Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Cisco has addressed several serious vulnerabilities in its enterprise products, particularly in Unity Connection. These flaws, identified as CVE-2026-20034 and CVE-2026-20035, could allow attackers to execute code, perform server-side request forgery (SSRF), or disrupt services. If exploited, these vulnerabilities could have significant implications for organizations using affected Cisco products, potentially leading to unauthorized access or service outages. Cisco has released patches to fix these issues, urging users to update their systems promptly to mitigate risks associated with these high-severity vulnerabilities.

Read Original

Researchers at Dragos have reported that commercial AI models, specifically from OpenAI and Anthropic, were used to plan and execute a cyber-attack on a water and drainage facility's operational technology. This incident raises significant concerns about the potential misuse of advanced AI tools in targeting critical infrastructure. The attackers were able to leverage AI to enhance their tactics, which poses a serious risk to essential services that rely on such technology for safe operations. As AI becomes more integrated into various sectors, there is an urgent need for companies to assess their cybersecurity measures and prepare for potential AI-driven threats. The implications of this attack could affect not only the targeted facility but also set a precedent for similar attacks against other critical infrastructure systems.

Read Original

Two American men have been sentenced for operating laptop farms that employed North Korean IT workers. Their schemes affected nearly 70 U.S. companies and generated around $1.2 million in revenue for North Korea. The laptop farms allowed the North Korean regime to circumvent international sanctions and tap into foreign markets. This incident raises significant concerns about the use of foreign labor for illicit activities and highlights the ongoing challenges in enforcing sanctions against North Korea. The sentences serve as a reminder of the legal consequences of facilitating such operations.

Read Original

Marlon Ferro, a 20-year-old from California, was sentenced to over six years in prison for his involvement in a massive cryptocurrency theft that totaled more than $250 million. This criminal network operated from late 2023 to early 2025, with members located across multiple states and even internationally. Ferro's role included hacking databases and making fraudulent phone calls to execute the theft. The stolen funds were reportedly used to finance a lavish lifestyle, including luxury fashion, nightclub parties, and private jets. This case highlights the ongoing risks associated with cryptocurrency theft and the lengths to which criminals will go for financial gain.

Read Original

Cisco's AI security researchers have discovered a vulnerability in vision-language models (VLMs) that could be exploited by attackers using subtle pixel-level changes in images. These small alterations can mislead the models into producing incorrect outputs without being noticeable to human observers. This poses significant risks for industries that rely on VLMs, such as autonomous vehicles and security systems, where accurate visual interpretation is crucial. The findings suggest that companies using these AI systems should review their security measures to prevent potential exploitation. As AI continues to integrate into various applications, understanding and mitigating such vulnerabilities becomes increasingly important.

Read Original

Two U.S. citizens were sentenced to 18 months in prison for operating 'laptop farms' that enabled North Korean IT workers to fraudulently secure remote jobs with around 70 American companies. This operation involved creating fake employment records and using stolen identities to bypass hiring protocols. The actions of these individuals not only violated U.S. law but also posed a national security risk by potentially providing North Korea with access to sensitive information and resources. The case brings attention to the ongoing issue of North Korean cyber operations and the challenges companies face in ensuring their hiring processes are secure against such fraudulent schemes.

Read Original

The software developer behind Daemon Tools has reported that a supply chain attack was contained after identifying the affected systems. They have removed files that may have been compromised and have validated the installation packages to ensure their integrity. This incident raises concerns about the security of supply chain processes in software development, as attackers increasingly target third-party components to infiltrate systems. Users of Daemon Tools should remain vigilant and ensure they are using the latest, verified versions of the software to avoid potential risks from similar attacks in the future.

Read Original

A recent issue identified during the 'TrustFall' convention reveals that malicious repositories can execute code in several coding tools, including Claude Code, Cursor CLI, Gemini CLI, and CoPilot CLI, with little to no user interaction required. This vulnerability is concerning because it relies on inadequate warning dialogs that fail to sufficiently alert users about the risks. As a result, developers using these tools could unknowingly run harmful code, leading to potential data breaches or system compromises. The lack of effective safeguards means that both individual developers and organizations using these tools are at risk. It's crucial for users to be aware of this vulnerability to avoid falling victim to such attacks.

Read Original

A new type of attack, dubbed the 'TrustFall' attack, reveals vulnerabilities in AI coding agents that can be exploited to execute supply chain attacks. Researchers have demonstrated that these AI tools, which are increasingly used to automate coding tasks, can be manipulated to include malicious code in software development processes. This poses a significant risk to organizations that rely on these AI agents for efficiency, as attackers could potentially compromise software before it reaches users. The implications are serious; if successful, such attacks could lead to widespread disruptions in supply chains, affecting various industries and their customers. Companies must be vigilant and implement safeguards to prevent these types of compromises.

Read Original
Critical
Why Outdated Maintenance Software Is a Growing Ransomware Risk

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Outdated maintenance software poses a significant risk for ransomware attacks by leaving systems vulnerable due to weak access controls and unpatched security flaws. As companies rely on these outdated systems, they expose critical operational data to potential attackers. This situation is particularly concerning for industries that depend on robust maintenance and operational integrity, as breaches could lead to severe disruptions and financial losses. Organizations are urged to regularly update their software and strengthen their cybersecurity measures to protect against these threats. Ignoring these vulnerabilities could have dire consequences for both the companies and their clients.

Read Original

U.S. Immigration and Customs Enforcement (ICE) is developing a new type of smart glasses equipped with facial recognition technology. These glasses will be linked to multiple databases, allowing agents to identify individuals in real-time while on duty. This development raises concerns about privacy and civil liberties, as it could significantly enhance surveillance capabilities. Critics argue that the use of such technology may lead to increased monitoring of citizens without their consent. The implications of this project extend beyond law enforcement, touching on broader issues of data security and the potential for misuse of sensitive information.

Read Original

A vulnerability in the Gemini CLI tool could have allowed attackers to inject malicious prompts into GitHub issues, potentially taking control of an AI agent responsible for triaging those issues. This could lead to unauthorized code execution and create avenues for supply chain attacks. The flaw poses a risk to developers and organizations using Gemini CLI, as it could compromise the integrity of their software development processes. Users need to be aware of this vulnerability and take necessary precautions to secure their systems. Researchers have flagged this issue, emphasizing the need for immediate attention to prevent exploitation.

Read Original
Critical
Scammers Use Hidden Text to Bypass AI Email Filters in Phishing Scams

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Scammers are now using invisible text in phishing emails to trick AI email filters, making it easier for their fraudulent messages to reach users' inboxes. This method involves inserting hidden characters that are not visible to the naked eye but can bypass automated security systems. As a result, more phishing emails could successfully land in inboxes, increasing the risk of users falling victim to scams. This tactic poses a significant challenge for email service providers and cybersecurity experts, who must adapt their filtering techniques to combat this evolving threat. Users should be vigilant and look out for suspicious emails, even if they seem to pass through standard security filters.

Read Original

The report for Q1 2026 details a range of newly discovered vulnerabilities and exploits in various software and systems. Researchers have identified several Command and Control (C2) frameworks utilized in Advanced Persistent Threat (APT) attacks, which indicates a concerning trend in cybercrime tactics. This information is crucial for organizations to understand the evolving threat landscape and to take proactive measures to protect their networks. By keeping track of these vulnerabilities, companies can better defend against potential attacks that exploit these weaknesses. It’s essential for IT teams to stay updated on these findings to ensure their systems are secure.

Read Original

Rep. Summer Lee, a House Democrat, is raising concerns about the government's use of spyware, particularly following a confirmation from ICE that they utilize such technology. This scrutiny comes on the heels of news that a close ally of former President Trump has taken on a leadership role at NSO Group, a company known for its controversial spyware products. Lee's letter to the Commerce Department seeks to clarify the extent of government surveillance practices and their implications for privacy rights. This situation highlights ongoing debates about the balance between national security and individual privacy, especially as government agencies increasingly turn to advanced surveillance technologies. The implications of these developments could affect not only government accountability but also public trust in law enforcement agencies.

Read Original
PreviousPage 182 of 370Next