Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Ivanti customers are facing a new security challenge as attackers exploit a zero-day vulnerability in a popular mobile endpoint security product. This flaw allows unauthorized access to victim networks, making it a prime target for cybercriminals. The issue is particularly pressing as Ivanti's products are widely used in various organizations, raising concerns about the potential scale of the attacks. Companies relying on these security solutions are urged to take immediate action to safeguard their networks. The ongoing exploitation of this vulnerability highlights the need for vigilance in maintaining cybersecurity measures and prompt updates to security software.

Impact: Ivanti mobile endpoint security products
Remediation: Organizations should update their Ivanti mobile endpoint security products to the latest version as soon as patches are available. Regularly reviewing security configurations and monitoring network activity for unusual behavior are also recommended mitigation strategies.
Read Original
Hackers Use Fake Claude AI Site to Infect Users With New Beagle Malware

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Researchers have identified a new cybersecurity threat involving a fake Claude AI website that is being used to distribute an undocumented backdoor known as Beagle. This malicious campaign leverages malvertising techniques to deceive users into downloading the malware, which can compromise their devices. As more people seek out AI tools, attackers are exploiting this interest to target unsuspecting users. The Beagle malware can potentially allow unauthorized access to a user's system, raising serious concerns about data security and privacy. Users should be cautious when visiting unknown sites and ensure their security software is up to date to protect against such threats.

Impact: Users visiting fake Claude AI websites
Remediation: Users should avoid visiting suspicious websites and ensure their antivirus software is updated and running.
Read Original

A new malware called PCPJack has emerged, replacing the previously known TeamPCP malware. This new variant cleverly utilizes parquet files to conduct stealthy reconnaissance across various cloud environments, allowing it to identify and target vulnerable systems without detection. The implications of PCPJack are significant, as it poses a risk to organizations that rely on cloud infrastructure for their operations. By exploiting these environments, attackers could potentially access sensitive data and cloud secrets, raising concerns about data security and privacy. Companies using cloud services should be vigilant and ensure their security measures are up to date to defend against this evolving threat.

Impact: Cloud environments and services
Remediation: Organizations should enhance their cloud security protocols and monitor for unusual file activity. Regular updates and audits of security configurations are also recommended.
Read Original

A new malware known as PCPJack has emerged, targeting exposed cloud infrastructure to steal user credentials. This worm not only pilfers sensitive information but also actively works to remove any existing access that the earlier TeamPCP malware had established on infected systems. The implications of PCPJack are significant, as it compromises cloud security and can lead to further unauthorized access and data breaches. Organizations with vulnerable cloud setups are particularly at risk, as the worm exploits weaknesses to gain access. Users and companies must bolster their security measures to protect against this evolving threat.

Impact: Exposed cloud infrastructure, TeamPCP infections
Remediation: Organizations should enhance cloud security protocols, monitor for unauthorized access, and remove any traces of TeamPCP infections.
Read Original

The Australian Cyber Security Center (ACSC) has issued a warning about a new malware campaign that uses a technique called ClickFix to spread the Vidar Stealer malware. This malware is designed to steal sensitive information from compromised systems. Organizations across various sectors are at risk of falling victim to these attacks, as the ClickFix method relies on social engineering tactics to trick users into downloading the malicious software. The ACSC emphasizes the importance of vigilance and recommends that businesses implement robust security measures to protect against these types of threats. As the campaign is currently active, companies need to be proactive in their cybersecurity efforts to avoid potential data breaches and financial losses.

Impact: Vidar Stealer malware affects organizations that may be tricked by ClickFix social engineering techniques.
Remediation: Organizations should implement strong security measures, including staff training on recognizing phishing attempts and ensuring up-to-date antivirus software.
Read Original

Ivanti has alerted its customers about a severe vulnerability in its Endpoint Manager Mobile (EPMM) software that is being actively exploited in zero-day attacks. This security flaw allows attackers to execute remote code, posing a significant risk to organizations using this mobile device management solution. Companies utilizing EPMM should prioritize applying the necessary patches to protect their systems. The vulnerability affects multiple versions of the software, making it crucial for users to act quickly. Failure to address this issue could lead to unauthorized access and potential data breaches, emphasizing the importance of timely updates in cybersecurity practices.

Impact: Ivanti Endpoint Manager Mobile (EPMM), affected versions not specified
Remediation: Customers should patch the high-severity vulnerability as soon as possible, specific patch details not provided
Read Original

Cisco has addressed several serious vulnerabilities in its enterprise products, particularly in Unity Connection. These flaws, identified as CVE-2026-20034 and CVE-2026-20035, could allow attackers to execute code, perform server-side request forgery (SSRF), or disrupt services. If exploited, these vulnerabilities could have significant implications for organizations using affected Cisco products, potentially leading to unauthorized access or service outages. Cisco has released patches to fix these issues, urging users to update their systems promptly to mitigate risks associated with these high-severity vulnerabilities.

Impact: Cisco Unity Connection and other unspecified enterprise products
Remediation: Patches released for the vulnerabilities; users are advised to update their systems to the latest versions.
Read Original

Researchers at Dragos have reported that commercial AI models, specifically from OpenAI and Anthropic, were used to plan and execute a cyber-attack on a water and drainage facility's operational technology. This incident raises significant concerns about the potential misuse of advanced AI tools in targeting critical infrastructure. The attackers were able to leverage AI to enhance their tactics, which poses a serious risk to essential services that rely on such technology for safe operations. As AI becomes more integrated into various sectors, there is an urgent need for companies to assess their cybersecurity measures and prepare for potential AI-driven threats. The implications of this attack could affect not only the targeted facility but also set a precedent for similar attacks against other critical infrastructure systems.

Impact: Operational technology of water and drainage facilities
Remediation: Companies should enhance cybersecurity protocols, conduct vulnerability assessments, and train personnel on the risks associated with AI tools in cybersecurity.
Read Original

Two American men have been sentenced for operating laptop farms that employed North Korean IT workers. Their schemes affected nearly 70 U.S. companies and generated around $1.2 million in revenue for North Korea. The laptop farms allowed the North Korean regime to circumvent international sanctions and tap into foreign markets. This incident raises significant concerns about the use of foreign labor for illicit activities and highlights the ongoing challenges in enforcing sanctions against North Korea. The sentences serve as a reminder of the legal consequences of facilitating such operations.

Impact: 70 U.S. companies
Remediation: N/A
Read Original

Marlon Ferro, a 20-year-old from California, was sentenced to over six years in prison for his involvement in a massive cryptocurrency theft that totaled more than $250 million. This criminal network operated from late 2023 to early 2025, with members located across multiple states and even internationally. Ferro's role included hacking databases and making fraudulent phone calls to execute the theft. The stolen funds were reportedly used to finance a lavish lifestyle, including luxury fashion, nightclub parties, and private jets. This case highlights the ongoing risks associated with cryptocurrency theft and the lengths to which criminals will go for financial gain.

Impact: Cryptocurrency assets
Remediation: N/A
Read Original

Cisco's AI security researchers have discovered a vulnerability in vision-language models (VLMs) that could be exploited by attackers using subtle pixel-level changes in images. These small alterations can mislead the models into producing incorrect outputs without being noticeable to human observers. This poses significant risks for industries that rely on VLMs, such as autonomous vehicles and security systems, where accurate visual interpretation is crucial. The findings suggest that companies using these AI systems should review their security measures to prevent potential exploitation. As AI continues to integrate into various applications, understanding and mitigating such vulnerabilities becomes increasingly important.

Impact: Vision-language models (VLMs) used in various AI applications, including autonomous vehicles and security systems.
Remediation: Companies should review their security measures for AI systems and consider implementing additional validation checks to detect pixel-level alterations.
Read Original

Two U.S. citizens were sentenced to 18 months in prison for operating 'laptop farms' that enabled North Korean IT workers to fraudulently secure remote jobs with around 70 American companies. This operation involved creating fake employment records and using stolen identities to bypass hiring protocols. The actions of these individuals not only violated U.S. law but also posed a national security risk by potentially providing North Korea with access to sensitive information and resources. The case brings attention to the ongoing issue of North Korean cyber operations and the challenges companies face in ensuring their hiring processes are secure against such fraudulent schemes.

Impact: American companies, North Korean IT workers
Remediation: Companies should enhance their hiring verification processes and implement stricter identity checks to prevent similar fraudulent activities.
Read Original

The software developer behind Daemon Tools has reported that a supply chain attack was contained after identifying the affected systems. They have removed files that may have been compromised and have validated the installation packages to ensure their integrity. This incident raises concerns about the security of supply chain processes in software development, as attackers increasingly target third-party components to infiltrate systems. Users of Daemon Tools should remain vigilant and ensure they are using the latest, verified versions of the software to avoid potential risks from similar attacks in the future.

Impact: Daemon Tools software and its installation packages
Remediation: Identified impacted systems, removed potentially compromised files, validated installation packages
Read Original

A recent issue identified during the 'TrustFall' convention reveals that malicious repositories can execute code in several coding tools, including Claude Code, Cursor CLI, Gemini CLI, and CoPilot CLI, with little to no user interaction required. This vulnerability is concerning because it relies on inadequate warning dialogs that fail to sufficiently alert users about the risks. As a result, developers using these tools could unknowingly run harmful code, leading to potential data breaches or system compromises. The lack of effective safeguards means that both individual developers and organizations using these tools are at risk. It's crucial for users to be aware of this vulnerability to avoid falling victim to such attacks.

Impact: Claude Code, Cursor CLI, Gemini CLI, CoPilot CLI
Remediation: Users should exercise caution when interacting with repositories, ensuring they only use trusted sources. Regularly updating software and monitoring for patches from the respective vendors is also advised.
Read Original

A new type of attack, dubbed the 'TrustFall' attack, reveals vulnerabilities in AI coding agents that can be exploited to execute supply chain attacks. Researchers have demonstrated that these AI tools, which are increasingly used to automate coding tasks, can be manipulated to include malicious code in software development processes. This poses a significant risk to organizations that rely on these AI agents for efficiency, as attackers could potentially compromise software before it reaches users. The implications are serious; if successful, such attacks could lead to widespread disruptions in supply chains, affecting various industries and their customers. Companies must be vigilant and implement safeguards to prevent these types of compromises.

Impact: AI coding agents, software development tools
Remediation: Implement security measures for AI coding tools, conduct regular code reviews, and ensure robust testing of AI-generated code.
Read Original
PreviousPage 25 of 213Next