Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A recent study by GreyNoise has revealed that a significant portion of malicious online activity, about 39%, comes from home networks, likely linked to residential proxy services. These proxies allow users to mask their true IP addresses, making it harder for security systems to identify and block malicious traffic. This trend poses a challenge for companies trying to maintain accurate IP reputation systems, as the line between legitimate and malicious traffic blurs. As residential proxies become more common, organizations may find it increasingly difficult to protect themselves from various cyber threats. This situation raises concerns for businesses relying on IP reputation to manage online security.

Read Original
Actively Exploited

Recent analysis has revealed that a malware known as Chaos is now targeting 64-bit Linux servers, primarily associated with groups linked to China. Researchers found that these attackers are employing a two-pronged strategy: one that acts quickly and another that allows for longer dwell times within compromised systems. This dual approach not only increases the chances of successful infiltration but also makes it harder for organizations to detect and respond to the attacks. Given the prevalence of Linux servers in various industries, this development poses a significant risk to a wide range of businesses, potentially leading to data breaches and service disruptions. Companies using Linux servers are urged to enhance their security measures to defend against this escalating threat.

Read Original

Hims & Hers Health, a telehealth service provider, has reported a data breach due to stolen support tickets from Zendesk, a third-party customer service platform. This incident raises concerns as it potentially exposes sensitive information from users who sought medical advice or treatment through the service. The company is urging affected users to stay vigilant about their personal information and to monitor their accounts for any suspicious activity. This breach underscores the risks associated with relying on third-party vendors for customer support and handling sensitive data. Users should be aware of possible phishing attempts or unauthorized access to their accounts following this incident.

Read Original

A Chinese cyber group known as TA416 has been targeting European government and diplomatic entities since mid-2025, resuming its activities after a two-year lull. This campaign employs malware like PlugX and uses OAuth-based phishing techniques to compromise systems. TA416 is linked to various other hacking groups, including DarkPeony and RedDelta, indicating a broader network of cyber threats. The resurgence of these attacks raises concerns about the vulnerability of government institutions in Europe, especially given the increasing geopolitical tensions. Authorities and organizations need to bolster their cybersecurity measures to protect sensitive information from these state-sponsored actors.

Read Original
Critical
North Korean Hackers Abuse GitHub to Spy on South Korean Firms

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

North Korean hackers have launched a significant spying campaign aimed at South Korean companies, according to researchers from FortiGuard Labs. This operation leverages GitHub, a widely used platform for software development, to facilitate their espionage activities. By creating malicious repositories, the attackers are able to trick employees into downloading harmful code that compromises their systems. Companies involved in critical sectors such as technology and defense are particularly at risk. This incident raises alarms about the ongoing threat posed by state-sponsored hacking groups and highlights the need for stronger cybersecurity measures among targeted organizations.

Read Original

The Qilin ransomware group has targeted Die Linke, a German political party, causing significant disruption to its IT systems. This attack not only resulted in a systems outage but also included threats of leaking sensitive data. The party confirmed that data had indeed been stolen during the breach. This incident raises concerns about the security of political organizations, especially in light of upcoming elections and the potential for sensitive information to be weaponized. As cyberattacks against political entities become more common, the implications for privacy and security in the political arena are increasingly serious.

Read Original

The Trump administration has proposed a budget that includes significant cuts to the Cybersecurity and Infrastructure Security Agency (CISA), amounting to hundreds of millions of dollars. This proposal has drawn sharp criticism from a leading congressional Democrat, who argues that reducing funding for CISA could undermine the nation's cybersecurity efforts. CISA plays a crucial role in protecting the country's critical infrastructure and responding to cyber threats. With the increase in cyberattacks and threats to national security, the proposed cuts raise concerns about the agency's ability to effectively safeguard against these dangers. This budget proposal, if enacted, could have serious implications for the security of government and private sector networks alike.

Read Original
Critical
AI Firm Mercor Confirms Breach as Hackers Claim 4TB of Stolen Data

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Mercor, an AI firm, has confirmed a significant data breach linked to a supply chain attack involving LiteLLM. Hackers claim to have stolen 4TB of sensitive data, which may include internal systems and proprietary information. This breach raises serious concerns about the security of supply chain processes, as attackers often exploit vulnerabilities in third-party software to gain access to larger networks. Companies that rely on LiteLLM and similar technologies should be particularly vigilant and assess their security measures. The implications of such a large data theft could be severe, affecting not only Mercor but also its clients and partners who may be at risk of data exposure or further attacks.

Read Original

Researchers from watchTowr have discovered two significant vulnerabilities in Progress ShareFile, specifically within the Storage Zones Controller (SZC) component of versions 5.x. The first vulnerability, identified as CVE-2026-2699, is an authentication bypass that could allow unauthorized users to access files. The second flaw, CVE-2026-2701, is a remote code execution vulnerability that could enable attackers to run arbitrary code on affected systems. These vulnerabilities pose a serious risk to organizations using ShareFile, as they could lead to unauthorized data access and potential exploitation. It is crucial for users to take immediate action to secure their systems against these vulnerabilities.

Read Original

The article discusses the rise of multi-extortion ransomware attacks, where attackers not only encrypt a victim's data but also threaten to leak sensitive information if their demands aren't met. This tactic adds pressure on victims, as the potential for public exposure can be damaging. Penta Security has developed a solution called the D.AMO platform, which aims to keep exfiltrated files encrypted, rendering them useless to attackers. This technology is crucial for organizations looking to protect their data from exploitation in such attacks. As ransomware tactics evolve, understanding and mitigating these risks is increasingly important for businesses of all sizes.

Read Original

Drift, a company involved in cryptocurrency, has suffered a significant loss of $285 million due to a sophisticated hacking operation likely orchestrated by North Korean cybercriminals. The attackers employed advanced techniques, including the use of nonce-based tricks to pre-sign transactions and delay approvals, allowing them to bypass security measures. This incident raises alarms about the vulnerabilities in cryptocurrency platforms and the potential for state-sponsored actors to exploit these weaknesses for financial gain. The scale of the theft not only impacts Drift but also poses broader implications for the cryptocurrency market, as it highlights the ongoing risks of cyberattacks in this rapidly evolving sector. As companies like Drift face these threats, it becomes crucial for the industry to bolster security measures to protect against such sophisticated attacks.

Read Original

The article discusses recent incidents where source code leaks have exposed vulnerabilities in software supply chains. These leaks reveal a concerning lack of oversight in how software is developed and maintained, affecting various companies that rely on third-party code. Without proper security measures, these weaknesses can be exploited by cybercriminals, potentially leading to widespread attacks on critical infrastructure. The piece argues for stronger regulations and security practices to safeguard against these risks, emphasizing that software supply chains should be treated with the same importance as traditional infrastructure. As the reliance on software grows, the need for vigilance and oversight becomes increasingly urgent.

Read Original

A new spear-phishing campaign has emerged, targeting senior executives and effectively bypassing multi-factor authentication (MFA) systems. This attack utilizes a recently identified phishing kit named VENOM, which allows attackers to craft convincing emails that trick recipients into providing sensitive information. The campaign poses a significant risk to businesses, as executives often have access to critical company data and systems. If successful, these attacks can lead to data breaches and financial losses. Companies must be vigilant and enhance their security measures to protect against such sophisticated phishing threats.

Read Original
Actively Exploited

WebinarTV has been found to be secretly joining public Zoom meetings, recording them, and then publishing the recordings online without the consent of the participants. This practice raises serious privacy concerns as it circumvents Zoom's built-in recording feature, making it difficult for the platform to take action against these recordings. Users who share sensitive information during these meetings could be at risk of having that information exposed to the public. The situation highlights the need for individuals and organizations to be more cautious about the privacy settings of their online meetings. Companies should consider implementing stricter access controls and educating their teams about the risks of public meeting invites to protect sensitive discussions.

Read Original

The maintainer of the Axios npm package, Jason Saayman, revealed that a recent supply chain attack was linked to a targeted social engineering effort by North Korean hackers known as UNC1069. The attackers specifically tailored their approach to Saayman, initially posing as the founder of a prominent organization to gain his trust. This incident raises significant concerns about the security of open-source software, as it shows how easily even experienced developers can be manipulated. The compromise could potentially expose countless projects that rely on Axios, a popular library used in web development. Developers and organizations using Axios need to be vigilant and review their dependencies to prevent exploitation stemming from this attack.

Read Original
PreviousPage 233 of 372Next