Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A serious vulnerability has been found in Forminator Forms, a popular WordPress plugin with over 600,000 installations. This flaw, identified as CVE-2026-15748 and rated 9.8 out of 10 on the CVSS scale, allows attackers to execute arbitrary code on affected websites without authentication. Discovered by a security researcher, this issue poses a significant risk as it could enable malicious users to upload harmful PHP files, compromising the security of the sites. Website owners using this plugin should be particularly vigilant, as the potential for exploitation is high. Immediate action is necessary to protect their systems and data.

Read Original

SafePal has reported a data breach that has impacted the personal information of 39,798 customers. The breach occurred due to a flaw in its order-tracking plugin, allowing hackers to access data related to orders placed between March 2, 2025, and April 11, 2026. Importantly, the breach did not compromise sensitive wallet credentials, private keys, seed phrases, or payment information, which may provide some reassurance to users. This incident raises concerns about the security of customer data in online services and highlights the need for companies to regularly update and monitor their plugins for vulnerabilities. Customers affected by this breach should remain vigilant and consider changing their account details as a precautionary measure.

Read Original

The LiteLLM supply-chain attack, linked to a malware known as 'SANDCLOCK,' has compromised credentials in over 2,000 code repositories, significantly impacting sectors such as technology, banking, healthcare, and retail. Researchers from Resecurity estimate that this breach has caused serious security concerns across these industries, as the backdoor allows attackers to manipulate or access sensitive data. The attack's implications are expected to linger, raising alarms about the security of software supply chains. Companies in the affected sectors are urged to assess their security measures and update their systems to prevent further exploitation. The depth of this breach underscores the vulnerabilities inherent in code repositories used by many organizations today.

Read Original

A vulnerability in UNISOC modems has been identified that allows remote code execution through video calls. This security flaw could potentially let attackers execute malicious code on devices using these modems, posing a significant risk to users. The issue affects a range of devices that incorporate UNISOC's technology, which is commonly found in smartphones and IoT devices. Given the widespread use of video calling, the implications of this vulnerability are serious, as it could lead to unauthorized access to sensitive information and control over affected devices. Users and manufacturers need to take immediate action to address this vulnerability to protect their devices from potential exploitation.

Read Original

The Evooo1Bot is a new Linux botnet that significantly enhances the capabilities of the existing Mirai botnet. Researchers found that Evooo1Bot is not just focused on launching DDoS attacks; it also includes modules for exploiting vulnerabilities, stealing credentials, and creating reverse SOCKS relays. This means that compromised devices can be used for more than just overwhelming targets with traffic; they can serve as a persistent infrastructure for attackers. The expansion of these capabilities poses a serious risk to users and organizations, as it increases the potential for data theft and ongoing exploitation. Security professionals need to be vigilant about the devices on their networks to prevent becoming part of this botnet.

Read Original

A recently discovered vulnerability, identified as CVE-2026-54121, poses a serious risk to organizations using Enterprise Certificate Authorities (CAs). This flaw allows a standard domain user to escalate their privileges, effectively turning the Enterprise CA into a Domain Controller. This situation can lead to unauthorized access and control over sensitive resources within the network. Organizations need to treat their Public Key Infrastructure (PKI) as a critical part of their security framework, as it plays a vital role in identity management. The importance of addressing this vulnerability cannot be overstated, as it highlights the need for stringent security measures around privileged accounts and trust relationships within IT environments. Patching is essential to mitigate this risk.

Read Original

Fortinet has acquired Virtue AI to enhance its security offerings related to artificial intelligence. This move is part of Fortinet's strategy to address the expanding security needs as organizations increasingly deploy AI applications and autonomous agents. With this acquisition, Fortinet aims to protect against new vulnerabilities that arise from these technologies, which now include various AI components such as prompts, models, and APIs. As businesses adopt AI, their security measures must evolve to cover not just traditional IT infrastructure but also the unique risks associated with AI systems. This acquisition signifies Fortinet's commitment to staying ahead in the rapidly changing cybersecurity landscape.

Read Original
Actively Exploited

A serious vulnerability has been discovered in the User Profile Builder plugin for WordPress, affecting around 40,000 websites. This flaw allows unauthenticated attackers to gain access to administrator accounts, potentially giving them control over the entire site. The issue is particularly concerning because it does not require any prior authentication, making it easier for malicious actors to exploit. Website owners using this plugin should take immediate action to secure their sites and prevent unauthorized access. Without quick remediation, these sites remain at risk of being compromised, which can lead to data breaches and other security incidents.

Read Original

Hackers are exploiting a recently patched vulnerability in macOS, known as CVE-2026-65400, which allows unauthorized access to the macOS Screen Sharing feature. This flaw enables attackers to bypass authentication and gain root access to affected systems, leading to the installation of cryptominers without user consent. The Netherlands’ National Cyber Security Centre has issued a warning about this active exploitation, emphasizing the need for users to update their systems. Apple has released patches for macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1) to address this issue, urging all macOS users to upgrade promptly to protect their devices. Failure to do so could leave systems vulnerable to further attacks and unauthorized resource usage.

Read Original

A recent incident involving Anthropic AI models has raised concerns about a naming error that allowed these models to target a real company. According to an AI security testing firm, the misnaming led to vulnerabilities that were exploited, potentially exposing sensitive information or causing disruptions. This incident serves as a critical reminder for companies to ensure that AI systems are thoroughly vetted for security flaws before deployment. The implications of such errors can be significant, particularly as AI models become more integrated into business operations. Companies using AI technologies should be vigilant about their security practices and consider potential risks associated with naming conventions and model training.

Read Original
Actively Exploited

CISA has added a new vulnerability, CVE-2025-62593, related to code injection in the Ray-Project, to its Known Exploited Vulnerabilities Catalog. This vulnerability is currently being exploited, posing a significant risk to federal agencies and potentially impacting organizations that utilize the Ray framework. Under the Binding Operational Directive 26-04, federal agencies are required to prioritize fixing high-risk vulnerabilities, like this one, especially on systems that could give attackers complete control post-exploitation. CISA encourages all organizations, not just federal ones, to adopt similar risk-based vulnerability management practices to enhance their security posture. If anyone is aware of other exploited vulnerabilities not listed in the catalog, they can submit them for consideration through CISA's nomination form.

Read Original

MCP servers can pose significant risks to organizations by exposing sensitive data through vulnerabilities like plaintext configuration files and excessive permissions. These weaknesses often go unnoticed by security teams, especially as AI agents become more integrated into enterprise systems. The Model Context Protocol (MCP) enables these AI agents to access various tools and data, increasing the likelihood of data leaks. Companies that implement MCP servers need to be aware of these risks and take proactive measures to secure their configurations and access controls. As the use of AI expands, the potential for security gaps in MCP servers could lead to serious breaches if not addressed promptly.

Read Original

General Electric (GE) and Philips are currently investigating claims that their systems were breached by the Clop ransomware gang, which allegedly stole sensitive data. Both companies have confirmed they are looking into these claims, but specific details about the stolen data or the extent of the breach have not been disclosed. This incident raises concerns about the security of critical infrastructure, particularly given the significant roles both GE and Philips play in healthcare and technology sectors. If the allegations are confirmed, it could have serious implications for patient privacy and operational integrity. The situation is still developing as both companies work to determine the full impact of the breach.

Read Original
Actively Exploited

Criminals are targeting public Wi-Fi networks in places like hotels and conference centers by hacking into their devices and altering DNS settings. This manipulation redirects users trying to access legitimate websites to fake login pages designed to capture their usernames and passwords. As more people connect to public Wi-Fi for convenience, they risk falling victim to this type of attack, which can lead to identity theft and unauthorized access to personal accounts. Users should be cautious when entering credentials on public networks and consider using a virtual private network (VPN) to protect their data. This issue underscores the need for better security practices in public internet access points to safeguard users' information.

Read Original

The European Telecommunications Standards Institute (ETSI) is moving forward with a new initiative under the Cyber Resilience Act, proposing 17 cybersecurity standards that vendors will be required to meet. This approval process aims to enhance the security and resilience of digital products and services across Europe. By establishing clear standards, ETSI seeks to address growing concerns about cybersecurity threats and ensure that companies implement adequate protections. This initiative is significant as it sets a framework for accountability in cybersecurity, potentially impacting a wide range of industries that depend on technology. The move comes at a time when cyber attacks are increasingly common, making it essential for organizations to prioritize security measures.

Read Original
PreviousPage 18 of 363Next