Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Former President Trump has authorized a new policy that allows private companies to engage in 'Cyber Effects Operations' against criminal activities. This means that these companies can now manipulate, disrupt, or destroy the information systems and networks of criminals. The intention behind this policy is to empower private entities to combat cybercrime more effectively, particularly in instances where government resources may be limited. However, this approach raises concerns about the potential for abuse and the risks associated with private entities taking on roles traditionally reserved for law enforcement. The implications of this policy could significantly alter the landscape of cybersecurity, as private companies may now operate with greater autonomy in the fight against cyber threats.

Read Original

Pennsylvania's new budget includes a significant boost for cybersecurity measures, allocating an additional $10 million specifically for these initiatives. Additionally, $3.7 million is designated for the Commonwealth Office of Digital Experience (CODE PA), which focuses on enhancing digital services across the state. This funding is a response to the growing need for improved cybersecurity as threats become more sophisticated and pervasive. By increasing investment in these areas, Pennsylvania aims to better protect its systems and data from potential cyberattacks, which can have serious implications for both state operations and residents' personal information. This move reflects a broader trend among states recognizing the importance of robust cybersecurity frameworks to safeguard public resources.

Read Original

Cameron Curry, a former contractor for Brightly Software, was sentenced to two years in prison after stealing sensitive corporate data and employee information during his contract. As his six-month role was ending, Curry used the stolen information to extort the company, demanding $7,540.92. This incident raises concerns about insider threats and the potential risks companies face from employees who may misuse their access. It serves as a reminder for organizations to implement stringent security measures and monitor employee activities to prevent similar situations in the future. The case emphasizes the need for effective data protection strategies to safeguard sensitive information from internal actors.

Read Original

Ukrainian authorities recently took decisive action against fraud by shutting down 94 call centers involved in investment scams. These centers targeted individuals, often enticing them with false promises of financial gain while attempting to gain access to their bank accounts. The operation resulted in the seizure of millions in cash, aiming to dismantle a network that exploited unsuspecting victims. This crackdown not only protects potential victims in Ukraine but also sends a strong message to scammers operating in the region. Such fraudulent activities can have widespread implications, affecting financial security and trust in legitimate investment opportunities.

Read Original
Actively Exploited

Recent reports have revealed significant vulnerabilities in WiFi-enabled AI devices, raising concerns about the security of personal and corporate networks. Attackers could exploit these weaknesses to gain unauthorized access, potentially leading to data breaches or other malicious activities. Affected devices include various smart home appliances, IoT devices, and AI-powered systems that rely on WiFi connectivity. As these technologies become more prevalent, users and companies need to be aware of the risks and take steps to secure their networks. It's essential for manufacturers to address these vulnerabilities promptly to protect users from potential exploitation.

Read Original

Taiwan has confirmed that it experienced a cyberattack that utilized artificial intelligence to target government systems. This incident marks a notable shift in how nation-state actors are conducting cyber operations, as the use of AI allows for faster and more autonomous attacks. The specific details of the attack, including the exact systems affected, have not been disclosed. However, it raises significant concerns about the increasing sophistication of cyber threats, particularly from state-sponsored groups. This incident serves as a wake-up call for governments worldwide to bolster their cybersecurity measures and prepare for more advanced attacks in the future.

Read Original

A newly found zero-day vulnerability in GeoServer is currently being exploited by attackers, as reported by watchTowr. This SQL injection flaw allows for remote code execution (RCE) and has not yet been patched. Researchers first disclosed the issue on August 12, 2026. Users of the open-source GeoServer platform are at risk, as the vulnerability could allow attackers to execute malicious code on affected systems. It’s crucial for organizations using GeoServer to remain vigilant and seek immediate remediation steps, as no updates or patches have been released to address this critical issue.

Read Original

This week's ThreatsDay Bulletin covers a range of cybersecurity updates, focusing on various threats and vulnerabilities impacting cloud services, AI tools, and more. Among the highlights is the emergence of GhostJacking AI attacks, which could allow attackers to hijack AI systems for malicious purposes. Additionally, EtherHiding ClickFix has been noted for its potential to obscure malicious activity in Ethereum transactions. A flaw in Cursor CLI has also been identified, posing risks to command-line interface security. These incidents underscore the ongoing challenges faced by security teams in protecting systems and user data against evolving threats. Organizations and users need to stay informed and take proactive measures to safeguard their environments against these vulnerabilities.

Read Original
Actively Exploited

The Jewelbug hacker group has successfully breached government webmail systems while simultaneously conducting cryptocurrency fraud schemes. This dual operation not only raises concerns about the security of sensitive government communications but also highlights the potential for financial exploitation through digital currencies. Governments and military organizations are particularly at risk, as the hackers target their systems for espionage purposes. The implications of such breaches are significant, as they can compromise national security and lead to unauthorized access to confidential information. The ongoing activities of Jewelbug underline the evolving tactics of cybercriminals, who are increasingly blending traditional espionage with modern financial crimes.

Read Original
Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure

Security Affairs

Actively Exploited

Shortly after its public disclosure, hackers began exploiting a serious vulnerability in Adobe Commerce known as CVE-2026-71362, which has a CVSS score of 9.1. This flaw allows attackers to hijack customer accounts without needing authentication, potentially exposing sensitive user data. Businesses using Adobe Commerce should be particularly vigilant, as this vulnerability could lead to unauthorized access to customer information and significant privacy breaches. The urgency of the situation is heightened by the rapid targeting of the flaw by cybercriminals, making it critical for affected organizations to act quickly to safeguard their systems and user data.

Read Original

A wave of tools claiming to remove watermarks from AI-generated text has appeared online following Anthropic's decision to add watermarks to content produced by its AI model, Claude. These tools include a popular open-source project on GitHub and various paid services designed to help users evade detection. However, none of these tools have been validated; Anthropic has not released a method to confirm whether the watermark removal claims are legitimate. This situation raises concerns about the integrity of AI-generated content and the potential for misuse, as users may rely on unverified tools to bypass detection mechanisms. The proliferation of such tools could complicate efforts to ensure accountability and transparency in AI-generated materials.

Read Original

Recent research indicates that mid-tier artificial intelligence models are becoming more adept at hacking, raising concerns among cybersecurity experts. While much attention has been on the advanced AI systems and their exploits, these cheaper and more efficient models are now capable of performing sophisticated attacks. This evolution poses a significant risk as it expands the pool of potential attackers, making it easier for individuals with less technical skill to engage in cybercrime. Companies and organizations must be aware of this shift and take proactive measures to strengthen their defenses against a wider range of threats. The implications of this development could affect numerous sectors, as the availability of these hacking tools increases the likelihood of cyber incidents.

Read Original

Ahead of the upcoming U.S. midterm elections, cybersecurity experts are warning about the potential risks posed by botnets. These networks of compromised computers could be employed to disrupt voting processes or manipulate information online. Election security teams need to be vigilant, ensuring that systems are fortified against such attacks. The focus is on ensuring the integrity of the electoral process, as even minor disruptions could lead to widespread consequences for public trust in the democratic system. The implications of these threats are significant, as they could affect not just the election outcome, but also citizens' perceptions of election security.

Read Original

Trezor, a manufacturer of hardware wallets, has reported a data breach that has impacted nearly 14,000 customers. The breach occurred after ShipMonk, the company's shipping and logistics provider, was hacked. As a result, sensitive customer information, including names and email addresses, may have been exposed. Trezor has stated that no funds or private keys were compromised, but the incident raises concerns about the security of third-party services used by companies. Customers are advised to be vigilant regarding potential phishing attempts that may arise from this breach.

Read Original

A new backdoor named PATCHCORD is targeting telecom providers in Afghanistan and critical infrastructure in South Asia. Researchers from Acronis Threat Research Unit found that this backdoor is delivered through deceptive methods, such as fake VPN installers that impersonate Afghan Telecom. This ongoing campaign poses significant risks as it aims at crucial communication and infrastructure systems, potentially leading to data breaches or disruption of services. The use of sector-specific lures indicates a tailored approach by the attackers, which raises concerns about the sophistication of these threats. Organizations in these regions need to be vigilant and enhance their cybersecurity measures to protect against such targeted attacks.

Read Original
PreviousPage 23 of 363Next