Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Actively Exploited

Mercor, an AI recruiting firm, is currently facing a significant security incident after a supply chain attack attributed to the cybercriminal group Lapsus$. The attackers claim to have stolen around 4 terabytes of data from the company. This breach raises serious concerns about the security of sensitive information related to recruitment and hiring processes, which could potentially impact both job seekers and employers using Mercor's services. The firm is actively investigating the breach to assess the extent of the damage and to implement necessary security measures. The situation highlights the risks associated with supply chain vulnerabilities, especially in sectors that rely heavily on technology and data management.

Read Original
Critical
Why GitHub Developers Are Targeted by Token Giveaway Scams

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

GitHub developers are increasingly being targeted by token giveaway scams, which promise fake rewards in exchange for personal information or cryptocurrency. These scams typically involve malicious links or repositories that appear legitimate but are designed to trick users into giving away sensitive data. Experts recommend that developers verify repositories, links, and maintainers before engaging with any offers. The urgency often created by these scams can lead to hasty decisions, resulting in compromised wallets and stolen tokens. This growing trend is a significant concern for the developer community, as falling victim to these scams can have serious financial and reputational consequences.

Read Original
Actively Exploited

Researchers have identified a new type of malware called CrystalX RAT, which poses serious risks to users by spying on them and stealing sensitive information. This remote access Trojan (RAT) can also alter device configurations, making it a potent tool for cybercriminals. The malware's sophisticated capabilities suggest that it could be used in targeted attacks against individuals or organizations. Users need to be vigilant and ensure their security measures are up to date to protect against this emerging threat. The discovery of CrystalX RAT emphasizes the ongoing challenges in cybersecurity and the need for continuous awareness and protection against evolving malware.

Read Original

WhatsApp has informed around 200 users that they were deceived into installing a counterfeit version of its iOS app, which contained spyware. Most of the affected individuals are based in Italy. The attackers reportedly employed social engineering tactics to trick users into downloading the malicious app. This incident raises concerns about the security of mobile applications and highlights the need for users to be vigilant about the sources from which they download software. With spyware potentially compromising personal information, it is crucial for users to ensure they are using legitimate applications from trusted sources.

Read Original

Microsoft is currently addressing an issue that affects some users of Classic Outlook trying to send emails through Outlook.com. The problem has been acknowledged as part of ongoing investigations into email delivery failures. While the company has not specified the exact number of users impacted, it is clear that those relying on Classic Outlook for their email communications are experiencing significant disruptions. This situation is important because it highlights the challenges users may face with legacy software in modern environments, potentially affecting business communications and personal messaging. Microsoft is working on a solution, but users should be aware of potential delays in their email delivery until the issue is resolved.

Read Original

A recent report from E2e-assure reveals that around 80% of critical infrastructure providers could face significant downtime, potentially costing them up to £5 million, due to cyber-attacks targeting operational technology (OT). These attacks can disrupt essential services, affecting everything from energy supply to transportation systems. The findings underscore the urgent need for these organizations to bolster their cybersecurity measures to protect against increasing threats. As cyber incidents become more common, the financial implications could be severe, leading to not just loss of revenue but also compromised public safety. This situation calls for immediate attention as critical infrastructure remains a prime target for malicious actors.

Read Original

WhatsApp has taken action against a fake version of its app created by the Italian spyware vendor SIO/Asigint, which targeted around 200 users, primarily in Italy. This malicious app was designed to install spyware on users' devices, compromising their privacy and security. WhatsApp is urging affected users to uninstall the fake app and reinstall the official version to protect themselves from potential data breaches. The incident serves as a reminder of the dangers posed by unofficial apps, which can often carry hidden threats. Users need to be vigilant and ensure they download apps only from trusted sources to avoid similar risks.

Read Original

Hackers have exploited a zero-day vulnerability in TrueConf conference servers, which enables them to execute arbitrary files on all connected endpoints. This means that attackers can potentially install malicious software on users' devices without their knowledge. The vulnerability poses a significant risk to organizations using TrueConf for video conferencing, especially as it allows for remote execution of harmful code. Users of TrueConf should be particularly vigilant and consider updating their systems to protect against these types of attacks. Security researchers are urging companies to monitor their networks for any suspicious activity related to this vulnerability.

Read Original

Cyberattacks are on the rise in Latin America, specifically targeting government systems. In Puerto Rico, there have been disruptive attacks that have affected government operations. Meanwhile, Colombia's health sector is facing a surge of probing activities, raising concerns about data integrity and system security. These incidents reflect a growing trend of cyber threats in the region, putting government agencies and public services at risk. As these attacks escalate, they not only disrupt essential services but also pose a challenge for authorities in maintaining public trust and safety.

Read Original

A recent report by StateScoop reveals that many Americans are increasingly worried about how the government manages their personal data. As federal agencies request more information from state governments, citizens feel they lack control over their data sharing. This concern reflects a broader unease about privacy and data security in a digital age where personal information is frequently collected and shared. The call for greater control over personal data management underscores the need for clear policies and protections to safeguard citizens' information from misuse. This situation raises questions about the balance between government data needs and individual privacy rights, making it a significant topic for ongoing public discourse.

Read Original
Actively Exploited

Cybersecurity incidents are increasingly being driven by identity theft, particularly through stolen login credentials. Reports indicate that attackers are using these stolen credentials as a primary way to infiltrate systems, leading to a surge in ransomware attacks. This trend poses significant risks for companies and individuals alike, as unauthorized access can lead to data breaches and financial losses. Organizations need to strengthen their security measures and educate users on the importance of password hygiene and multi-factor authentication to combat this rising threat. The alarming rise in credential abuse emphasizes the need for vigilance in cybersecurity practices.

Read Original
Actively Exploited

Cybercriminals are sending out fake LinkedIn alert messages that claim to offer job opportunities, but their real goal is to steal user credentials. This phishing campaign tricks recipients into providing sensitive information, putting their accounts at risk. The fraudulent messages imitate legitimate notifications from LinkedIn, making them difficult to detect. Users who fall for this scam could find their personal data compromised, leading to potential identity theft or unauthorized access to their accounts. It's essential for LinkedIn users to be cautious and verify messages before clicking on any links or providing information.

Read Original
Actively Exploited

A recent report from Infosecurity Magazine reveals that the Phantom Stealer, a .NET-based malware, has been targeting manufacturing, technology, and logistics sectors across Europe. This malware is part of the Phantom Project cybercrime kit, which also includes a crypter and a remote access tool. The attacks occurred in a series of phishing campaigns from November 2025 to January 2026. Organizations in these industries should be aware of the potential for data breaches and operational disruptions due to these ongoing attacks. The targeted sectors are crucial for the economy, making the successful exploitation of these vulnerabilities particularly concerning.

Read Original

Hasbro, the well-known toy company, is currently investigating a cyberattack that has affected its operations. While details are still emerging, the company is looking into the possibility of compromised files, which could potentially expose sensitive information. This incident raises concerns not only for Hasbro but also for customers and partners who may be impacted by data breaches or operational disruptions. As the investigation unfolds, it will be crucial for Hasbro to communicate transparently with stakeholders and take necessary steps to secure its systems. Cyberattacks on major companies like Hasbro remind us that even well-established brands are vulnerable to security threats.

Read Original
Anthropic Leaks 512,000 Lines of Claude AI Code in Major Blunder

Hackread – Cybersecurity News, Data Breaches, AI and More

Anthropic, the AI research company, accidentally exposed over 512,000 lines of code related to its Claude AI system. This significant leak included sensitive information about two of its projects, KAIROS and Capybara. As a result, users are being urged to switch to the Native Installer to mitigate any potential risks associated with this exposure. The incident raises concerns about data security and the safeguards in place for proprietary code, especially given the competitive nature of the AI industry. It serves as a reminder of how human error can lead to significant breaches of confidentiality and proprietary information.

Read Original
PreviousPage 236 of 372Next