Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

In 2023, the Spring Application Framework has seen significant security updates, with 91 vulnerabilities patched this year alone. This marks a notable increase compared to previous years, where only 16 vulnerabilities were addressed in 2025 and 22 in 2024. These vulnerabilities can potentially affect a wide range of applications built on the Spring Framework, which is widely used in enterprise software development. Developers and organizations utilizing Spring should prioritize updating to the latest versions to safeguard their applications. As cyber threats continue to evolve, keeping software up to date is crucial for maintaining security and protecting sensitive data.

Read Original

Red Hat and the Keycloak project have issued important patches to fix a severe security vulnerability in Keycloak, an open-source identity and access management server. This flaw, identified as CVE-2026-18963, allows unauthenticated attackers to reset passwords and potentially take over any user account without needing prior access. Rated 9.1 on the CVSS scale, this vulnerability poses a significant risk to organizations using Keycloak for managing user identities and access. Users and administrators are strongly advised to apply the patches immediately to protect their systems and prevent unauthorized account access.

Read Original

Researchers have identified a cyber espionage campaign aimed at Myanmar's government and IT sectors, dubbed Operation QUICSILVER. This operation employs a deceptive tactic, using graduation ceremony invitations to lure victims into downloading a malicious Go backdoor known as QUICAgent. The campaign is believed to be orchestrated by a threat actor connected to China, suggesting a state-sponsored motivation behind the attacks. The targeting of government and technology sectors raises concerns about the potential for sensitive data breaches and the undermining of national security. As cyber threats continue to evolve, the implications for Myanmar's digital infrastructure could be significant.

Read Original

The article discusses the security risks associated with short-lived workloads, which are increasingly common in cloud environments. These ephemeral identities can create long-lasting identity risks as traditional security governance struggles to keep up. Organizations often fail to manage these temporary identities effectively, leading to potential unauthorized access or data breaches. This issue is particularly relevant for companies that rely on dynamic cloud services, as they need to adopt more agile security measures to protect sensitive information. As the use of short-lived workloads continues to rise, addressing these identity management challenges becomes crucial for maintaining overall cybersecurity.

Read Original

Akamai's recent research reveals that a small group of AI super-users, making up only 5% of employees in enterprises, poses a significant security risk. While security teams are focused on managing the everyday use of AI tools like ChatGPT and Claude, these power users are integrating unverified AI applications into essential business processes. This behavior can lead to vulnerabilities as these tools may not have undergone proper security assessments. The implications are serious, as critical operations could be compromised due to the lack of oversight and potential malicious exploitation. Companies need to address this issue by implementing stricter controls and guidelines around AI tool usage to protect their operations.

Read Original

Juan Manuel Gouveia-Aguilera has been sentenced to eight years in federal prison for his involvement in an ATM jackpotting scheme that resulted in millions of dollars in losses. Jackpotting is a method where attackers exploit vulnerabilities in ATMs to dispense cash fraudulently. Gouveia-Aguilera's actions significantly impacted financial institutions and customers who rely on ATM services. This case serves as a reminder of the ongoing challenges banks face in securing their systems against sophisticated attacks. Law enforcement continues to target such criminal activities to protect consumers and maintain the integrity of financial services.

Read Original

The US Cybersecurity and Infrastructure Security Agency (CISA) is urging federal agencies to rethink their logging practices to ensure that logs can effectively help in detecting and understanding cyberattacks. The Logging Reference Architecture (LRA), released in August 2026, serves as a guideline for federal civilian agencies to comply with logging requirements set by the Office of Management and Budget. However, CISA also encourages critical infrastructure operators and other governmental organizations to adopt these practices. The focus is on whether organizations can utilize their log data to trace back and analyze incidents when they occur. This guidance aims to bolster the security posture of not just government entities but also the broader critical infrastructure sector, which is increasingly targeted by cyber threats.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for U.S. government agencies to patch a vulnerability in the Zimbra Collaboration Suite (ZCS) within three days. This flaw is currently being exploited by attackers, raising concerns about the potential for data breaches and unauthorized access to sensitive information. Zimbra is widely used for email and collaboration, making it critical that organizations act quickly to secure their systems. The agency's move underscores the need for immediate action to prevent exploitation and safeguard government communications. Agencies should ensure their ZCS installations are updated to mitigate this risk effectively.

Read Original

Apollo Global, a private equity firm, has suffered a data breach that has exposed personal information of its clients. This incident appears to be part of a broader trend where attackers are targeting large financial institutions. While details on the specific data compromised are still emerging, the breach raises concerns about the security of sensitive financial information. Clients and stakeholders should remain vigilant as the fallout from this breach could have significant implications for their privacy and security. The incident underscores the risks that financial companies face in safeguarding their data against increasingly sophisticated cyberattacks.

Read Original

Iranian hackers successfully targeted a power plant in the UK, causing a shutdown that lasted four days. This incident disrupted operations and raised alarms about the vulnerability of the UK's energy infrastructure. Experts are particularly concerned about the potential for similar attacks in the future, emphasizing the need for improved defenses against cyber threats. The breach underscores the ongoing risks posed by state-sponsored hacking groups, especially those linked to Iran. As the energy sector increasingly relies on digital systems, ensuring their security is becoming more critical than ever.

Read Original

TikTok has agreed to a $400 million settlement with the U.S. Justice Department related to violations of children's privacy laws. The company will pay $300 million upfront and an additional $100 million contingent upon the dismissal of a previous consent decree involving its predecessor, Musical.ly. This settlement arises from allegations that TikTok collected personal data from minors without proper consent, raising concerns about the protection of children's online privacy. The outcome of this settlement is significant as it underscores the ongoing scrutiny of social media platforms and their practices regarding user data, particularly for younger audiences. The financial penalties serve as a warning to other companies about the importance of compliance with privacy regulations.

Read Original
Actively Exploited

A recent cyber-attack attributed to Iranian hackers has caused a shutdown of a power plant in the UK, raising concerns about the vulnerabilities in the country’s critical national infrastructure (CNI). Experts are warning that this incident reveals significant weaknesses in the systems that support essential services like electricity generation. The attack not only disrupted operations but also served as a wake-up call for the government and private sector to bolster their cybersecurity defenses. As the threat of state-sponsored cyber activities continues to rise, stakeholders are urged to reassess their security measures to protect against future incidents. This attack could have broader implications for national security and public safety if similar vulnerabilities are exploited elsewhere.

Read Original

The article discusses concerns surrounding the use of AI agents in cybersecurity, particularly focusing on the risks associated with AI penetration testing tools. As organizations increasingly adopt these technologies, there are questions about the legal liabilities and potential misuse of AI agents. Employees using these tools might unintentionally expose their companies to security vulnerabilities or legal repercussions if the AI behaves unpredictably. The discussion emphasizes the need for clear guidelines and training for employees to safely utilize AI in their cybersecurity efforts. This is particularly important as companies strive to balance innovation with security and compliance.

Read Original

Slovakia's National Security Authority (NBÚ) has issued a warning about vulnerabilities in certain road speed cameras. These weaknesses could allow attackers to access vehicle data and potentially gain remote control of the cameras, posing risks to public networks. This alert is not about tampering with speeding tickets; instead, it emphasizes a serious cybersecurity concern that could affect traffic management and public safety. The NBÚ's warning serves as a reminder for the need to secure critical infrastructure, as these vulnerabilities could be exploited for malicious purposes. Addressing these issues promptly is essential to protect both motorists and the integrity of public systems.

Read Original

TikTok has agreed to pay $400 million to settle a lawsuit in the United States regarding its collection of data from users under the age of 13. This settlement comes after claims that the social media platform violated child privacy laws. The lawsuit, announced by the U.S. Department of Justice, emphasizes the importance of protecting children's personal information online. By settling, TikTok aims to resolve the legal issues without admitting to any wrongdoing. This case is significant as it highlights ongoing concerns about data privacy for minors and sets a precedent for how similar cases may be handled in the future.

Read Original
PreviousPage 23 of 384Next