Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A data breach affecting nearly 197,000 Zara customers has been linked to a cyberattack on a former technology provider, ShinyHunters. The breach exposed sensitive customer information, including emails, purchase history, and support data. This incident raises concerns about the security measures in place at third-party vendors that companies rely on. Customers whose data was compromised may face increased risks of phishing attempts and identity theft. As major retailers like Zara continue to rely on external partners, ensuring robust security practices across their supply chain becomes increasingly critical.

Read Original

A group known as ShinyHunters has claimed responsibility for a data breach affecting Canvas, a learning management system used by schools across the United States. They allege that they have obtained personal data from nearly 9,000 educational institutions, which could include sensitive information about students and staff. The potential release of this data poses significant risks, as it could lead to identity theft and other forms of exploitation. The incident raises concerns about the security measures in place to protect educational data, highlighting the need for institutions to enhance their cybersecurity protocols. As the situation develops, affected schools may need to inform their communities and take steps to mitigate the impact of this breach.

Read Original

The RansomHouse hacking group has claimed responsibility for a breach of Trellix's source code repository, revealing a small set of images as proof of the attack. This incident raises concerns about the security of Trellix's products and the potential exposure of sensitive information. With the source code compromised, attackers could exploit vulnerabilities or develop attacks against Trellix's software. The breach not only affects Trellix but also poses risks to its users, who may be at increased risk of cyberattacks. As the situation develops, it is crucial for Trellix and its customers to take immediate steps to assess their security posture and mitigate any potential fallout from the breach.

Read Original

The article discusses a common misconception in cybersecurity where organizations mistake vulnerability scanning for penetration testing. A survey by the SANS Institute found that over 60% of organizations confuse these two distinct practices. Vulnerability scanning involves identifying potential security weaknesses, while penetration testing simulates real-world attacks to exploit those vulnerabilities. This distinction is crucial for Chief Information Security Officers (CISOs) as reliance on scanning alone can leave organizations exposed to risks that a comprehensive penetration test would reveal. Understanding the difference can help improve security postures and better allocate resources to protect sensitive data.

Read Original

CISA, the U.S. Cybersecurity and Infrastructure Security Agency, has issued an urgent notice to federal agencies to address a serious vulnerability in Ivanti Endpoint Manager Mobile (EPMM). This flaw has been exploited in zero-day attacks, meaning attackers have already taken advantage of it before a fix was available. Federal agencies have just four days to patch their systems to prevent potential breaches. The vulnerability poses a significant risk as it could allow unauthorized access to sensitive information. Agencies using Ivanti EPMM need to act quickly to secure their networks and protect against these exploits.

Read Original

The Polish Security Agency has reported that hackers breached the industrial control systems (ICS) at five water treatment plants. These intrusions allowed attackers to modify the operational parameters of critical equipment, posing a direct threat to the safety of the public water supply. This situation raises serious concerns about the security of essential infrastructure and the potential for public health risks. Authorities are likely to investigate further to understand the extent of the breaches and to implement stronger security measures. The incident emphasizes the need for improved cybersecurity protocols in vital services that impact daily life.

Read Original
Actively Exploited

The Australian Cyber Security Centre (ACSC) has issued a warning about a malicious campaign that targets organizations using ClickFix, a tool that is being exploited to deliver Vidar infostealer malware. This malware is designed to steal sensitive information, including personal data and credentials. Organizations that utilize ClickFix should be particularly vigilant as the attackers are actively using this method to compromise systems. This situation poses a significant risk to data security and privacy, as the stolen information can lead to further attacks or identity theft. Companies are urged to review their security measures and stay updated on potential threats to safeguard their operations.

Read Original

A cyberattack has taken down the Canvas system, a widely used platform for online learning by thousands of schools and universities. This disruption comes at a particularly challenging time as students prepare for their final exams, leading to significant chaos and frustration. The attack has affected access to course materials, assignments, and other essential resources, making it difficult for students to study effectively. As educational institutions increasingly rely on digital platforms, incidents like this raise concerns about the security measures in place to protect sensitive academic data and ensure continuity of learning. Schools are now scrambling to address the situation as finals approach, highlighting the need for stronger cybersecurity protocols in the education sector.

Read Original

Zara, the popular fast-fashion retailer, has suffered a data breach that compromised the personal information of over 197,000 customers. According to Have I Been Pwned, hackers accessed the company’s databases, leading to concerns about the potential misuse of sensitive customer data. The breach raises significant alarm as it could expose customers to identity theft and fraud. Affected individuals may need to monitor their accounts closely and consider taking additional security measures to protect their information. This incident serves as a reminder for companies to strengthen their cybersecurity protocols to prevent future breaches.

Read Original

A recent report analyzing over 25 million security alerts from enterprise environments reveals a troubling trend: organizations are overlooking many low-severity threats. These findings indicate that defenders may be institutionalizing a practice of ignoring less critical alerts, which could leave them vulnerable to potential attacks. The dataset included 10 million monitored alerts, suggesting a significant gap in how companies assess and respond to security risks. This lack of attention to low-severity alerts could lead to missed opportunities for early threat detection and response. As organizations increasingly rely on automated systems for security monitoring, it’s crucial they maintain vigilance over all threat levels to protect their networks effectively.

Read Original

Two U.S. citizens, Matthew Issac Knoot and Erick Ntekereze Prince, have been sentenced to 18 months in prison for their involvement in operating 'laptop farms' that facilitated North Korean IT workers in securing jobs at nearly 70 American companies. These operations reportedly generated over $1.2 million for the North Korean government, which is under strict sanctions due to its nuclear program and other criminal activities. The men were found guilty in separate cases of aiding North Korea in exploiting the U.S. job market, which raises significant national security concerns. This incident underscores the potential risks associated with remote work arrangements and highlights the need for companies to be vigilant against illicit activities that could undermine economic and security interests. The case serves as a warning that similar schemes could lead to serious legal consequences for individuals and businesses involved.

Read Original

The PCPJack campaign appears to be linked to a former member of a hacking group known as TeamPCP. SentinelOne, a cybersecurity firm, has suggested that this campaign is an effort to remove TeamPCP from compromised machines. While details about the specific methods and targets of this campaign are still emerging, the involvement of a former insider raises concerns about insider threats and the potential for further breaches. This incident highlights the ongoing risks associated with hacking groups and underscores the need for organizations to remain vigilant in monitoring their systems for unusual activity and potential insider threats.

Read Original

A 34-year-old man from Virginia has been convicted for conspiring to erase numerous federal databases after being fired from his position as a government contractor. Prosecutors stated that the individual intentionally destroyed data from at least 33 databases, which were critical to various federal agencies. This act of sabotage not only endangered government operations but also posed significant risks to data integrity and availability. The incident raises concerns about insider threats within federal agencies and the potential for disgruntled employees to compromise sensitive information. Sentencing is expected to take place in the coming months, underlining the serious legal repercussions for such actions.

Read Original

A new malware called 'PCPJack' has emerged, specifically designed to target web applications and cloud environments, such as AWS, Docker, and Kubernetes. This worm not only removes existing infections from a group known as TeamPCP but also steals user credentials. The dual functionality makes it particularly dangerous as it can both cleanse systems of one threat while introducing a new one. Organizations utilizing these cloud services should be vigilant and assess their security measures to prevent unauthorized access and data breaches. The presence of such malware underscores the need for continuous monitoring and robust security practices in cloud environments.

Read Original
CVE-2025-68670: discovering an RCE vulnerability in xrdp

Securelist

Researchers conducting a security assessment of Kaspersky USB Redirector discovered a critical remote code execution (RCE) vulnerability in the xrdp server component, identified as CVE-2025-68670. This vulnerability allows attackers to execute arbitrary code on affected systems before authentication, which poses a significant risk. Fortunately, project maintainers acted quickly to patch the vulnerability, reducing the potential for exploitation. Users of xrdp should ensure they apply the latest updates to protect their systems. This incident underscores the importance of regular security assessments and timely patch management to defend against emerging threats.

Read Original
PreviousPage 180 of 370Next