Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

On December 26, 2023, the Oltenia Energy Complex, Romania's largest coal-based energy producer, fell victim to a ransomware attack attributed to the Gentlemen ransomware group. The attack severely disrupted the company's IT infrastructure, impacting its ability to operate effectively. Although specific details about the extent of the damage or data breaches have not been disclosed, the incident raises concerns about the vulnerability of critical infrastructure to cyber threats. As energy providers are essential for public services, such attacks can significantly affect energy supply and operational stability. Authorities and cybersecurity experts are likely to investigate the incident further to understand its implications and improve defenses against similar attacks in the future.

Impact: Oltenia Energy Complex IT infrastructure
Remediation: N/A
Read Original

A former customer support agent at Coinbase has been arrested in India after allegedly assisting hackers in stealing sensitive customer data from the company's database. The individual reportedly provided login credentials and other confidential information, which allowed the hackers to access customer accounts. This incident raises concerns about insider threats within companies that handle sensitive financial information. Coinbase, a major cryptocurrency exchange, is now facing scrutiny regarding its internal security measures and employee vetting processes. The breach could undermine customer trust and highlights the importance of robust security protocols to protect user data from both external and internal threats.

Impact: Coinbase customer database, customer accounts
Remediation: N/A
Read Original
Actively Exploited

In 2025, several significant cybersecurity threats emerged, most notably the global attacks attributed to a group known as Salt Typhoon. These attacks targeted multiple sectors, causing widespread concern among businesses and government agencies alike. Additionally, the discovery of a vulnerability named React2Shell raised alarms due to its potential impact on systems using React framework, which is widely adopted in web development. Researchers emphasized that this vulnerability could allow attackers to execute arbitrary code, putting countless applications at risk. Organizations are urged to review their security measures and apply necessary updates to safeguard against these evolving threats.

Impact: React framework applications, various organizations targeted by Salt Typhoon
Remediation: Apply security patches for React framework; enhance monitoring and incident response plans for organizations targeted by Salt Typhoon.
Read Original

Korean Air has reported a data breach that has compromised the personal information of thousands of its employees. The incident occurred due to a cyberattack on Korean Air Catering & Duty-Free (KC&D), a supplier that was previously a subsidiary of the airline. While the exact details of the data exposed have not been disclosed, such breaches can lead to serious privacy risks for those affected. This incident raises concerns about the security measures in place at third-party vendors and the potential ripple effects on employee trust and company reputation. As companies increasingly rely on external partners, ensuring robust cybersecurity across the supply chain is crucial.

Impact: Korean Air employees' personal data, including potentially sensitive information.
Remediation: N/A
Read Original

Fortinet has issued a warning about ongoing attacks that exploit an old vulnerability in its FortiOS software, identified as CVE-2020-12812. This flaw allows attackers to bypass two-factor authentication, which can significantly compromise the security of affected systems. Organizations using FortiOS should be particularly vigilant, as this vulnerability has resurfaced in active attacks. The potential for unauthorized access puts sensitive data at risk, making it critical for users to address this issue promptly. Cybersecurity teams are urged to review their systems and implement necessary updates to safeguard against these threats.

Impact: FortiOS versions that are vulnerable to CVE-2020-12812, particularly those configured with two-factor authentication.
Remediation: Users should apply the latest patches for FortiOS as provided by Fortinet. It is also recommended to review and strengthen two-factor authentication configurations and monitor system access logs for any suspicious activities.
Read Original
Critical 0day flaw Exposes 70k XSpeeder Devices as Vendor Ignores Alert

Hackread – Cybersecurity News, Data Breaches, AI, and More

Researchers have identified a critical unpatched vulnerability, designated CVE-2025-54322, in XSpeeder networking devices, which are widely used in industrial and branch environments. Approximately 70,000 devices are affected, leaving them open to potential exploitation. The flaw was discovered by AI agents, but the vendor has not addressed the alert, raising concerns about the security of these devices. This situation poses a significant risk, as attackers could exploit the vulnerability to gain unauthorized access or disrupt operations. Companies using XSpeeder devices should take immediate action to assess their security posture and implement necessary safeguards to protect their networks.

Impact: XSpeeder networking devices, approximately 70,000 units in industrial and branch settings.
Remediation: Companies should evaluate their XSpeeder devices for potential exposure and consider implementing network segmentation and monitoring to mitigate risks. Regularly updating security protocols and reviewing access controls can also help protect against exploitation until a patch is made available.
Read Original

Coupang, a major ecommerce platform, is responding to a significant data breach that has affected approximately 33.7 million users. In an effort to compensate for the breach, the company plans to issue $1.17 billion in purchase vouchers to those impacted. This incident raises concerns about the security of personal data in the ecommerce sector and the potential risks users face when their information is compromised. The breach highlights the ongoing challenges that large online retailers encounter in safeguarding customer data. Users should remain vigilant about their personal information and monitor their accounts for any unusual activity.

Impact: Coupang ecommerce platform, 33.7 million user accounts
Remediation: Issuing purchase vouchers to affected users
Read Original

Fortinet has issued a warning about a vulnerability in FortiOS that has been around for five years but is still being exploited by attackers. This flaw allows unauthorized users to bypass two-factor authentication (2FA) on FortiGate firewalls, which are widely used by organizations to secure their networks. The continued exploitation of this vulnerability poses a significant risk to companies relying on these firewalls, as it can lead to unauthorized access and potential data breaches. Users of FortiGate firewalls are urged to take immediate action to protect their systems by applying available security updates. This situation serves as a reminder of the importance of keeping software up to date and addressing known vulnerabilities promptly.

Impact: FortiGate firewalls running FortiOS
Remediation: Users should apply the latest security patches from Fortinet to mitigate this vulnerability.
Read Original

Kaspersky has reported on a new campaign from the HoneyMyte APT group, also known as Mustang Panda or Bronze President, which has evolved to use a sophisticated kernel-mode rootkit. This rootkit is designed to deploy and secure a backdoor known as ToneShell, which allows attackers to maintain persistent access to compromised systems. The implications of this development are significant, as it enhances the group’s ability to infiltrate networks and evade detection. Organizations need to be vigilant against these advanced tactics to protect sensitive data and maintain system integrity. This campaign highlights the ongoing threats posed by state-sponsored hacking groups and the need for robust cybersecurity measures.

Impact: Kernel-mode rootkit, ToneShell backdoor, potentially various operating systems affected by the rootkit.
Remediation: Organizations should implement advanced endpoint detection and response solutions, regularly update their systems, and conduct thorough security audits to detect and mitigate such threats.
Read Original

A newly discovered vulnerability in MongoDB, referred to as MongoBleed, poses a significant risk by allowing remote attackers to extract sensitive information from affected servers without authentication. This flaw has been exploited in real-world attacks, raising alarms among organizations that utilize MongoDB for their data management. The vulnerability's ability to leak data could expose sensitive customer information, business secrets, and other critical data. Companies using MongoDB should prioritize patching their servers to mitigate potential breaches. It's crucial for users to remain vigilant and ensure their systems are secure against this emerging threat.

Impact: MongoDB servers
Remediation: Organizations should apply security patches provided by MongoDB and follow best practices for securing their databases.
Read Original

A Chinese cyberespionage group known as Evasive Panda has been using a technique called DNS poisoning to install a backdoor known as MgBot on targeted systems in Türkiye, China, and India. Kaspersky researchers identified this campaign, which shows the group's focus on espionage activities against specific entities in these countries. DNS poisoning allows attackers to redirect victims to malicious servers without their knowledge, facilitating the installation of the backdoor. This incident raises concerns about the security of sensitive information, as the MgBot backdoor can provide attackers with ongoing access to compromised systems. Organizations in the affected regions should be vigilant and strengthen their cybersecurity measures to protect against such sophisticated attacks.

Impact: N/A
Remediation: Organizations should implement DNS security measures, monitor for unusual network activity, and ensure systems are updated with the latest security patches.
Read Original

A serious vulnerability in MongoDB, designated as CVE-2025-14847 and known as MongoBleed, is currently being exploited globally. This flaw, which has a CVSS score of 8.7, allows attackers to access sensitive data stored in the server's memory without needing authentication. Researchers have identified over 87,000 instances of MongoDB that could be affected by this issue. The potential for data leakage poses a significant risk to organizations using this database technology, making it critical for them to address the vulnerability promptly. Companies should assess their systems and implement necessary security measures to safeguard against this ongoing threat.

Impact: MongoDB servers, version not specified
Remediation: Organizations should immediately review their MongoDB configurations and apply any available security patches. It is advisable to implement access controls and monitor server activity for any unauthorized access attempts. Users should also consider upgrading to the latest version of MongoDB that addresses this vulnerability.
Read Original

A recent global study by Trellix reveals that enterprise security teams are adapting their strategies to cope with constant disruptions in the cybersecurity landscape. The study indicates that resilience is no longer just a long-term goal but a necessary part of the security framework for Chief Information Security Officers (CISOs). As organizations increasingly adopt hybrid infrastructure—which integrates cloud, on-premises, and isolated systems—they must rethink their operational strategies and infrastructure design. The use of artificial intelligence is also reshaping how companies prepare for ongoing threats and regulatory pressures. This shift towards automation is prompting security teams to reassess their approaches to ensure they can withstand evolving challenges.

Impact: N/A
Remediation: N/A
Read Original

A serious vulnerability known as MongoBleed (CVE-2025-14847) is currently being exploited, exposing over 80,000 MongoDB servers on the public internet. This flaw affects multiple versions of MongoDB, allowing attackers to potentially access sensitive information stored on these servers. The scale of the exposure raises significant security concerns, as many organizations may not be aware that their databases are at risk. Companies using affected MongoDB versions should take immediate action to secure their data and prevent unauthorized access. Failure to address this vulnerability could lead to severe data breaches and loss of sensitive information.

Impact: MongoDB versions affected include all versions with the MongoBleed vulnerability; specific versions are not detailed.
Remediation: Organizations should immediately update to the latest MongoDB version that addresses the MongoBleed vulnerability. Additionally, they should implement strict access controls and monitor their servers for any suspicious activity. Regularly auditing configurations and applying security patches as they become available is also recommended.
Read Original

Condé Nast has reported a significant data breach involving the personal information of 2.3 million subscribers from WIRED.com. The hacker, known as 'Lovely', posted the leaked data on December 20, 2025, on a hacking forum called Breach Stars. In addition to the WIRED records, the hacker claims to have access to data from up to 40 million more users associated with other Condé Nast brands. This breach raises serious concerns about the security of personal information held by major publishers and the potential for further exposure of sensitive data. Users affected by this incident may face risks such as identity theft and phishing attacks, emphasizing the need for vigilance in monitoring their accounts and personal information.

Impact: WIRED.com subscriber records, potential data from 40 million additional Condé Nast brand users
Remediation: Users should monitor their accounts for unusual activity, change passwords, and consider using identity theft protection services.
Read Original
PreviousPage 179 of 219Next