Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A Russian-linked hacking group known as TA446 is actively targeting iPhone users through a new phishing campaign that employs the DarkSword iOS exploit kit. These attacks involve sending malicious emails designed to compromise iOS devices, putting users' personal information at risk. The group, also referred to as SEABORGIUM and ColdRiver, has been noted for its sophisticated tactics in the past. This wave of phishing emphasizes the increasing dangers that smartphone users face, especially as attackers refine their methods to bypass security measures. As these campaigns evolve, it’s crucial for iPhone users to remain vigilant about suspicious emails and links.

Read Original
Actively Exploited

The European Commission has confirmed that its Europa.eu web platform experienced a data breach following a cyberattack attributed to the ShinyHunters extortion gang. This group is known for targeting various organizations and leaking sensitive information online. The breach raises concerns about the security of personal data held by the European Commission, which could potentially affect thousands of users who interact with the platform. The incident highlights ongoing cybersecurity challenges faced by governmental institutions in safeguarding sensitive information. As investigations continue, it remains crucial for affected individuals to stay informed about potential fallout and take necessary precautions to protect their data.

Read Original

Researchers from the University of Oxford and the AI Security Institute have created a benchmark called SandboxEscapeBench. This tool tests whether AI agents can break free from their container sandboxes, which are used to safely run code and access system resources without risking the host system. The benchmark specifically evaluates scenarios where an AI agent has shell access, aiming to determine if it can escape the confines of its sandbox. This research is significant because if AI agents can escape, they might pose risks to the systems they were intended to protect. Understanding these vulnerabilities is crucial for developers and organizations that rely on AI technologies.

Read Original
Actively Exploited

The latest Malware newsletter from Security Affairs reports on several significant cybersecurity threats. One notable incident involves new malware specifically targeting users of Cobra DocGuard software, potentially compromising sensitive data. Additionally, Iranian cyber actors have been using Telegram as a command and control channel to distribute malware to predetermined targets, raising concerns about state-sponsored cyber activities. The newsletter also discusses the Trivy supply chain attack, which has now expanded to include compromised Docker images, putting many containerized applications at risk. Lastly, a new malware called VoidStealer has been identified, which manipulates Chrome debugging tools to extract user information. These developments highlight ongoing vulnerabilities in software and the tactics employed by cybercriminals and state actors alike.

Read Original

In a recent cybersecurity incident, the hacking group ShinyHunters has claimed responsibility for breaching a European Commission group linked to Iran, known as Handala. This attack has raised concerns about the security of sensitive information and the potential implications for international relations. Additionally, the group reportedly hacked FBI Director Kash Patel’s personal data, which could expose vulnerabilities in U.S. federal cybersecurity measures. The incidents underline the ongoing risks associated with state-sponsored hacking and the need for improved defenses against such threats. As these attacks come to light, organizations and governments may need to reassess their cybersecurity protocols to protect against similar intrusions in the future.

Read Original

At the BSides SF 2026 hacker conference, a researcher warned that Software as a Service (SaaS) and cloud assets are increasingly vulnerable to identity-based ransomware attacks. This type of attack exploits weaknesses in identity management systems, allowing attackers to gain unauthorized access and encrypt critical data. Organizations that rely on cloud services for their operations, especially those with inadequate security measures in place, are at significant risk. The researcher emphasized that as more businesses transition to these platforms, the need for robust identity protection becomes essential. Companies should prioritize enhancing their identity security protocols to mitigate these risks and protect sensitive customer information.

Read Original

At the RSAC 2026 conference, researchers discussed the emergence of Shai-Hulud worms, which have taken advantage of automatic updates in open-source software repositories. They warned that these types of supply-chain attacks may become more common, posing significant risks to software integrity and security. This could affect a wide range of organizations that rely on open-source software for their operations. The implications are serious, as attackers could potentially infiltrate systems through seemingly legitimate software updates, compromising sensitive data and systems. Companies using open-source solutions need to be vigilant and implement stricter security measures to protect against these evolving threats.

Read Original
ShinyHunters Claims 350GB Data Breach at European Commission

Hackread – Cybersecurity News, Data Breaches, AI and More

ShinyHunters, a notorious hacking group, claims to have breached the European Commission's systems, resulting in the leak of 350GB of sensitive data. This incident raises significant concerns about the security of governmental data and the potential implications for privacy and national security. The European Commission is currently investigating the breach, but as of now, there has been no independent verification of ShinyHunters' claims. Such a large data leak could expose confidential communications and personal information, which might lead to further cyber threats or exploitation. The situation underscores the need for robust cybersecurity measures within governmental organizations to protect against such attacks.

Read Original

Iranian hackers known as the Handala Hack Team have breached the personal email account of Kash Patel, the director of the FBI. They leaked various sensitive photos and documents online, claiming that Patel is now among their list of successful targets. This incident raises concerns about the security of personal email accounts for high-ranking officials and the potential for sensitive information to be misused. The breach not only affects Patel personally but also poses broader implications for national security, as it demonstrates the vulnerability of even top-tier officials to cyberattacks. Such incidents can undermine public trust in the security measures protecting important government figures and their communications.

Read Original
Lloyds Group to Compensate 450,000 Customers After App Glitch

Hackread – Cybersecurity News, Data Breaches, AI and More

Lloyds Banking Group has announced plans to compensate around 450,000 customers due to a glitch in their mobile banking app that unintentionally exposed sensitive customer data. The issue arose when certain users were able to see details of other customers' accounts, including names and transaction histories. This incident raises significant concerns about data privacy and security, as affected individuals may worry about the potential misuse of their information. Lloyds is working to address the problem and ensure that such vulnerabilities are not repeated in the future. The compensation is part of their effort to regain customer trust after this security mishap.

Read Original

An Iranian hacking group named Handala claims to have breached the personal email account of FBI Director Kash Patel, leaking various files and photos. The FBI has acknowledged the incident but stated that no sensitive government data was compromised in the breach. This incident raises concerns about the security of personal accounts held by high-ranking officials, as attackers may seek to exploit such information for various motives. While the FBI is aware of the situation, the lack of exposed government data may provide some reassurance, though it still points to the ongoing risks posed by state-sponsored hacking groups targeting individuals in influential positions.

Read Original
High
Iran-Linked Handala Hackers Breach FBI Chief Kash Patel’s Gmail

Hackread – Cybersecurity News, Data Breaches, AI and More

Iran-linked hackers known as Handala have successfully breached the Gmail account of FBI Chief Kash Patel, resulting in the leak of various personal photos and documents. While officials have stated that no classified information was compromised in this incident, the breach raises concerns about the security of sensitive communications within high-ranking government officials. The exposure of personal data could potentially lead to further security risks or exploitation. This incident serves as a reminder of the ongoing cyber threats posed by state-sponsored actors and the importance of robust security measures for public officials. As the investigation unfolds, it remains crucial for government agencies to assess their cyber defenses against such targeted attacks.

Read Original
Critical
ShinyHunters Walk Away from BreachForums, Leak 300,000-User Database

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

ShinyHunters, a notorious hacking group, has departed from BreachForums and leaked a database containing information on 300,000 users. This data breach raises alarms as ShinyHunters warns that all active domains associated with the leak are fake, suggesting that users should be cautious of phishing attempts. The group has also threatened to release more data from forum backups, indicating that the situation could worsen. Users affected by this breach may have their personal information exposed, which could lead to identity theft or other malicious activities. This incident underscores the ongoing risks associated with online forums and the potential for significant data leaks.

Read Original

Researchers from OX Security have found that AI coding assistants often make the same types of mistakes as human developers. This suggests that while these tools can increase productivity, they are not infallible and can introduce coding errors into software. The study emphasizes the need for developers to treat AI tools like junior developers, meaning they should verify and review the code generated by these assistants thoroughly. This approach is crucial for companies relying on AI for software development, as it highlights the importance of maintaining coding standards and ensuring quality control. The findings serve as a reminder that while AI can assist in coding, human oversight is still essential to catch errors that could lead to vulnerabilities in applications.

Read Original

The European Commission reported a cyberattack that targeted its cloud infrastructure, specifically affecting the systems that host its Europa.eu websites. The attack was detected on March 24 and was swiftly contained, with measures put in place to prevent any disruption to website availability. Fortunately, there was no impact on the Commission's internal networks. Initial investigations indicate that while the attack was serious enough to warrant immediate action, it did not compromise the integrity or accessibility of the websites involved. This incident raises concerns about the security of cloud systems used by public institutions and emphasizes the need for robust cybersecurity measures.

Read Original
PreviousPage 242 of 372Next