Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

30,000 Korean Air Employee Records Stolen as Cl0p Leaks Data Online

Hackread – Cybersecurity News, Data Breaches, AI, and More

Actively Exploited

Korean Air has confirmed a significant data breach affecting the personal information of around 30,000 employees. The breach occurred after the Cl0p ransomware group targeted a catering partner that handles sensitive employee data. The leaked information includes names, social security numbers, and other personal details, raising concerns about identity theft and privacy violations. In response to the incident, Korean Air is taking steps to enhance their data security measures and protect their staff's information. This incident serves as a reminder of the vulnerabilities that companies face when working with third-party vendors.

Impact: Korean Air employee records, catering partner data
Remediation: Korean Air is enhancing data security measures; specific steps not detailed.
Read Original

IBM has issued a warning about a serious authentication bypass vulnerability in its API Connect platform. This flaw could allow attackers to gain unauthorized access to applications remotely, putting sensitive data at risk. Businesses using this enterprise tool should prioritize applying the necessary patches to safeguard their systems. The vulnerability affects various versions of the API Connect platform, making it critical for companies to act swiftly to prevent potential breaches. Ignoring this issue could lead to significant security incidents and data compromises.

Impact: IBM API Connect enterprise platform
Remediation: Customers are urged to apply the latest patches provided by IBM to mitigate the vulnerability.
Read Original

The European Space Agency (ESA) has confirmed a security breach that affected its external science servers. The incident came to light after a hacker attempted to sell stolen data from these servers. While the ESA is currently investigating the breach, details about the extent of the data compromised have not been fully disclosed. This incident raises concerns about the security of sensitive scientific data and the potential implications for ongoing research and collaboration within the space sector. The breach highlights the increasing vulnerability of even highly specialized organizations to cyberattacks, underscoring the need for robust cybersecurity measures.

Impact: European Space Agency external science servers
Remediation: N/A
Read Original

A serious vulnerability known as MongoBleed (CVE-2025-14847) was disclosed shortly after Christmas 2023, allowing attackers to remotely access and leak memory from unpatched MongoDB servers using zlib compression, without requiring any authentication. This flaw primarily affects deployments of MongoDB Server that utilize zlib network compression, a common feature in many setups. The vulnerability is significant because it exposes sensitive data stored in these databases, potentially impacting organizations across the U.S., China, and the EU. Cybersecurity experts are urging companies that use MongoDB to assess their systems for this vulnerability and apply necessary updates or patches to protect against exploitation. The situation highlights ongoing security challenges in the management of popular open-source database systems.

Impact: MongoDB Server deployments using zlib network compression
Remediation: Organizations should immediately patch their MongoDB servers to the latest version that addresses this vulnerability. Additionally, disabling zlib compression on affected servers can mitigate the risk until a patch is applied. Regular security audits and updates are recommended to ensure all systems remain secure.
Read Original

The U.S. Treasury's Office of Foreign Assets Control (OFAC) has lifted sanctions on three individuals associated with the Intellexa Consortium, which is known for its commercial spyware called Predator. The individuals include Merom Harpaz, Andrea Nicola Constantino, Hermes Gambazzi, and Sara Aleksandra Fayssal Hamou. This decision raises concerns about the potential implications for privacy and surveillance, as Predator spyware has been linked to various abuses in tracking and monitoring individuals. The removal of sanctions could allow these individuals greater access to resources and networks, which may impact ongoing discussions about the regulation of spyware and its use by governments and private entities. This development is particularly significant given the rising scrutiny of surveillance technologies worldwide.

Impact: Predator spyware
Remediation: N/A
Read Original

Ransomware attacks are becoming more frequent and sophisticated, posing significant risks to organizations. A recent report by Semperis indicates that over half of the companies that faced ransomware incidents in the past year were targeted during weekends or holidays, when fewer employees are monitoring systems. This trend suggests that attackers are exploiting times of reduced vigilance to infiltrate networks. Additionally, advancements in AI are enabling more complex attacks, further complicating defenses. As these threats evolve, organizations need to be more proactive in their cybersecurity measures to protect sensitive data and ensure business continuity.

Impact: N/A
Remediation: Organizations should enhance monitoring during weekends and holidays, invest in AI-driven security tools, and conduct regular cybersecurity training for staff.
Read Original

The European Space Agency (ESA) has reported a breach involving external servers that contained unclassified information related to collaborative engineering efforts. While the data accessed was not classified, the incident raises concerns about the security of sensitive information even when labeled as unclassified. The breach emphasizes the importance of securing all types of data, as attackers can exploit vulnerabilities in external systems. ESA has not specified the exact nature of the attack or the extent of the data accessed, but it is a reminder for organizations to review their cybersecurity measures, especially regarding external servers. This incident could potentially affect partnerships and collaborative projects within the space sector, highlighting the need for robust security protocols.

Impact: External servers of the European Space Agency containing unclassified engineering information
Remediation: N/A
Read Original

Researchers have identified a campaign dubbed 'Zoom Stealer' that targets users of popular web browsers, specifically Chrome, Firefox, and Microsoft Edge. This attack has already impacted around 2.2 million users through 18 malicious browser extensions. These extensions are designed to gather sensitive information related to online meetings, including URLs, IDs, topics, descriptions, and even embedded passwords. The implications of this data theft are significant, as it can lead to unauthorized access to corporate meetings and sensitive discussions. Companies using these browsers should be vigilant and consider removing any unverified extensions to protect their data.

Impact: Chrome, Firefox, Microsoft Edge users; 18 malicious browser extensions
Remediation: Users should remove any suspicious or unverified browser extensions and ensure their browsers are updated to the latest versions.
Read Original

OpenAI has raised concerns about prompt injection, a method where attackers embed harmful instructions within seemingly harmless online content. This type of security risk poses a particular threat to AI agents like ChatGPT Atlas, which are designed to function in web browsers and assist users with various tasks. The company recently implemented a security update for Atlas following internal testing that revealed vulnerabilities. OpenAI cautions that due to the nature of web content, prompt injection may never be fully resolved, leaving users at risk. As AI tools become more integrated into everyday online activities, the potential for exploitation through this technique highlights ongoing challenges in securing AI systems against sophisticated attacks.

Impact: ChatGPT Atlas, OpenAI AI agents
Remediation: Security update for ChatGPT Atlas has been implemented
Read Original
Actively Exploited

Scammers are using artificial intelligence to create realistic images of damaged products to fraudulently obtain refunds. This tactic involves generating images that appear to show broken or defective items, which the scammers then submit to retailers as proof of purchase. This fraudulent activity poses a risk to online retailers and consumers alike, as it could lead to financial losses and increased prices for legitimate buyers. Retailers may need to enhance their verification processes to combat this type of scam, ensuring they can distinguish between genuine claims and fraudulent ones. As AI technology becomes more accessible, such scams could become more prevalent, highlighting the need for vigilance in online transactions.

Impact: Online retailers, consumers
Remediation: Retailers should enhance verification processes for refund claims and consider implementing AI detection tools to identify fraudulent images.
Read Original

The cybercriminal group known as Silver Fox has recently shifted its focus to Indian users, employing income tax-themed phishing emails to spread a remote access trojan called ValleyRAT. This malware is designed to give attackers remote control over infected systems. Researchers from CloudSEK, Prajwal Awasthi and Koushik Pal, noted that the attack utilizes a sophisticated method involving DLL hijacking to ensure the malware remains persistent on the target devices. Users in India should be particularly cautious of emails related to taxes, as they are being used as bait to deliver this malicious software. The rise in such targeted phishing campaigns emphasizes the need for increased awareness and cybersecurity measures among individuals and organizations.

Impact: ValleyRAT malware, phishing emails targeting Indian users
Remediation: Users should be wary of suspicious emails, especially those related to income tax, and ensure their antivirus software is up to date. It's advisable to employ email filtering solutions and conduct regular security awareness training.
Read Original

Researchers have identified a new tactic used by the Chinese advanced persistent threat group, Mustang Panda, involving a kernel-mode rootkit. This rootkit utilizes a signed driver file that contains two user-mode shellcodes to deploy the ToneShell backdoor. This method allows the attackers to gain deeper access to the victim's systems, making detection more difficult. Organizations should be aware of this sophisticated technique, as it poses significant risks to data integrity and security. Protecting systems against such advanced threats is crucial for maintaining cybersecurity hygiene.

Impact: Windows operating systems, specifically those vulnerable to kernel-mode attacks
Remediation: Implement security patches for affected Windows systems, monitor for unusual activity, and consider endpoint detection solutions to identify rootkit behavior.
Read Original

Recent findings from Veza reveal that companies are struggling to manage a rapidly expanding identity attack surface. The number of permissions—essentially access rights for users—has grown at a pace that outstrips the ability of security teams to monitor them. Veza's data shows over 230 billion permissions are currently in use, creating significant blind spots in security oversight. This situation poses a risk as enterprises attempt to manage access requests and audits with inadequate visibility into who can do what within their systems. As non-human identities, such as bots and automated processes, become more prevalent, the challenges around identity security are intensifying, making it crucial for organizations to rethink their access management strategies.

Impact: N/A
Remediation: Companies should enhance their identity management systems to improve visibility and control over permissions.
Read Original

Sax, a major US accounting firm, has revealed a data breach that has affected around 220,000 individuals. The breach was detected over a year ago, but the firm took considerable time to investigate the incident thoroughly. While specific details about how the breach occurred have not been disclosed, it raises significant concerns about the security of sensitive financial information. Affected individuals may need to monitor their accounts closely for any signs of unauthorized activity. This incident highlights the ongoing vulnerability of even well-established firms in protecting client data against cyber threats.

Impact: Personal data of approximately 220,000 individuals, including financial information.
Remediation: N/A
Read Original

Korean Air reported a data breach linked to a cyberattack on its catering and duty-free supplier, KC&D. This incident has compromised the personal information of approximately 30,000 employees. The breach originated from KC&D, which provides in-flight catering services and operates a duty-free shop for Korean Air. As a result, sensitive data, likely including names and possibly other personal details, may be at risk. This incident raises concerns about the security of third-party vendors and the potential for further exploitation of the leaked data.

Impact: Personal data of approximately 30,000 Korean Air employees
Remediation: Korean Air and KC&D are likely reviewing their security measures and may implement stricter access controls and monitoring; specific remediation steps were not disclosed.
Read Original
PreviousPage 178 of 219Next