RansomHouse, a known ransomware group, has claimed responsibility for a recent breach of Trellix, a cybersecurity company. The group has released screenshots that reportedly show their access to Trellix’s internal services, raising concerns about the security of sensitive information stored by the company. This incident highlights the ongoing risks that cybersecurity firms face, as they are often targeted due to the valuable data they protect. Users and clients of Trellix should remain vigilant about their data security and monitor for any unusual activities. The attack underscores the importance of robust security measures within the cybersecurity sector itself, as breaches can have far-reaching implications for trust and security in the industry.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
A newly discovered zero-day vulnerability in Linux, dubbed Dirty Frag, allows local attackers to gain root access on various major Linux distributions with a single command. This issue affects most users running popular distros, making it a significant concern for system administrators and everyday users alike. Researchers have identified that this vulnerability can be exploited without requiring any special privileges, which further raises the stakes. Given the broad impact, it's crucial for users to be aware of this vulnerability and take appropriate measures to protect their systems. The situation emphasizes the need for prompt updates and vigilance in security practices across the Linux ecosystem.
The Pentagon is advancing its military strategy by integrating artificial intelligence into various operations, including cybersecurity and command systems. By May 2026, this integration is expected to fundamentally change how the military conducts warfare, moving from theoretical concepts to practical applications. This shift suggests that AI will play a crucial role in targeting and operational efficiency, potentially impacting how conflicts are managed on the ground. The development raises important questions about the implications of using AI-driven systems in military contexts, particularly regarding cybersecurity vulnerabilities and ethical considerations. As these technologies become operational, they could reshape the landscape of modern warfare significantly.
A vulnerability has been discovered in the Claude extension for Chrome that could allow attackers to take control of the AI agent. The issue arises from lax permissions and improper implementation of trust, enabling unauthorized prompts to be injected. This could lead to malicious activities being carried out under the guise of the AI agent, potentially affecting users who rely on this extension for their tasks. It's crucial for users of the Claude extension to be aware of this vulnerability and take necessary precautions. Developers need to address these issues promptly to safeguard users against potential exploits.
An independent audit of Roblox's automated chat filter, which processes billions of messages daily, has revealed significant shortcomings in its ability to moderate harmful content. Researchers from the University of Arizona and Arizona State University analyzed around two million chat messages from popular games on the platform, finding that the filter often fails to catch dangerous interactions. This includes instances of grooming, sexual content aimed at minors, threats of violence, and references to self-harm. The use of 'leet speak' and coded language appears to be bypassing the existing moderation systems, raising serious concerns about the safety of young users on the platform. The findings underscore the need for better protective measures to ensure a safer environment for children on Roblox.
The Hacker News
A newly discovered vulnerability, named Dirty Frag, poses a significant local privilege escalation risk within the Linux kernel, affecting several major distributions. This flaw is considered a successor to another serious vulnerability known as Copy Fail (CVE-2026-31431), which has already seen active exploitation. Dirty Frag allows attackers to gain root access on systems running vulnerable kernel versions. The vulnerability was reported to Linux kernel maintainers, but as of now, it remains unpatched. Users of Linux distributions should be aware of this issue and take necessary precautions to secure their systems, especially since it has been linked to ongoing exploitation in the wild.
A significant data extortion attack has hit Canvas, a popular education technology platform used by numerous schools and colleges across the United States. The cybercriminal group responsible for the attack defaced the login page, posting a ransom demand while threatening to expose sensitive information from 275 million students and faculty members at nearly 9,000 educational institutions. This incident has caused widespread disruption to classes and coursework, raising concerns about the security of student data in the educational sector. The situation is ongoing, and institutions are currently grappling with the implications of the attack, including potential data breaches and operational challenges. The attack underscores the vulnerabilities in digital education systems and the urgent need for enhanced cybersecurity measures.
Hackread – Cybersecurity News, Data Breaches, AI and More
The ShinyHunters hacking group has defaced the Canvas LMS portal, which is widely used by universities for online learning. This breach has disrupted access for hundreds of universities around the globe, impacting students and faculty who rely on the platform for their education. Instructure, the company behind Canvas, confirmed the breach and is currently working to restore services. This incident raises concerns about the security of educational platforms, especially as online learning continues to be a primary method of instruction. The attack highlights the ongoing risks that educational institutions face from cybercriminals.
The ShinyHunters extortion group has successfully hacked into the Canvas login portals of numerous colleges and universities, taking advantage of a vulnerability in the education technology platform developed by Instructure. This breach has resulted in the defacement of these portals, impacting the ability of students and staff to access their accounts. The attack not only disrupts educational operations but also raises concerns about the security of sensitive information stored within these systems. Instructure has faced similar breaches in the past, which emphasizes the ongoing challenges in protecting educational technology from cyber threats. This incident serves as a reminder for institutions to strengthen their cybersecurity measures to guard against such attacks.
Ivanti customers are facing a new security challenge as attackers exploit a zero-day vulnerability in a popular mobile endpoint security product. This flaw allows unauthorized access to victim networks, making it a prime target for cybercriminals. The issue is particularly pressing as Ivanti's products are widely used in various organizations, raising concerns about the potential scale of the attacks. Companies relying on these security solutions are urged to take immediate action to safeguard their networks. The ongoing exploitation of this vulnerability highlights the need for vigilance in maintaining cybersecurity measures and prompt updates to security software.
Hackread – Cybersecurity News, Data Breaches, AI and More
Researchers have identified a new cybersecurity threat involving a fake Claude AI website that is being used to distribute an undocumented backdoor known as Beagle. This malicious campaign leverages malvertising techniques to deceive users into downloading the malware, which can compromise their devices. As more people seek out AI tools, attackers are exploiting this interest to target unsuspecting users. The Beagle malware can potentially allow unauthorized access to a user's system, raising serious concerns about data security and privacy. Users should be cautious when visiting unknown sites and ensure their security software is up to date to protect against such threats.
A new malware called PCPJack has emerged, replacing the previously known TeamPCP malware. This new variant cleverly utilizes parquet files to conduct stealthy reconnaissance across various cloud environments, allowing it to identify and target vulnerable systems without detection. The implications of PCPJack are significant, as it poses a risk to organizations that rely on cloud infrastructure for their operations. By exploiting these environments, attackers could potentially access sensitive data and cloud secrets, raising concerns about data security and privacy. Companies using cloud services should be vigilant and ensure their security measures are up to date to defend against this evolving threat.
A new malware known as PCPJack has emerged, targeting exposed cloud infrastructure to steal user credentials. This worm not only pilfers sensitive information but also actively works to remove any existing access that the earlier TeamPCP malware had established on infected systems. The implications of PCPJack are significant, as it compromises cloud security and can lead to further unauthorized access and data breaches. Organizations with vulnerable cloud setups are particularly at risk, as the worm exploits weaknesses to gain access. Users and companies must bolster their security measures to protect against this evolving threat.
The Australian Cyber Security Center (ACSC) has issued a warning about a new malware campaign that uses a technique called ClickFix to spread the Vidar Stealer malware. This malware is designed to steal sensitive information from compromised systems. Organizations across various sectors are at risk of falling victim to these attacks, as the ClickFix method relies on social engineering tactics to trick users into downloading the malicious software. The ACSC emphasizes the importance of vigilance and recommends that businesses implement robust security measures to protect against these types of threats. As the campaign is currently active, companies need to be proactive in their cybersecurity efforts to avoid potential data breaches and financial losses.
Ivanti has alerted its customers about a severe vulnerability in its Endpoint Manager Mobile (EPMM) software that is being actively exploited in zero-day attacks. This security flaw allows attackers to execute remote code, posing a significant risk to organizations using this mobile device management solution. Companies utilizing EPMM should prioritize applying the necessary patches to protect their systems. The vulnerability affects multiple versions of the software, making it crucial for users to act quickly. Failure to address this issue could lead to unauthorized access and potential data breaches, emphasizing the importance of timely updates in cybersecurity practices.