Aura, a cybersecurity firm, has reported a data breach that affects approximately 900,000 records. The breach occurred after an employee was targeted in a phone phishing attack, which allowed attackers to steal information from a marketing tool used by the company. This incident raises concerns about the effectiveness of employee training in recognizing phishing attempts and the security measures in place for sensitive data. Users whose information may have been compromised should remain vigilant about potential follow-up phishing attempts or identity theft. The breach serves as a reminder for organizations to continuously update their security protocols and educate employees about the risks of social engineering attacks.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Password reset processes can be vulnerable to privilege escalation attacks, as they are often less secure than regular logins. Attackers exploit weaknesses in these workflows to gain unauthorized access to accounts, potentially leading to serious data breaches. Specops Software outlines several strategies to fortify these procedures, emphasizing the need for stronger verification methods during resets. This is particularly important for organizations that manage sensitive information, as a compromised account can have significant repercussions. By implementing better security practices, companies can better protect their users and maintain trust.
BleepingComputer
Ubiquiti has addressed two vulnerabilities in its UniFi Network Application, including a serious flaw that could let attackers take control of user accounts. This vulnerability is particularly concerning as it affects the security of network management for users, potentially allowing unauthorized access to sensitive information and settings. Users of the application should ensure they update to the latest version to mitigate this risk. The company has emphasized the importance of applying these patches promptly to maintain network security. As cyber threats continue to evolve, staying updated with software patches is crucial for protecting against potential account takeovers.
Hackread – Cybersecurity News, Data Breaches, AI and More
SpyCloud's 2026 Identity Exposure Report reveals a significant rise in identity theft cases involving non-human identities, such as bots and automated systems. Researchers found that these types of identity theft are being used to commit fraud and manipulate systems across various sectors, affecting businesses and consumers alike. The report indicates that attackers are increasingly targeting automated accounts, which can bypass traditional security measures. This trend raises concerns for companies that rely on automated processes and have not implemented robust identity verification systems. The findings emphasize the need for organizations to reassess their security protocols to protect against this evolving threat.
Researchers have uncovered a toolkit used by the Beast Ransomware group, detailing their methods from initial reconnaissance to the final encryption of files. This toolkit includes various tools that allow the attackers to gather intelligence on their targets, exploit vulnerabilities, and encrypt victims' data for ransom. The discovery is significant because it provides insight into the operational techniques of the group, potentially helping organizations bolster their defenses against future attacks. Companies in sectors that typically face ransomware threats should pay close attention to these findings and review their security measures accordingly. The information also serves as a reminder of the ongoing risks posed by ransomware actors, who continue to evolve their tactics.
Hackread – Cybersecurity News, Data Breaches, AI and More
Researchers at Bitdefender have uncovered a malicious extension for the Windsurf IDE that exploits the Solana blockchain to steal developer credentials. This fraudulent extension targets developers who may unknowingly install it, putting their sensitive information at risk. The use of blockchain technology in this attack makes it particularly concerning, as it could allow for more sophisticated tracking and data theft. Developers need to be vigilant about the extensions they install, as this incident highlights the potential dangers associated with seemingly innocuous tools. The implications of such attacks can be significant, affecting not only individual developers but also the broader ecosystem of software development.
The Cybersecurity and Infrastructure Security Agency (CISA) is advising U.S. organizations to take immediate steps to secure their Microsoft Intune systems. This warning comes after a cyberattack targeted Stryker, a major medical technology company, exploiting vulnerabilities in the Intune endpoint management tool. The breach led to significant disruptions in Stryker's operations, raising concerns about the security of similar systems across various organizations. CISA recommends that users follow Microsoft's security guidance to bolster their defenses against potential attacks. This incident highlights the need for vigilance in managing endpoint systems, particularly in sectors that handle sensitive data.
Infosecurity Magazine
The UK's Financial Conduct Authority (FCA) has introduced new rules aimed at simplifying the process of reporting cyber incidents and issues related to third-party vendors. These updates are designed to provide clearer guidelines for financial firms, ensuring that they report incidents promptly and transparently. This move comes in response to the increasing frequency and complexity of cyber threats facing the financial sector. By establishing more straightforward reporting protocols, the FCA hopes to enhance the overall security posture of financial institutions and improve their ability to manage risks associated with third-party relationships. This change will affect all regulated firms within the UK’s financial services industry, emphasizing the importance of robust incident management practices.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about active exploitation of a recently patched vulnerability in SharePoint, identified as CVE-2026-20963. This remote code execution flaw allows attackers to run malicious code on affected systems, posing a significant risk to organizations using the software. Microsoft released a patch for this vulnerability back in January, but the discovery of in-the-wild exploitation suggests that some users may not have applied the update. Organizations using SharePoint should prioritize implementing the latest security updates to protect against potential breaches. Failing to address this vulnerability could lead to unauthorized access and data compromise, making it crucial for companies to stay vigilant and proactive in their cybersecurity practices.
Arcjet has introduced a new feature called AI Prompt Injection Protection aimed at defending production AI systems from prompt injection attacks. This capability identifies harmful prompts at the application's boundary, allowing developers to intercept and block malicious instructions before they can affect the AI model's inference process. As more companies rapidly deploy AI features, ensuring their security has become increasingly challenging. This solution is particularly relevant given that prompt injection attacks can manipulate AI systems, potentially leading to unauthorized access or misuse of sensitive data. By implementing this protection, organizations can better secure their AI applications against emerging threats.
The European Union has imposed sanctions on several companies based in China and Iran due to their involvement in cyberattacks. These sanctions prevent the listed entities from entering or conducting business within the EU. The move is part of broader efforts to counteract malicious cyber activities that could threaten EU member states and their interests. By targeting these companies, the EU aims to hold them accountable for their actions and deter future cyber incidents. This decision underscores the EU's commitment to enhancing cybersecurity and protecting its digital infrastructure from foreign threats.
The Hacker News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has alerted government agencies about two significant security vulnerabilities affecting the Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint. Both flaws, identified as CVE-2025-66376 and another not specified in the article, have been found to be actively exploited by attackers. The CVE-2025-66376 vulnerability has a CVSS score of 7.2, indicating a moderate to high risk. Organizations using these platforms are urged to apply the necessary patches to protect against potential attacks. The exploitation of these vulnerabilities underscores the need for timely updates and vigilance in cybersecurity practices, especially for government entities.
Akamai's latest security report reveals that internet-facing systems are facing increasing levels of malicious traffic, particularly targeting APIs, web applications, and DDoS channels. From January 2024 to December 2025, the number of web attacks aimed at applications and APIs has steadily risen, indicating a growing threat to organizations that rely on these technologies. This uptick in malicious activity suggests that attackers are honing their skills and strategies, making it crucial for companies to enhance their security measures. As APIs become more integral to business operations, understanding and mitigating these risks is essential for protecting sensitive data and maintaining service availability. Organizations should prioritize monitoring and defending their API infrastructures to counter these persistent threats.
The U.S. Department of Energy is preparing to release its first cybersecurity strategic plan aimed at strengthening the security of the nation's power grid. This move comes in response to a rise in cyber threats targeting critical infrastructure, highlighting the need for a more coordinated defense approach. The plan is expected to outline strategies for improving resilience against potential cyberattacks, which could disrupt energy supply and impact millions of Americans. By focusing on enhancing security measures, the Department of Energy aims to protect not just the grid itself, but also the broader economy and public safety. This initiative reflects growing concerns among government officials about the vulnerabilities in the energy sector and the increasing sophistication of cyber adversaries.
SCM feed for Latest
LangSmith, a platform for developing AI agents, and SGLang, a framework for serving large language models, have both been found to have significant security vulnerabilities. These flaws could allow attackers to take control of user accounts on LangSmith and execute code remotely on SGLang. The implications are serious, as these vulnerabilities could lead to unauthorized access and data breaches. Users of these platforms should be aware of the risks and take necessary precautions to secure their accounts. The discovery of these issues emphasizes the need for ongoing vigilance in the security of AI tools.