Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Chinese state-backed hackers have been targeting journalists and activists in Taiwan, Hong Kong, Tibet, and the Uyghur region through phishing campaigns over the past nine months. These campaigns are believed to be orchestrated by freelance hackers affiliated with the Chinese government, aiming to extract sensitive information from individuals who are often critical of the Chinese regime. The report from Recorded Future details the tactics used in these attacks, which are particularly concerning given the ongoing suppression of dissent in these regions. The implications are serious, as these efforts not only threaten the safety of the targeted individuals but also aim to silence voices of opposition and undermine press freedom. This situation highlights the ongoing cybersecurity risks faced by those advocating for human rights in China and surrounding areas.

Read Original
Actively Exploited

The Brazilian hacker group LofyGang has made a comeback, targeting Minecraft players with a new malware strain called LofyStealer or GrabBot. This marks their first attack in over three years, indicating a renewed focus on exploiting gamers. The malware is designed to steal sensitive information from users, which can lead to account takeovers and other malicious activities. As Minecraft remains a popular game, players should be particularly vigilant about their account security and be cautious of any suspicious links or downloads. This resurgence of LofyGang emphasizes the ongoing risks faced by online gaming communities.

Read Original

SonicWall has issued an urgent warning about vulnerabilities in its firewall products that could allow attackers to bypass security measures, access restricted services, and potentially crash the firewall systems. These flaws could put organizations at risk of unauthorized access and service disruptions. Users of affected SonicWall firewalls are strongly advised to apply patches immediately to protect their networks. The vulnerabilities were disclosed recently, and the company is emphasizing the need for swift action to mitigate any potential exploitation. Failure to patch could leave systems open to attacks that compromise sensitive data and operational integrity.

Read Original
Actively Exploited

A recent supply chain attack, dubbed the Mini Shai-Hulud attack, has targeted SAP's NPM packages. This attack involves a preinstall hook that downloads and executes a malicious Bun binary, which allows the attackers to evade security monitoring measures. As a result, developers using these NPM packages may unknowingly execute harmful code within their environments. This incident raises significant concerns about the integrity of software supply chains, especially for organizations relying on third-party packages for their development processes. Users of SAP NPM packages should be vigilant and review their dependencies to mitigate potential risks.

Read Original
Actively Exploited

A Brazilian tech company, which specializes in DDoS protection, has been implicated in enabling a botnet that has targeted other internet service providers in Brazil with massive DDoS attacks. The CEO of the firm claims that these attacks stemmed from a security breach and suggested that a rival company might be behind the malicious activities to damage his firm's reputation. This situation raises serious concerns about the integrity of cybersecurity firms and their ability to protect clients. It also highlights the potential for internal issues or competition to lead to significant disruptions in the tech industry. The ongoing attacks could impact the reliability of internet services for many users and businesses in Brazil.

Read Original
Actively Exploited

When a new asset is launched, it doesn't take long for attackers to start probing for vulnerabilities. Research from Sprocket Security indicates that automated attacks can transition from discovering a new asset to compromising it in less than 24 hours. This rapid timeline highlights the urgency for companies to implement security measures as soon as new systems or applications go live. Organizations need to be aware that every new asset is a potential target, and proactive monitoring and defense strategies are crucial. The findings serve as a reminder that cybersecurity should be a priority right from the moment a new asset is activated.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has released a new guide focused on applying zero-trust security principles to operational technology (OT) environments. This initiative aims to improve cybersecurity while ensuring the safety and availability of critical systems. The guide is intended for organizations that manage OT systems, emphasizing the importance of integrating cybersecurity measures into their operational processes. By adopting a zero-trust approach, organizations can better defend against potential cyber threats while maintaining operational continuity. This guidance is particularly relevant as industries increasingly face cyber risks that can impact both security and functionality.

Read Original

A new vulnerability known as 'Copy Fail' has been identified in Linux kernels released since 2017. This flaw allows local, unprivileged attackers to escalate their privileges and gain root access to affected systems. Researchers have published an exploit for this vulnerability, raising concerns about its potential for misuse. Major Linux distributions are at risk, which could allow attackers to take control of sensitive systems. Users of these systems should be aware of the threat and take steps to secure their environments.

Read Original

A serious vulnerability (CVE-2026-41940) affecting cPanel, a widely used web hosting control panel, has been exploited by attackers for several months before a patch was released. This authentication bypass flaw has been in active use since at least February 23, 2026, with indications that it may have been abused even earlier. The vulnerability primarily impacts users of cPanel, which is often provided by shared hosting services. The delay in addressing this issue raises concerns about the security of web hosting environments and the potential for unauthorized access to sensitive data. Companies using cPanel are urged to apply the latest security updates as soon as possible to mitigate risks associated with this exploit.

Read Original

The UK’s public education sector has seen a significant rise in cyber breaches over the past year, even as the overall national threat levels remain stable. This surge in attacks is particularly concerning because it affects schools, colleges, and universities, which often hold sensitive personal data of students and staff. Researchers indicate that these incidents can disrupt educational operations and compromise the privacy of those involved. The increase in cyber incidents poses serious risks not only to the institutions themselves but also to the broader community as attackers may exploit stolen data for malicious purposes. Addressing these vulnerabilities is crucial to protect both educational resources and personal information.

Read Original

Amazon has reported a staggering increase in cyberthreat attempts, rising from 100 million to approximately 750 million per day as of the end of 2024. This sharp spike in attempted intrusions signals a growing concern for businesses relying on cloud services. The surge in threats underscores the need for companies to bolster their cybersecurity measures, especially as hybrid warfare tactics evolve. With more organizations moving to cloud-based infrastructures, understanding and preparing for potential downtime or breaches is crucial. Users and businesses must remain vigilant and proactive in their security strategies to mitigate risks associated with these increasing threats.

Read Original

Researchers have identified a new Python-based backdoor called DEEP#DOOR, which is designed to gain persistent access to compromised systems and steal sensitive information, including browser and cloud credentials. The attack is initiated through a batch script named 'install_obf.bat', which disables essential Windows security features, allowing the malware to operate undetected. This backdoor can pose significant risks to both individual users and organizations, as it can access a wide range of data stored on affected devices. The stealthy nature of DEEP#DOOR makes it particularly dangerous, as it can remain hidden while actively siphoning off sensitive credentials. Users and companies need to be vigilant about their security measures to prevent such intrusions.

Read Original

A recently discovered flaw in the Gemini command-line interface (CLI) has raised significant security concerns. This vulnerability allows attackers to create malicious configurations that could execute commands outside of the intended sandbox environment. This means that attackers could potentially gain control of host systems, leading to serious risks such as supply chain attacks. Companies using Gemini CLI should be particularly vigilant, as this flaw could affect various applications and services relying on this tool. The implications are severe, as unauthorized command execution could compromise sensitive data and system integrity.

Read Original

Researchers at Claroty have identified two serious vulnerabilities in the EnOcean SmartServer, a device commonly used in building automation systems. These flaws allow attackers to bypass security measures and execute code remotely, potentially giving them control over various building functions. This is particularly concerning as such systems manage critical infrastructure like lighting, heating, and security. The vulnerabilities could affect a wide range of buildings that rely on SmartServer technology, making it imperative for affected organizations to take immediate action. Without proper remediation, these weaknesses could lead to unauthorized access and significant operational disruptions.

Read Original

A serious authentication bypass vulnerability identified as CVE-2026-41940 has been discovered in cPanel, WHM, and WP Squared. This flaw has been actively exploited by attackers since late February, allowing unauthorized access to systems using these platforms. cPanel and WHM are widely used web hosting control panels, making this issue particularly concerning for hosting providers and website owners. Users of affected systems should take immediate action to secure their environments, as the vulnerability poses a significant risk to sensitive data and system integrity. As proof-of-concept (PoC) code is now available, the potential for widespread exploitation increases, underscoring the urgency for users to address this vulnerability promptly.

Read Original
PreviousPage 192 of 370Next