybersecurity measures to protect against evolving threats.

Impact: Industrial control systems, manufacturing systems, energy sector technologies, transportation systems
Remediation: Organizations should implement stronger security protocols, conduct regular vulnerability assessments, and ensure timely updates to industrial control systems.
Read Original
Actively Exploited

Researchers have discovered a vast network of over 18,000 command-and-control servers operated by Chinese cybercriminals, which have been used to facilitate malware attacks. These servers are spread across 48 different hosting providers and account for nearly 84% of all malicious cyber activities within Chinese hosting environments over the past three months. This extensive operation poses significant risks to businesses and individuals, as the malware can compromise systems and steal sensitive information. The scale of the operation indicates a well-organized effort that could have far-reaching implications for cybersecurity in the region and beyond. Companies need to remain vigilant and enhance their defenses against these types of threats.

Impact: N/A
Remediation: Companies should enhance their cybersecurity measures, regularly update their systems, and monitor for any suspicious activity.
Read Original
PreviousPage 158 of 219Next