Falcon AIDR, a cybersecurity tool, has identified vulnerabilities specifically targeting the prompt layer in Kubernetes AI applications. These vulnerabilities can allow attackers to manipulate the AI models used within Kubernetes environments, potentially leading to unauthorized access or data breaches. Companies utilizing Kubernetes for their AI applications need to be aware of these risks, as they could face significant operational impacts if exploited. The findings emphasize the necessity for organizations to strengthen their security measures around AI deployments in Kubernetes. Failure to address these vulnerabilities could result in compromised AI systems and sensitive data exposure.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Help Net Security
Researchers from the Norwegian University of Science and Technology and the University of the Aegean have developed a new open-source Wi-Fi cyber range designed specifically for security training. Unlike typical training programs that treat Wi-Fi as just another component alongside other wireless technologies, this new resource focuses solely on the IEEE 802.11 standard, which is crucial as Wi-Fi is often the primary entry point for cyber attackers targeting corporate networks. This initiative addresses a significant gap in hands-on training environments, providing a dedicated platform for professionals to enhance their skills in defending against Wi-Fi related security threats. By making this tool freely available, the researchers aim to improve the overall security posture of organizations that rely heavily on wireless networks.
The U.S. House Committee on Homeland Security has called for testimony from executives at Instructure regarding two significant cyberattacks on its Canvas platform, executed by the ShinyHunters extortion group. These attacks compromised sensitive student data and caused disruptions in schools, particularly during critical final exam periods. The incidents raised alarms about the security measures in place to protect educational institutions, as they directly affect students' academic performance and privacy. The committee's inquiry highlights the growing concern over cyber threats targeting educational technology, emphasizing the need for stronger safeguards against such breaches. As schools increasingly rely on digital platforms, the implications of these attacks could lead to calls for more stringent regulations and practices to protect student information.
CyberScoop
A new malware known as 'Mini Shai-Hulud' has compromised hundreds of open-source packages in a significant supply-chain attack. This malware has targeted major registries, disguising itself behind legitimate release signatures, which allows it to infiltrate software updates unnoticed. As a result, developers and organizations relying on these open-source packages may unknowingly integrate malicious code into their applications. This incident emphasizes the vulnerabilities present in the software update process and raises concerns about the security of open-source software. Researchers are urging developers to be vigilant and to verify the integrity of their dependencies before use.
Hackread – Cybersecurity News, Data Breaches, AI and More
The hacking group ShinyHunters has reported that their domain, shinyhunte.rs, was suspended following a series of attacks on the Canvas Learning Management System (LMS). As a result, they have moved their operations entirely to their dark web site, which uses the .onion domain. This shift highlights the ongoing challenges in combating cybercriminal activities, especially those targeting educational platforms. The suspension of their domain could hinder their ability to communicate and distribute stolen data, but it also indicates the persistent nature of such groups in adapting to law enforcement actions. Users of Canvas and other educational institutions should remain vigilant as these incidents can impact the security of sensitive student information.
A recent wave of attacks, referred to as 'Mini' Shai-Hulud, has compromised hundreds of packages from popular repositories like npm and PyPI. Attackers are exploiting trusted OpenID Connect (OIDC) tokens to bypass integrity checks, allowing them to distribute malicious code disguised as legitimate packages. This situation puts developers and organizations at risk, as they may unknowingly incorporate these tainted packages into their projects. The incident serves as a reminder for users to scrutinize package sources and implement additional security measures when managing dependencies. Ongoing vigilance is crucial to mitigate the potential fallout from these compromised packages.
Fortinet has issued urgent security patches to address two serious vulnerabilities in its FortiSandbox and FortiAuthenticator products. These flaws could allow attackers to execute commands or arbitrary code, posing a significant risk to organizations using these systems. The vulnerabilities affect both security and authentication processes, making them critical to address promptly. Users and administrators are advised to apply the patches immediately to protect their environments from potential exploitation. This situation underscores the need for ongoing vigilance in managing software security and ensuring systems are updated.
Hackread – Cybersecurity News, Data Breaches, AI and More
Researchers at Ontinue have identified a malware campaign that is specifically targeting developers. The campaign uses fake installers for a software called Claude Code to trick users into downloading malware that steals browser credentials, including passwords and cookies. This is particularly concerning for developers as they often store sensitive information in their browsers. The use of fake installers raises alarms about the increasing sophistication of cyber attacks aimed at software developers, who may be more vulnerable due to their technical backgrounds and reliance on various tools. Users are advised to be cautious when downloading software and to verify sources before installation.
BleepingComputer
Škoda Auto has reported a data breach following a hack of its online shop, which has resulted in the theft of personal information from an undisclosed number of customers. The company, part of the Volkswagen Group, has not revealed specific details about the types of data compromised. This incident raises concerns about the security of online shopping platforms and the sensitivity of customer data stored by automotive companies. Affected customers should be vigilant for potential phishing attempts or identity theft in the wake of this breach. The incident underscores the ongoing risks faced by businesses that handle personal information online.
Hackread – Cybersecurity News, Data Breaches, AI and More
Pwn2Own Berlin 2026 has reached full capacity for the first time, leading some researchers who were unable to participate to disclose zero-day exploits publicly. These exploits target widely used software and hardware, specifically Firefox and NVIDIA products, as well as various AI platforms. This situation raises concerns for users and companies relying on these technologies, as zero-day vulnerabilities can be exploited by attackers before patches are released. The public disclosure of these vulnerabilities means that organizations need to act quickly to assess their exposure and implement necessary security measures. This incident emphasizes the ongoing arms race between security researchers and hackers in the cybersecurity landscape.
Researchers have discovered that a tokenizer library file used in Hugging Face AI models can be manipulated, allowing attackers to hijack the model's outputs and exfiltrate sensitive data. This vulnerability affects the integrity of AI models hosted on the Hugging Face platform, which are widely utilized in various applications, including natural language processing tasks. If exploited, this could lead to unauthorized access to data processed by these models, posing risks to both developers and end-users. It is crucial for organizations using these models to be aware of this issue and take steps to secure their implementations. The manipulation of a single file demonstrates how even small changes can have significant security implications.
Sasha Levin, a co-maintainer of the Linux kernel, has introduced a proposal for a runtime killswitch designed to disable vulnerable kernel functions temporarily. This mechanism would be accessible through securityfs, allowing system administrators to quickly mitigate risks associated with known vulnerabilities. The proposal aims to provide a practical solution for managing vulnerabilities in the Linux kernel, which is critical given the widespread use of Linux in servers and devices. By enabling a quick response to potential exploits, this initiative could help enhance the security posture of systems utilizing the Linux kernel. The implementation of such a killswitch is especially relevant as cyber threats continue to evolve, targeting vulnerabilities in operating systems.
SCM feed for Latest
A newly discovered vulnerability, identified as CVE-2026-41940, is affecting cPanel and WebHost Manager, allowing attackers to exploit it shortly after it was made public. The threat actor known as Mr_Rot13 has been observed using this flaw to deploy a backdoor known as Filemanager, which can grant unauthorized access to compromised systems. This situation poses serious risks to web hosting providers and their customers, as it could lead to data breaches and unauthorized control over hosted websites. Companies using affected versions of cPanel and WebHost Manager need to take immediate action to secure their systems and protect sensitive data from being exploited. The urgency of addressing this vulnerability cannot be overstated, given the potential for widespread impact on affected users.
Cyber Defense Magazine
Synthetic identity fraud is becoming increasingly prevalent, with research indicating that about 1 in 25 identity verification attempts involve someone trying to impersonate another individual. This type of fraud is especially concerning for financial institutions and online service providers, as it can lead to significant financial losses and damage to customer trust. Experts suggest that to combat this issue effectively, organizations should focus equally on both biometric verification methods and traditional document verification processes. By improving these verification systems, companies can better protect themselves and their customers from identity theft and fraud. This shift is crucial as attackers continue to evolve their tactics, making it necessary for businesses to stay ahead of these risks.
West Pharmaceutical Services recently fell victim to a ransomware attack that forced the company to take its systems offline worldwide. Hackers not only encrypted files but also exfiltrated sensitive data, raising concerns about the potential impact on the company's operations and the confidentiality of customer information. This incident highlights the growing threat of ransomware attacks in the healthcare sector, where the implications can be particularly severe given the sensitive nature of the data involved. Companies in similar industries should take this event as a wake-up call to bolster their cybersecurity measures and prepare for potential attacks. The full extent of the damage and the specific data compromised is still under investigation.