Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A recent supply chain attack has compromised over 320 NPM packages under the @antv namespace. This attack was executed through a hacked maintainer account, which allowed malicious versions of these packages to be published. Users who depend on these packages for their projects may unknowingly download the harmful versions, putting their systems at risk. The incident serves as a reminder of the vulnerabilities present in package management systems and the importance of secure maintainer accounts. Developers should review their dependencies and ensure they are using trusted versions to protect their applications.

Read Original
Critical
Fake Word Phishing Reveals Enterprise Blind Spot in Trusted Remote Access Tools

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Researchers have discovered a new phishing method that exploits trusted remote access tools by disguising malicious files as legitimate Word documents. This tactic targets enterprises, taking advantage of the trust associated with popular remote access software. The attackers trick users into opening these fake documents, which can lead to unauthorized access and potential data breaches. This incident reveals a significant vulnerability in how companies manage remote access tools and highlights the need for better security practices. Organizations must enhance their training and awareness programs to protect against such deceptive attacks.

Read Original

As companies rapidly deploy artificial intelligence projects, security teams are finding themselves reacting to vulnerabilities after they go live. The rush to implement AI solutions often sidelines security considerations, leaving systems exposed to various risks. This trend poses significant challenges, as organizations struggle to secure their AI applications once they are already in production. The lack of preemptive security measures can lead to data breaches and other security incidents, affecting not only the companies involved but also their customers and partners. As AI becomes more integrated into business operations, prioritizing security from the start is crucial to safeguard sensitive information and maintain trust.

Read Original

A new vulnerability known as PinTheft has been identified in Arch Linux systems, allowing local attackers to escalate their privileges to root. This flaw has been patched recently, but now a proof-of-concept exploit has been released publicly, which could make it easier for malicious actors to take advantage of the vulnerability. Users running Arch Linux should be particularly vigilant, as this could lead to unauthorized access and control over affected systems. The presence of a publicly available exploit raises concerns about potential attacks, especially in environments where security measures may not be robust. It’s crucial for users to apply the latest patches and updates to mitigate the risks associated with this vulnerability.

Read Original
Actively Exploited

Researchers from Barracuda have reported that a new type of scareware, known as CypherLoc, has been involved in nearly three million attacks targeting users. This malicious software seeks to instill fear in users by falsely claiming their data is compromised, prompting them to purchase unnecessary security services. The sheer volume of attacks indicates a widespread campaign that could affect anyone using vulnerable systems. As more users fall victim to these tactics, it raises concerns about the effectiveness of current cybersecurity measures and the need for increased awareness. Companies and individuals alike should remain vigilant against such scams, ensuring they do not fall prey to these intimidation tactics.

Read Original

GitHub has confirmed that a hacking group known as TeamPCP accessed 3,800 internal repositories due to a compromised Visual Studio Code extension installed by an employee. The malicious extension was designed to steal credentials, allowing the attackers to gain unauthorized access to sensitive data within GitHub's infrastructure. This incident raises significant concerns about software supply chain security and the potential risks associated with third-party tools that developers use. GitHub has not disclosed the specific data that may have been exposed but emphasizes the importance of securing development environments to prevent similar attacks in the future. Companies using GitHub must be vigilant and review their security practices to mitigate the risks posed by such vulnerabilities.

Read Original
Critical
Banana RAT Malware in Fake Invoices Hits Customers at 16 Brazilian Banks

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

A new malware strain known as Banana RAT is targeting customers of 16 Brazilian banks through deceptive tactics involving fake invoices and misleading security update screens. This malware is designed to steal sensitive information by tricking users into scanning fraudulent QR codes. The attack not only compromises personal data but also poses a significant financial risk to victims. As cybercriminals increasingly exploit these social engineering techniques, it's vital for users to remain vigilant and question unexpected communications that ask for sensitive information. The situation underscores the need for heightened security awareness among banking customers.

Read Original

Researchers have identified a vulnerability in ExifTool, a widely used tool for reading and writing metadata in image files, that could allow attackers to compromise macOS systems through malicious images. This vulnerability, tracked as CVE-2026-3102, poses a significant risk to users who handle image files, as it enables the execution of harmful code when a malicious image is processed. Users running macOS could be particularly affected, especially those who frequently use ExifTool or similar applications. The implications are serious, as attackers could exploit this flaw to gain unauthorized access to systems, potentially leading to data breaches or other malicious activities. It’s crucial for users to stay informed about this issue and take appropriate steps to protect their systems.

Read Original

A trojanized Visual Studio Code extension was installed by a GitHub employee, leading to a significant security breach where approximately 3,800 internal repositories were exfiltrated. The hacking group TeamPCP has claimed responsibility for the attack and is demanding a ransom of $50,000. This incident is particularly striking given GitHub's role as a major platform for software development, emphasizing the risks associated with third-party extensions. The breach raises serious concerns about the security practices surrounding code editors and the potential vulnerabilities they introduce into development environments. As the situation unfolds, it serves as a reminder for organizations to scrutinize the tools and extensions their developers use.

Read Original

According to the latest Verizon Data Breach Investigations Report (DBIR), 31% of data breaches in the past year were triggered by software vulnerabilities. This marks a significant shift, as exploits of these vulnerabilities have surpassed credential theft as the primary method for attackers to gain access to systems. The findings suggest that organizations need to prioritize patch management and vulnerability assessments to protect their data. With software flaws being a major entry point for data breaches, companies should be vigilant in monitoring their systems and applying necessary updates promptly. The report serves as a wake-up call for businesses to fortify their defenses against these increasingly common attacks.

Read Original

Microsoft has addressed a significant vulnerability in its BitLocker encryption feature, identified as YellowKey and tracked under the CVE-2026-45585 designation. This security flaw, which has a CVSS score of 6.8, allows attackers to bypass key protections, potentially exposing sensitive data on affected systems. The issue was publicly disclosed last week, prompting Microsoft to issue a mitigation to protect users. This vulnerability primarily affects Windows operating systems that utilize BitLocker for disk encryption. Given that BitLocker is widely used by businesses and individuals to secure data, the implications of this flaw are serious, making it crucial for users to implement the provided mitigation as soon as possible.

Read Original

Microsoft has recently disclosed a zero-day vulnerability known as YellowKey that affects Windows BitLocker, which is used for encrypting drives. This vulnerability allows unauthorized access to protected drives, posing a significant risk to users' sensitive data. While Microsoft has not specified which particular versions of Windows are impacted, the potential for exploitation raises concerns for many users and organizations relying on BitLocker for data protection. Microsoft has provided mitigation strategies to help users safeguard their systems until a more permanent fix is available. It is crucial for users to implement these mitigations to prevent unauthorized access to their data.

Read Original

Interpol recently launched 'Operation Ramz', a significant initiative targeting cybercrime across 13 countries in the Middle East and North Africa (MENA) region. This operation marks the largest collaborative effort among law enforcement agencies in the area, aiming to tackle various cybercriminal activities. While specific numbers of arrests or cases were not disclosed, the operation is seen as a pivotal step in enhancing cross-border cooperation against cyber threats. The collaboration demonstrates a growing recognition of the need for regional partnerships in addressing cybercrime, which continues to evolve in sophistication and scale. Such initiatives are crucial as they help to disrupt criminal networks and protect citizens from cyber threats.

Read Original

Large language models are increasingly being used in operational roles, where they can manage live infrastructure by querying data and making configuration changes. However, this raises significant security concerns, particularly the 'confused-deputy problem.' This issue occurs when an AI assistant is tricked into executing commands that it shouldn't, potentially leading to unintended consequences. The deployment of such autonomous systems means that companies need to be vigilant about how these AI tools are integrated into their networks. Proper safeguards and monitoring are essential to prevent misuse or errors that could disrupt operations.

Read Original

On July 23, 2025, Luxembourg experienced a major telecom outage that lasted over three hours, affecting landline, 4G, 5G, and emergency services. The disruption was reportedly caused by a zero-day vulnerability in Huawei enterprise routers. This flaw allowed attackers to exploit the system, leading to widespread communication failures across the country. The incident raised concerns about the security of telecom infrastructure and the potential risks associated with undisclosed vulnerabilities in widely used equipment. The implications of this outage are significant, as it not only disrupted everyday communications but also emergency services, highlighting the critical need for robust cybersecurity measures in telecommunications.

Read Original
PreviousPage 164 of 370Next