Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Researchers from ReliaQuest have discovered that attackers are using a combination of open-source tools, specifically ClickFix and PySoxy, to maintain persistent access to compromised systems after an initial social engineering attack. This method allows them to bypass traditional security measures and maintain control over their targets. The findings highlight how attackers are increasingly leveraging readily available tools to extend their foothold within networks, making it harder for organizations to detect and respond to breaches. Companies need to be aware of these tactics and strengthen their defenses against social engineering and the use of such tools. It's essential for organizations to continuously monitor their systems and educate employees about potential phishing attacks.

Read Original

A group identified as TeamPCP has been linked to a series of supply chain attacks that have affected several popular software packages, including those from TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI. These attacks involved modifying npm and PyPI packages to include a hidden JavaScript file named 'router_init.js', which is designed to gather information about how the software is executed. This kind of attack can significantly impact users, as it compromises the integrity of software dependencies that many developers rely on. The obfuscation of the malicious code makes it difficult for users to detect the threat. As this campaign unfolds, developers and users of the affected packages should remain vigilant and consider reviewing their dependencies to ensure they are not using compromised versions.

Read Original

A recent supply-chain attack, dubbed Shai-Hulud, has compromised hundreds of packages on npm and PyPI, delivering malware designed to steal user credentials from developers. The malicious packages include those named TanStack and Mistral, which were likely added to the repositories without proper scrutiny. This incident raises significant concerns for developers who rely on these platforms for trusted packages and could lead to unauthorized access to sensitive information. Users of these compromised packages are urged to take immediate action to secure their systems and check for any unauthorized access. The attack highlights the ongoing vulnerabilities within software supply chains and the need for enhanced security measures by developers and organizations alike.

Read Original

A new worm, dubbed Mini Shai-Hulud, has infected hundreds of npm packages linked to the TanStack open-source ecosystem. This self-propagating worm is designed to steal user credentials, posing a significant risk to developers and organizations using these packages. The infections can spread rapidly, potentially compromising numerous projects that rely on these npm packages. Given the widespread use of npm in JavaScript development, this incident raises concerns about supply chain security and the need for vigilance among developers. Users of affected packages should take immediate steps to secure their systems and monitor for unusual activity.

Read Original
Copy.Fail Linux Vulnerability

Schneier on Security

A newly disclosed Linux vulnerability, dubbed 'copy.fail', poses a serious risk across multiple distributions, including Ubuntu, RHEL, Debian, SUSE, Amazon Linux, and Fedora. Revealed by Theori on April 29, 2026, this local privilege escalation flaw allows attackers to manipulate the Linux kernel's crypto API to write unauthorized data into the page cache of files they do not own. Importantly, the exploit does not modify files on disk, making it difficult for traditional monitoring tools like AIDE and Tripwire to detect. This vulnerability is concerning because it affects a wide range of systems without requiring any specific modifications for different distributions. Organizations using these Linux variants should prioritize assessing their security posture and applying necessary mitigations to protect against potential exploitation.

Read Original

A recent supply chain attack known as the Mini Shai-Hulud campaign has resulted in the release of over 400 malicious versions of 170 software packages. Companies like TanStack, Mistral AI, and UiPath have been affected by this incident. Researchers have noted that the attack targets developers by compromising popular package repositories, which could lead to the distribution of malware to unsuspecting users. This incident is concerning as it highlights the vulnerabilities in the software supply chain and raises alarms for organizations relying on third-party packages for their development processes. Companies must take immediate action to audit their dependencies and ensure they are using secure versions of software packages.

Read Original
Actively Exploited

Researchers from HiddenLayer have discovered a malicious repository on Hugging Face that contains an infostealer malware. This malware is designed to harvest sensitive information from users' systems, particularly targeting credentials and private data. The repository falsely mimics legitimate projects associated with OpenAI, tricking unsuspecting developers into downloading it. Users who have interacted with this repository may be at risk of data theft, underscoring the need for vigilance when downloading code from online repositories. The incident serves as a reminder for developers to verify the authenticity of resources before use, as attackers increasingly employ typosquatting techniques to compromise systems.

Read Original

Instructure, the company known for the Canvas learning management system, has struck a deal with the ShinyHunters extortion group to stop the leaked data from being published online. This arrangement comes after a recent data breach where sensitive information was compromised. While specific details about the stolen data have not been disclosed, the agreement aims to protect users and educational institutions that rely on Canvas for their online learning needs. This incident raises concerns about data security in educational technology, highlighting the ongoing risks that organizations face from cybercriminals. It serves as a reminder for companies to strengthen their cybersecurity measures to prevent future breaches.

Read Original

South Staffordshire Water has been fined nearly £1 million by the Information Commissioner's Office (ICO) due to multiple data protection violations. The breaches stemmed from inadequate security measures that allowed unauthorized access to customer data, affecting thousands of individuals. This incident raises concerns about how utility companies manage sensitive customer information and the consequences of failing to protect that data. The fine serves as a reminder to organizations about the importance of maintaining robust data security practices to safeguard user privacy. With increasing scrutiny on data protection, companies must prioritize compliance to avoid similar penalties in the future.

Read Original

Instructure, the company behind the educational platform Canvas, has come to an agreement with the cybercrime group ShinyHunters after they breached Instructure's network. The attackers threatened to leak 3.65TB of sensitive information, which includes data from thousands of schools and universities. Instructure announced the agreement in an update, although specifics of the deal were not disclosed. This incident raises concerns about the security of educational institutions and the potential exposure of student and faculty information. The breach highlights the vulnerabilities that many organizations face in safeguarding their networks against cyber threats.

Read Original

Kaspersky researchers have identified key trends in ransomware for 2026, indicating a shift in tactics among cybercriminals. One notable trend is the emergence of EDR killers, tools designed to bypass endpoint detection and response systems, making it easier for attackers to operate undetected. Additionally, there is a growing focus on data leaks rather than just data encryption, meaning that attackers might threaten to expose sensitive information instead of simply locking it away. This change could lead to increased pressure on organizations to comply with ransom demands, as the risk of public exposure rises. These trends are significant as they suggest that companies will need to adapt their security strategies to combat evolving ransomware tactics effectively.

Read Original

In May 2026, a significant update was released, addressing 130 Common Vulnerabilities and Exposures (CVEs), including 30 classified as critical. These vulnerabilities impact various software and systems, potentially affecting millions of users and organizations. Notably, the update includes patches for several widely-used products, emphasizing the urgent need for companies to apply these updates to protect their systems from potential exploitation. Researchers warn that failure to address these vulnerabilities could lead to serious security breaches, as attackers often target systems that have not been updated. Users and IT departments should prioritize these patches to enhance their cybersecurity posture and mitigate risks associated with the newly disclosed vulnerabilities.

Read Original

Instructure, the company behind the Canvas learning management system, faced a serious incident when the cybercrime group ShinyHunters threatened to leak sensitive data from over 8,800 school systems. The attackers had stolen information including personal data from students and educators, putting many institutions at risk. After an intense standoff, Instructure claims that the hackers returned the stolen data, but the situation raises significant concerns about data security in educational environments. This incident highlights the vulnerabilities that many schools face, particularly as they increasingly rely on digital platforms for learning. The return of the data does not erase the potential harm done, as affected institutions must now assess their security measures to prevent future breaches.

Read Original

A security researcher has introduced a tool called GhostLock that exploits a legitimate Windows file API to prevent access to files on local systems and SMB network shares. This proof-of-concept tool demonstrates how attackers could potentially block users from accessing important files, which could lead to significant disruptions in both personal and organizational environments. The ability to manipulate file access raises concerns for businesses relying on shared network drives and highlights the need for improved security measures to protect against such attacks. As this tool becomes known, companies and users alike may need to reassess their file access protocols and security practices to mitigate risks. The implications of this vulnerability could affect a wide range of Windows systems and applications that utilize the Windows file API.

Read Original
Actively Exploited

The article discusses the limitations of technical security measures in preventing cyber attacks, emphasizing that employees often serve as the first line of defense. It outlines four specific types of attacks that target human vulnerabilities, such as phishing and social engineering. These attacks exploit the trust and behavior of employees rather than technical flaws in systems. This highlights the need for companies to invest in training and awareness programs for their staff to recognize and respond to potential threats effectively. As cyber threats continue to evolve, a well-informed workforce is crucial for enhancing overall security.

Read Original
PreviousPage 176 of 370Next