Hackread – Cybersecurity News, Data Breaches, AI and More
Actively Exploited
ViperTunnel is a new backdoor malware linked to the DragonForce ransomware, specifically targeting businesses that operate on Windows servers in the US and the UK. This Python-based malware allows attackers to gain unauthorized access to systems, which can lead to data theft or further exploitation. Companies utilizing Windows server environments should be particularly vigilant, as the malware poses a significant risk to their operations and data security. The emergence of ViperTunnel highlights the ongoing challenges businesses face in protecting their networks from evolving ransomware threats. Organizations are urged to implement strong security measures and regularly update their systems to fend off such attacks.
A recent analysis by OX Security examined 216 million security findings from 250 organizations over a span of 90 days. The report revealed that while the overall number of security alerts increased by 52% compared to the previous year, the number of critical risks surged by almost 400%. This alarming trend is largely attributed to the rapid growth of AI-assisted development, which is outpacing the ability to manage high-impact vulnerabilities. As organizations adopt more AI technologies, they need to be vigilant about the increasing density of these vulnerabilities, which could lead to significant security breaches if not addressed promptly. Companies must prioritize their security measures to keep up with this accelerating risk landscape.
RCI Hospitality, a major player in the nightclub industry, has reported a data breach due to an IDOR (Insecure Direct Object Reference) vulnerability in RCI Internet Services. This security flaw exposed sensitive contractor data, potentially affecting individuals associated with the company. The breach was disclosed in a filing with the Securities and Exchange Commission (SEC), indicating that the company is taking the matter seriously. This incident raises concerns about data security in the hospitality sector, as breaches can lead to identity theft and other malicious activities. Stakeholders will need to monitor the situation closely as RCI investigates the extent of the exposure and implements necessary safeguards.
A serious vulnerability has been discovered in ShowDoc, an online tool used by IT teams for document sharing and collaboration. This flaw, identified as CVE-2025-0520, allows attackers to execute remote code on unpatched servers, posing a significant risk to organizations that have not updated their systems. With a CVSS score of 9.4, this remote code execution vulnerability is currently being exploited in the wild, meaning that attackers are actively taking advantage of it. Companies using ShowDoc need to prioritize patching their servers to protect against potential breaches and unauthorized access to sensitive information. Failing to address this issue could lead to severe consequences for affected organizations.
A recent study has revealed that over one-third of the official partners of the FIFA World Cup 2026 are exposing the public to the risk of email fraud. This vulnerability arises mainly from the use of unsecured email practices, which can make them easy targets for phishing attacks. The findings suggest that these partners, which include various companies and organizations involved with the event, need to enhance their email security measures to protect their communications and sensitive information. The implications are significant, as successful email fraud can lead to financial losses and damage to reputations, especially for high-profile events like the World Cup. Stakeholders are urged to adopt stronger security protocols to mitigate these risks and safeguard their users.
In April 2026, a significant cybersecurity update revealed two zero-day vulnerabilities and eight critical flaws among a total of 164 Common Vulnerabilities and Exposures (CVEs). These security issues affect a variety of products and systems, potentially putting businesses and individual users at risk. The zero-days, which have not been publicly disclosed in detail, are particularly concerning as they allow attackers to exploit systems before patches are available. Companies using affected software are urged to prioritize applying the latest updates to mitigate any risks. This situation serves as a reminder of the ongoing security challenges faced by organizations in safeguarding their digital environments.
Basic-Fit, a popular fitness chain in Europe, has reported a significant data breach affecting approximately one million of its customers. Hackers managed to infiltrate the company's systems and accessed sensitive information. While Basic-Fit has not specified exactly what data was compromised, breaches of this nature often involve personal details such as names, email addresses, and possibly payment information. This incident raises concerns about the security of customer data in the fitness industry, especially as more people rely on online services for their health and fitness needs. Customers are advised to monitor their accounts for any unusual activity and consider changing their passwords to enhance their security.
U.S. Senator Chuck Grassley is investigating eight major tech companies for potentially failing to properly report instances of child sexual abuse material (CSAM). The companies under scrutiny include Meta, Amazon AI Services, TikTok, Snapchat, Discord, X.AI, Grindr, and Roblox. This inquiry follows concerns about how these platforms handle and report CSAM, which is a significant issue given the potential harm to children and the legal obligations these companies have. Grassley's investigation aims to ensure that these tech giants are held accountable for their reporting practices and that they take necessary steps to protect vulnerable users. The outcome of this probe could lead to stricter regulations and oversight of how online platforms manage and report such sensitive content.
Security experts are sounding alarms about a potential surge of AI-related vulnerabilities following the launch of Anthropic's Claude Mythos. In a new report from the Cloud Security Alliance (CSA), they warn that this advanced AI model could introduce new weaknesses that attackers might exploit. The paper suggests that Chief Information Security Officers (CISOs) should brace for a wave of security challenges as the technology becomes more widely adopted. This situation is critical because organizations may not be fully prepared to address the unique risks associated with AI systems, which could lead to significant breaches or data leaks. Companies need to proactively evaluate their security measures and develop strategies to mitigate these emerging threats.
Juniper Networks has released patches for approximately 30 vulnerabilities in its Junos OS and related systems, according to a report from SecurityWeek. These vulnerabilities could potentially affect a wide range of networking devices and systems that rely on Junos OS, making it crucial for users to apply the updates promptly to secure their environments. The company has not specified whether any of these vulnerabilities are actively being exploited in the wild, but the number of issues warrants immediate attention. Organizations utilizing Juniper's networking products should review their systems and implement the necessary patches to mitigate risks associated with these vulnerabilities. Regular updates are essential to maintaining the security of network infrastructures.
In March 2026, cybersecurity researchers from Check Point reported a significant concentration of ransomware attacks, with nearly half attributed to three specific groups. Qilin led the charge, responsible for 20% of the 672 attacks. Following them was Akira, accounting for 12%, and Dragonforce RaaS, which was linked to 8% of the incidents. This concentrated activity raises alarms for businesses and organizations, as it indicates that a small number of groups are driving a large portion of ransomware incidents. Companies need to bolster their defenses against these specific threats to protect their data and systems.
Researchers from JUMPSEC have reported that a misconfigured command-and-control server linked to the MuddyWater group has exposed custom malware tools, including the CastleRAT variant, which are being used against Israeli targets. The operation appears to involve Iranian cyber actors, specifically those associated with TAG-150. The exposed server has revealed crucial details about these cyber tools, indicating that the attackers are actively targeting specific regions and organizations. This incident raises concerns about the security of Israeli entities and highlights the ongoing cyber warfare in the region, emphasizing the need for heightened vigilance against such threats.
A new version of the GlassWorm campaign is targeting software developers by distributing a fake Visual Studio Code extension. This malicious extension acts as a dropper, compiled using the Zig programming language, and can infect multiple integrated development environments (IDEs) on the same machine. By exploiting a trusted platform, attackers can silently install harmful software that compromises development environments. This poses a significant risk to developers and organizations using these tools, as it can lead to unauthorized access to sensitive code and data. Users of various IDEs should be cautious about the extensions they install and ensure they come from verified sources.
Synthetic identity fraud is on the rise, with a recent analysis from LexisNexis Risk Solutions revealing an eightfold increase in reported cases. This type of fraud now accounts for eleven percent of all fraud incidents worldwide, indicating a troubling trend where attackers are using generative AI to create convincing fake identities. This surge poses significant risks to financial institutions and businesses, as they may unknowingly engage with these fraudulent identities, leading to financial losses and compromised customer data. The growing sophistication of these scams makes it crucial for organizations to enhance their identity verification processes and stay vigilant against AI-driven deception.
A recent survey by the SANS Institute revealed that 92% of organizations do not regularly rotate machine credentials, which are essential for securing non-human identities, such as those used by automated systems and AI. As these non-human identities expand rapidly, the lack of effective governance measures leaves companies vulnerable to potential breaches. The survey suggests that many enterprises have outdated practices that fail to keep pace with the growing complexity of their IT environments. This oversight could allow malicious actors to exploit these weaknesses and gain unauthorized access to critical infrastructure. The findings emphasize the urgent need for organizations to reassess their security protocols and implement regular credential management practices to mitigate risks.