Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

The National Motor Freight Traffic Association (NMFTA) has issued a warning about a significant increase in cyber-enabled cargo theft targeting the trucking industry. Their 2026 Transportation Industry Cybersecurity Trends Report indicates that attackers are using more sophisticated methods to steal cargo, which not only affects the freight companies but also poses risks to supply chain integrity and consumer safety. This rise in theft could lead to higher costs for transportation and logistics firms, potentially impacting prices for consumers. As these cyber threats evolve, the NMFTA stresses the need for enhanced cybersecurity measures within the industry to protect against these growing risks.

Impact: Trucking industry, freight companies, supply chain systems
Remediation: Enhanced cybersecurity measures, employee training on phishing and security protocols
Read Original

Askul, a major Japanese e-commerce and logistics company, has reported a significant data breach following a ransomware attack by a group called RansomHouse. This incident has compromised over 700,000 records, raising concerns about the security of sensitive information related to both businesses and consumers who rely on Askul for office supplies and logistics services. The attack underscores the ongoing risks faced by companies in the e-commerce sector, particularly as cybercriminals increasingly target organizations with ransomware. As a result, affected individuals and businesses may be at risk of identity theft and other cyber threats. Companies should take this incident as a wake-up call to bolster their cybersecurity measures and ensure they have effective data protection strategies in place.

Impact: Over 700,000 records from Askul's customer database
Remediation: Companies should enhance cybersecurity protocols and consider implementing more stringent data protection measures.
Read Original
Hackers Claim Stealing 94GB of Pornhub Premium User Watch Histories

Hackread – Cybersecurity News, Data Breaches, AI, and More

Actively Exploited

A hacking group known as ShinyHunters has reportedly stolen 94GB of data from former Pornhub Premium users, which includes their watch histories. This breach is part of an extortion campaign aimed at these users, raising significant privacy concerns. The attackers utilized a smishing attack, where they sent phishing messages via text to lure victims into revealing personal information. While the specifics of the breach are still being investigated, conflicting reports have emerged about the extent and security of the data involved. This incident underscores the ongoing risks associated with online platforms, particularly regarding user data security and the potential for exploitation by cybercriminals.

Impact: Pornhub Premium user watch histories
Remediation: Users should monitor their accounts for suspicious activity and consider changing passwords. Enabling two-factor authentication can also help enhance security.
Read Original

LKQ, a US autoparts manufacturer, has confirmed a data breach affecting over 9,000 individuals. The breach involved unauthorized access to personal data, raising concerns about the security of sensitive information. This incident highlights the vulnerabilities that companies face, especially those relying on systems like Oracle EBS. Those affected may be at risk for identity theft and other forms of fraud, emphasizing the need for individuals to monitor their accounts and consider additional security measures. Companies are urged to review their security protocols to prevent similar incidents in the future.

Impact: Personal data of over 9,000 individuals
Remediation: N/A
Read Original

A recent operation led by Eurojust has dismantled a call center fraud ring based in Ukraine, which was responsible for defrauding victims of approximately $12 million. The operation involved multiple European law enforcement agencies working together to target the network of scammers who deceived individuals, often by impersonating legitimate companies. This crackdown is significant as it not only disrupts the financial gains of the fraudsters but also aims to protect vulnerable populations from ongoing scams. The investigation highlights the collaborative efforts across borders to combat organized crime, especially in the realm of online fraud. As these types of scams continue to evolve, law enforcement agencies emphasize the need for public awareness and vigilance against such fraudulent schemes.

Impact: N/A
Remediation: N/A
Read Original

Kaspersky's GReAT team has reported an increase in cyberattacks from the ForumTroll APT group, which is specifically targeting Russian political scientists. The attackers are using a tool known as the Tuoni framework to infiltrate their devices. This situation is concerning as it shows a focused attempt to compromise the devices of individuals involved in political research, potentially to gather sensitive information or disrupt their work. The targeting of political scientists indicates a strategic move to influence or monitor political discourse in Russia. These incidents serve as a reminder of the ongoing risks faced by academics and researchers in politically sensitive environments.

Impact: Devices of Russian political scientists, potentially including personal computers and academic networks.
Remediation: N/A
Read Original

The Chinese cyber espionage group known as Ink Dragon has reportedly infiltrated European government networks to conduct its operations. Researchers have found that this group is using these networks to mask its activities, making it challenging for authorities to detect their movements. This situation raises concerns about national security, as sensitive information may be at risk. The infiltration of government systems not only threatens the integrity of those networks but also poses risks to the safety of citizens and international relations. As the group continues its activities, it underscores the need for improved cybersecurity measures within government infrastructures.

Impact: European government networks
Remediation: Strengthening cybersecurity protocols, monitoring network traffic for unusual activity, and implementing stricter access controls.
Read Original

LKQ, a major player in the auto parts industry, has confirmed a breach involving their Oracle EBS system, compromising the personal information of thousands of individuals. The attack raises serious concerns about data security, as sensitive information could be misused by cybercriminals. While LKQ has not disclosed the exact number of affected individuals, the incident underscores the vulnerabilities that can exist in enterprise resource planning systems. Companies using similar platforms should take this as a wake-up call to assess their security measures and ensure that personal data is adequately protected. The breach serves as a reminder of the increasing risks businesses face from cyberattacks in today's digital landscape.

Impact: Oracle EBS system, personal data of thousands of individuals
Remediation: N/A
Read Original

Afripol is addressing regional cybersecurity challenges stemming from rapid digital growth, a lack of cybersecurity expertise, and the rise of organized cybercrime. These issues are putting pressure on law enforcement and prosecutors who are struggling to keep up with the evolving threat landscape. The organization is focusing on enhancing cooperation among countries in Africa to better combat cybercriminal activities. This collective approach aims to strengthen the region's defenses against cyber threats, making it crucial for the safety and security of businesses and individuals in the area. As cybercriminal syndicates become more sophisticated, regional collaboration is essential for effective law enforcement and prosecution.

Impact: N/A
Remediation: N/A
Read Original

Illusory Systems has reached a settlement with the Federal Trade Commission (FTC) regarding a 2022 hack that compromised its Token Bridge software. The FTC charged the company for misrepresenting the security measures in place, stating that the executives did not implement adequate safeguards to protect user assets. As a result of the breach, attackers were able to exploit vulnerabilities, leading to significant financial losses. This incident underscores the need for companies in the cryptocurrency space to maintain transparent and effective cybersecurity practices. The settlement may also serve as a warning to other firms about the importance of accurately representing their security capabilities to users and regulators.

Impact: Token Bridge software
Remediation: N/A
Read Original

The outgoing chief of the Government Accountability Office (GAO) has raised concerns about the Cybersecurity and Infrastructure Security Agency (CISA) potentially easing its efforts in cybersecurity. In a recent statement, he emphasized the need for continued vigilance in the face of increasing cyber threats. He warned that any reduction in focus could leave critical infrastructure vulnerable to attacks. The comments come amid ongoing discussions about the role and funding of CISA, which is tasked with protecting the nation’s cybersecurity. As CISA navigates its priorities, the former GAO chief's remarks serve as a reminder of the persistent risks in the digital landscape and the importance of maintaining robust security measures.

Impact: CISA, critical infrastructure sectors
Remediation: N/A
Read Original

Reports have surfaced regarding a cyberattack on PDVSA, Venezuela's state-owned oil and gas company, which allegedly led to major disruptions in its operations. While PDVSA has attempted to downplay the incident, the extent of the disruption suggests significant implications for the company and potentially for the wider oil market. This incident raises concerns about the security of critical infrastructure in the sector and the potential for similar attacks targeting other companies. As PDVSA navigates the aftermath, both the company and industry observers will be watching closely to assess the impact on production and supply chains.

Impact: PDVSA operations
Remediation: N/A
Read Original

The article discusses how the shift towards open-source libraries and AI-powered coding tools is creating new risks for software development. As developers increasingly rely on third-party resources to speed up their work, they unintentionally expose their projects to vulnerabilities that can be exploited by cybercriminals. These risks affect a wide range of companies and software products, as attackers look for weak points in the development process. The growing use of AI for coding assistance also raises concerns about the potential for introducing flaws or malicious code without developers' awareness. This situation emphasizes the need for businesses to assess their third-party dependencies and implement stronger security measures.

Impact: Open-source libraries, AI-powered coding tools
Remediation: Companies should evaluate their use of third-party libraries and AI tools, implement security assessments, and establish guidelines for secure coding practices.
Read Original

The Texas Attorney General has filed a lawsuit against five major television manufacturers, claiming they illegally collected user data by using Automated Content Recognition (ACR) technology to monitor what viewers watch. The lawsuit alleges that these companies failed to inform users about this data collection, raising significant privacy concerns. ACR technology allows devices to identify and record content without the viewer's explicit consent, which the state argues is a violation of consumer protection laws. This case underscores the ongoing debate over user privacy and data collection practices in smart devices, particularly as more households adopt smart TVs. If successful, the lawsuit could lead to stricter regulations on how companies handle user data in the future.

Impact: Smart TVs from five major manufacturers (not specified)
Remediation: N/A
Read Original

Urban VPN Proxy, a browser extension, is facing accusations of collecting users' AI chat conversations without their consent. This raises significant privacy concerns, especially for users who rely on the VPN service for secure browsing. Researchers discovered that the extension may be logging sensitive information, which could potentially be misused or exposed. The implications of this practice are serious, as it undermines user trust in VPN services, which are typically used to protect privacy online. Users of Urban VPN should be aware of these allegations and consider the risks associated with using this tool for private communications.

Impact: Urban VPN Proxy browser extension
Remediation: Users should consider uninstalling the Urban VPN Proxy extension and switching to a reputable VPN service that prioritizes user privacy.
Read Original
PreviousPage 188 of 219Next