Hackread – Cybersecurity News, Data Breaches, AI and More
At the Wiz ZeroDay.Cloud event, researchers disclosed significant vulnerabilities in PostgreSQL that have existed for 20 years. These flaws, particularly in the pgcrypto module, could allow attackers to exploit the database's security, raising serious concerns for organizations relying on PostgreSQL for data management. The researchers emphasized the urgency of applying patches to mitigate these risks and protect sensitive information. With many systems still using outdated versions, companies should prioritize updating their PostgreSQL installations to safeguard against potential attacks. This incident serves as a stark reminder of the importance of regular security audits and timely updates in maintaining database integrity.
Fraudsters are increasingly targeting credit unions by exploiting standard business processes rather than using traditional hacking methods. According to research from Flare, these criminals use stolen identities to navigate verification systems, allowing them to secure loans fraudulently. This method of structured loan fraud poses a significant risk to credit unions, as it can lead to substantial financial losses and undermine customer trust. By bypassing security measures that are typically relied upon, these fraudsters are able to manipulate systems in ways that may not trigger alarms. It’s essential for credit unions to enhance their verification processes to combat this type of fraud effectively.
DigiCert, a prominent certificate authority, has revoked a number of certificates after a security breach involving its internal support portal. Hackers managed to deliver malware through a customer chat channel, which infected an analyst’s system. This breach allowed them access to sensitive internal systems, raising concerns about the security of the certificates issued by DigiCert. The incident highlights significant vulnerabilities in customer support systems, emphasizing the need for stronger security measures in such environments. Companies relying on DigiCert for SSL certificates may need to assess the implications of this breach on their own security postures.
Stephen Campbell from Team Cymru has expressed concerns that many small defense contractors in the U.S. are not adequately equipped to fend off cyberattacks, particularly those originating from nation-state hackers. These smaller firms often use edge devices, which can be vulnerable entry points for attackers. Campbell emphasizes that without sufficient network data and resources, these companies struggle to detect and mitigate intrusions. This lack of preparedness could have serious implications, not just for the contractors themselves but also for national security, as these companies often handle sensitive defense information. The warning serves as a call for increased investment in cybersecurity measures among smaller firms in the defense sector.
The cybercrime group Silver Fox, based in China, has launched a phishing campaign targeting organizations in India and Russia using a new malware known as ABCDoor. The attackers sent emails posing as communications from the Income Tax Department of India in December 2025, followed by similar attempts aimed at Russian entities. This tactic is concerning as it exploits tax-related themes to gain trust and infiltrate systems. The use of ABCDoor malware can lead to unauthorized access to sensitive information, potentially compromising the security of targeted organizations. As cyber threats continue to evolve, it is crucial for companies in these regions to enhance their security measures and educate employees on recognizing phishing attempts.
CISA has issued a warning that the 'Copy Fail' vulnerability in Linux systems is being actively exploited by attackers. This flaw was disclosed just one day prior by researchers from Theori, who also released a proof-of-concept exploit. The vulnerability allows attackers to gain root access to compromised Linux systems, putting a wide range of users and organizations at risk. System administrators and users of affected Linux distributions need to take immediate action to secure their systems against potential exploits. The rapid exploitation following the disclosure highlights the urgency for organizations to patch their systems as soon as possible.
Microsoft has acknowledged that the April 2026 security updates for Windows are causing issues with third-party backup applications that rely on the psmounterex.sys driver. This problem is affecting various backup solutions, preventing users from successfully backing up their data. The situation is significant as it could lead to data loss for individuals and businesses that depend on these backup tools for data protection. Microsoft has not yet released a specific fix or workaround for this issue, leaving users in a precarious position. Companies and users are advised to monitor for updates from Microsoft regarding this ongoing issue.
Researchers have identified a new phishing technique that exploits Amazon's Simple Email Service (SES) to send fraudulent emails that appear legitimate. By using this widely trusted cloud email service, attackers can bypass traditional email security measures. Victims may struggle to distinguish these phishing emails from real communications, making them more susceptible to scams. The implications are significant, as this method could lead to increased identity theft and financial loss for individuals and organizations alike. Users are advised to be vigilant and verify the authenticity of unexpected emails, especially those requesting sensitive information or prompting urgent actions.
The article discusses the growing importance of data centers as critical infrastructure in today's digital economy, particularly due to the rising reliance on artificial intelligence. As businesses, supply chains, and national security increasingly depend on cloud services, data centers have become attractive targets for cyberattacks. The piece emphasizes that protecting these facilities is essential not just for individual companies but also for national security. It suggests that without proper safeguards, disruptions to data centers could have widespread repercussions, affecting numerous sectors and services that rely on cloud computing. The call to recognize data centers as critical infrastructure underscores the need for enhanced security measures to fend off potential threats.
The UK’s National Cyber Security Centre (NCSC) has issued a warning that advancements in artificial intelligence are leading to faster discovery of software vulnerabilities. This acceleration could result in a surge of urgent software updates, often referred to as a 'patch wave', to address these newly identified flaws. CTO Ollie Whitehouse cautioned that this trend increases the risk of large-scale exploitation by skilled attackers who could take advantage of unpatched vulnerabilities. This situation places pressure on software vendors to quickly develop and deploy fixes, highlighting the need for organizations to remain vigilant and prompt in their patching efforts. As the technology continues to evolve, the implications for cybersecurity could be significant, affecting a wide range of software products and systems across various industries.
The article discusses the challenges organizations face in transitioning to post-quantum cryptography while managing threats posed by artificial intelligence. Experts like Bobby Ford and HD Moore emphasize that traditional security measures may not suffice against AI-driven attacks, which are becoming more sophisticated and prevalent. Companies and institutions must adapt their defenses to counter these emerging risks effectively. The piece also touches on the need for collaboration among cybersecurity professionals to share knowledge and strategies in this evolving landscape. This is particularly urgent as the timeline for quantum computing advancements accelerates, potentially rendering current encryption methods obsolete.
OpenAI is planning to broaden its Trusted Access for Cyber program, which is designed to assist cyber defenders across various government levels, including federal, state, and local agencies. This initiative aims to enhance the cybersecurity capabilities of these agencies, helping them better protect against cyber threats. By extending its program, OpenAI seeks to provide government entities with advanced tools and resources to strengthen their defenses. This move comes as cyber threats continue to evolve, underscoring the need for robust support for those tasked with safeguarding public information and infrastructure. The collaboration between tech companies like OpenAI and government bodies could lead to improved security measures that benefit all citizens.
A major international operation has led to the arrest of at least 276 individuals involved in cryptocurrency investment scams that targeted American citizens. The crackdown was spearheaded by Dubai Police, in collaboration with the U.S. Federal authorities, and resulted in the closure of nine scam centers. These operations had reportedly caused millions of dollars in losses to unsuspecting investors. This coordinated effort underscores the growing issue of cryptocurrency fraud, which has become increasingly prevalent as more people engage in digital investments. The significant amount seized, totaling $701 million, indicates the scale of these scams and the need for ongoing vigilance in the crypto space.
CrowdStrike recently conducted technical risk assessments that revealed common exposure patterns among various organizations. Their findings suggest that many companies share similar vulnerabilities, which could be exploited by cyber attackers. This information is crucial for businesses to understand where they may be at risk and to take proactive steps to secure their systems. By identifying these patterns, CrowdStrike aims to help organizations bolster their defenses and minimize the likelihood of a successful cyber attack. The assessments encourage companies to assess their security measures and address any weaknesses found.
Instructure, an educational technology company, has confirmed that it suffered a data breach after a cyberattack. The ShinyHunters group, known for its extortion tactics, claims responsibility for the attack. Users of Instructure's platforms, which include tools like Canvas, may have had their personal data compromised. This incident raises concerns about the security of educational technologies and the potential risks to students and educators. As cyberattacks on educational institutions become more frequent, stakeholders need to ensure that proper security measures are in place to protect sensitive information.