Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

OpenAI has introduced a new variant of its ChatGPT specifically designed for cybersecurity, named the GPT 5.4 Cyber model. This model is part of an expanded Trusted Access for Cyber program, which aims to enhance security measures and tools available to users. With this move, OpenAI is positioning itself against competitors like Anthropic and their Project Glasswing. The development raises important questions about the access and control of powerful AI technologies in the cybersecurity space, particularly regarding who can utilize these advanced tools and how they will be applied in real-world scenarios. As companies increasingly rely on AI for security, the implications of access and usage will be significant for both organizations and individual users.

Read Original
Actively Exploited

Researchers have discovered that 100 Chrome extensions, published through five different accounts, are part of a coordinated campaign designed to steal user data and create backdoors. These malicious extensions utilize shared command and control (C&C) infrastructure, indicating a well-organized effort by the attackers. Users who have installed these extensions are at risk of having their data compromised, which could lead to identity theft or other forms of online fraud. This incident serves as a reminder for users to be cautious when installing browser extensions and to regularly review their installed add-ons for any suspicious activity. The findings underscore the need for enhanced scrutiny of browser extensions to protect user privacy and security.

Read Original
Actively Exploited

A serious security flaw has been identified in the nginx-ui MCP, specifically an authentication bypass vulnerability tracked as CVE-2026-33032. This vulnerability has a high severity score of 9.8 on the CVSS scale and is currently being exploited in the wild, making it a pressing concern for users and organizations running affected versions. Attackers could potentially gain unauthorized access to systems using this flaw, which poses significant risks to data integrity and confidentiality. It's crucial for system administrators to take immediate action to protect their environments from these attacks. Timely updates and security patches are essential to mitigate the risks associated with this vulnerability.

Read Original
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover

The Hacker News

Actively Exploited

A serious vulnerability, identified as CVE-2026-33032, has been discovered in nginx-ui, a management tool for Nginx servers. This flaw allows attackers to bypass authentication, potentially giving them full control of the Nginx service. Dubbed MCPwn by Pluto Security, the vulnerability has a CVSS score of 9.8, indicating its critical nature. Users of nginx-ui are at risk, as the flaw is currently being actively exploited in the wild. It's crucial for affected organizations to take immediate action to secure their systems and prevent unauthorized access.

Read Original

A report detailing the state of cybersecurity threats to industrial automation systems in Q4 2025 reveals concerning trends in malware and infection vectors. Researchers identified various types of malware that are increasingly targeting these systems, affecting industries across different regions. The report emphasizes that many organizations remain vulnerable due to outdated security measures and a lack of awareness about emerging threats. This situation puts critical infrastructure at risk, potentially leading to operational disruptions and safety hazards. Companies are urged to enhance their cybersecurity protocols and invest in better defenses to protect against these sophisticated attacks.

Read Original
ShinyHunters Leak Rockstar Games Data, No Player Records Impacted

Hackread – Cybersecurity News, Data Breaches, AI and More

The hacking group ShinyHunters has leaked 7.54 GB of data from Rockstar Games, specifically from their Snowflake analytics systems. Fortunately, Rockstar confirmed that no player records or personal information were compromised in this incident. This leak raises concerns about the security of game development companies and the potential for sensitive corporate information to be exposed. While player data remains safe, the breach could still impact Rockstar's reputation and business operations. Companies in the gaming industry need to be vigilant about their data security to prevent similar incidents in the future.

Read Original

Ivanti has patched two vulnerabilities in its Neurons for IT Service Management (ITSM) product that could allow remote attackers to maintain access to user accounts even after they have been disabled. Additionally, these flaws could enable attackers to access information from other user sessions. This raises serious concerns for organizations using Ivanti's ITSM solutions, as it puts sensitive user data at risk and undermines account security. Companies should ensure they update to the latest versions to mitigate these risks and protect their systems from potential exploitation. The vulnerabilities highlight the need for continuous monitoring and prompt application of security patches in IT management tools.

Read Original

Congress is preparing to discuss the reauthorization of a contentious foreign surveillance program that allows U.S. intelligence agencies to monitor the communications of non-U.S. citizens. Former President Donald Trump has expressed support for extending this program, arguing it is essential for national security. However, some lawmakers are advocating for stronger privacy protections for American citizens, raising concerns about potential overreach and the impact on civil liberties. The debate reflects growing tensions between security measures and individual privacy rights in the digital age. As this issue unfolds, it could significantly influence how surveillance is conducted and regulated in the U.S.

Read Original
Critical
13.5M Device Botnet Drives 2 Tbps DDoS Attacks on FinTech, Qrator Finds

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

A recent report from Qrator Labs indicates that the largest known DDoS botnet has expanded to encompass 13.5 million devices. This massive botnet is capable of launching Distributed Denial of Service (DDoS) attacks reaching up to 2 terabits per second. The primary target of these attacks has been the financial technology sector, raising concerns for companies in that space. With such a vast number of devices potentially under the control of attackers, the threat to both service availability and data security is significant. Companies in the FinTech sector, as well as other industries relying on online services, need to bolster their defenses to mitigate the risks associated with these powerful DDoS attacks.

Read Original

Fortinet has addressed serious vulnerabilities in its FortiSandbox product that could allow attackers to bypass authentication and execute arbitrary commands through HTTP requests. These flaws pose a significant risk, as they could lead to unauthorized access and control over affected systems. Users of FortiSandbox should prioritize applying the patches released by Fortinet to protect their environments. The vulnerabilities highlight the ongoing need for vigilance in cybersecurity practices, especially for companies using Fortinet's security solutions. Timely updates and patches are crucial in preventing potential exploitation of these weaknesses.

Read Original
Actively Exploited

Researchers at Barracuda have reported a significant increase in brute-force attacks originating from the Middle East, with a startling 88% of such attempts occurring in the region during the first quarter of the year. This surge raises concerns for organizations that may be targeted, especially those with weak password policies or inadequate security measures. Brute-force attacks involve systematically trying various password combinations to gain unauthorized access to accounts, which can lead to data breaches and financial losses. Companies in sectors like finance, healthcare, and e-commerce should take this trend seriously and reinforce their security protocols to protect sensitive information. Implementing stronger password requirements and two-factor authentication are crucial steps to mitigate these risks.

Read Original

Raspberry Pi OS 6.2, which is based on the Trixie version, has made a significant change by disabling passwordless sudo for new installations. This adjustment aims to enhance security and reduce the risk of unauthorized access. While passwordless sudo can be convenient for users, it also poses a security risk that can be exploited by attackers. The Raspberry Pi Foundation continues to review the operating system's security measures to strike a balance between usability and protection. Users installing the latest version will now be required to enter a password when using sudo commands, which adds a layer of security against potential threats.

Read Original

Researchers have identified two high-severity vulnerabilities in PHP Composer, a tool widely used by developers to manage PHP libraries. These flaws could allow attackers to execute arbitrary commands by exploiting malicious repository configurations and specially crafted inputs, particularly affecting those using Perforce version control system. This is concerning for developers who rely on Composer to securely manage their dependencies, as the vulnerabilities could lead to unauthorized access or control over systems. Immediate action is necessary to protect applications that depend on this tool, especially since the risks associated with such command execution can be severe. Developers are advised to review their configurations and stay updated on any patches released to address these vulnerabilities.

Read Original

OpenAI is enhancing its cybersecurity efforts by expanding its Trusted Access for Cyber (TAC) program, which now aims to provide thousands of verified cybersecurity professionals with prioritized access to advanced AI tools. This expansion includes the introduction of GPT-5.4-Cyber, a specialized version of their AI designed to assist in identifying and addressing vulnerabilities in critical software. The initiative focuses on empowering defenders who are responsible for protecting software systems from potential attacks. By equipping these professionals with better resources, OpenAI hopes to improve the speed and effectiveness of vulnerability management. This move is significant as it addresses the ongoing challenge of staying ahead of attackers in the cybersecurity landscape.

Read Original

The Cloud Security Alliance has issued a warning about a significant change in how quickly vulnerabilities can be exploited. Researchers are particularly concerned about Anthropic’s Claude Mythos, an AI system capable of autonomously identifying thousands of zero-day vulnerabilities in popular operating systems and web browsers. It doesn't just find these flaws; it also creates working exploits without any human intervention. This rapid pace of exploit development poses a challenge for organizations that rely on traditional patch cycles, as the time to fix vulnerabilities is shrinking. Companies will need to adapt their security strategies to keep up with this evolving threat landscape.

Read Original
PreviousPage 217 of 371Next