Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Walmart has implemented a unique approach to cybersecurity by co-locating its red and blue teams to foster trust and enhance security. This method, known as purple teaming, encourages collaboration between offensive (red) and defensive (blue) cybersecurity professionals. By working together in exercises, these teams can better understand each other's tactics and improve the overall security posture of the organization. This strategy not only helps in identifying vulnerabilities but also in developing more effective defenses against potential attacks. As cyber threats continue to evolve, Walmart's approach may serve as a model for other companies looking to strengthen their security frameworks.

Read Original

Hackers are increasingly targeting individuals by stealing private photos from social media and personal accounts, then selling these images on the dark web. This practice, known as sextortion, poses a significant risk to anyone with sensitive images online. The FBI has issued a warning about this trend, emphasizing the need for users to take proactive steps to protect their privacy. Individuals can safeguard themselves by enhancing their account security, being cautious about what they share online, and using privacy settings effectively. The rise in these incidents highlights the importance of digital hygiene in an age where personal information can be easily exploited.

Read Original
Actively Exploited

A new type of malware known as WindRelay is being used in conjunction with the SpyNote Remote Access Trojan (RAT) to execute live-call scams. This combination allows fraudsters to clone credit cards during phone calls, posing a significant risk to unsuspecting victims. The attackers can manipulate information in real-time, making it easier for them to deceive individuals and potentially steal their financial information. This incident serves as a reminder for users to be cautious during phone conversations, especially when discussing sensitive information. Awareness and vigilance are key to preventing falling victim to such scams.

Read Original
Actively Exploited

The FBI has issued a warning regarding a growing trend where hackers are targeting social media and online accounts of both adults and children to steal explicit images and videos. These cybercriminals use various tactics to gain access to accounts, raising concerns about the safety and privacy of users online. The stolen content can be used for blackmail or shared publicly, which can have severe emotional and psychological impacts on the victims. This incident is particularly alarming given the increasing prevalence of such cyber crimes, especially as more people share personal content online. Users are urged to enhance their account security by using strong passwords and enabling two-factor authentication to protect their private information from these malicious actors.

Read Original

Suisun City, California, experienced a cyber incident that began early on August 7 when malware infiltrated the city's IT network. The attack raised concerns as local governments have seen an increase in cyber threats recently. Details about the specific type of malware or the extent of the damage are still unclear, but the incident highlights the vulnerabilities that municipal systems face. Officials are likely assessing the impact on city services and working on recovery strategies. As cyberattacks on local governments become more common, this incident serves as a reminder of the need for enhanced cybersecurity measures in public sectors.

Read Original

The Colombian Justice Ministry has fallen victim to a ransomware attack just days before a presidential transition. This incident is part of a broader trend of increasing cyberattacks targeting government and critical infrastructure in Latin America. The breach raises concerns about the security of sensitive governmental data and the potential disruption of services during a politically sensitive time. As attackers continue to exploit vulnerabilities within public institutions, the urgency for enhanced cybersecurity measures becomes more evident. The ramifications of such attacks can extend beyond immediate operational impacts, potentially affecting public trust in government stability and security.

Read Original

Researchers recently identified vulnerabilities in Zoom's screenshare annotation feature that could allow attackers to execute remote code on devices of meeting participants. These flaws were uncovered with the help of AI tools, which indicates a growing trend of using advanced technology in security research. Users of Zoom, particularly those who frequently use the screenshare feature, are at risk. If exploited, these vulnerabilities could lead to unauthorized access to sensitive information or control over user devices. It's crucial for Zoom to address these flaws promptly to protect their users and maintain trust in their platform.

Read Original

For the past 17 months, an unknown individual has been accessing Salesforce and ServiceNow portals worldwide, according to researchers from Reco who are tracking this ongoing campaign dubbed 'City-Forum.' The campaign began using a domain that was registered back in 2002 but has since been linked to a generic server hosted in Germany. This unauthorized access has allowed the attacker to pull sensitive records from these widely used platforms, which could potentially compromise the data of numerous organizations. This situation raises serious concerns about the security measures in place for cloud-based services and highlights the need for companies to review their access controls and monitoring practices to protect against such long-term intrusions.

Read Original

Signal has rolled out a new feature called automatic key verification to enhance the security of its encrypted messaging service. This feature allows users to easily confirm that their chats haven't been tampered with by any unauthorized parties. Signal, known for its strong end-to-end encryption, aims to give users peace of mind by streamlining the verification process. According to Signal engineer Katherine Yen, this mechanism helps ensure that no unexpected entities are intercepting conversations, bolstering user privacy and trust in the platform. As more people rely on secure messaging, such enhancements are crucial for maintaining confidentiality in digital communications.

Read Original
Actively Exploited

Bitdefender has reported a concerning trend where fake downloads of the movie 'The Odyssey' are being used to spread Lumma Stealer malware. These downloads are disguised as scene releases, featuring .exe files that are made to look like VLC media player icons. Users attempting to download the movie may unknowingly install this malicious software, which can steal sensitive information. This situation poses a significant risk, particularly for those looking for free downloads of popular media. It serves as a reminder for users to exercise caution and verify the legitimacy of files before downloading them.

Read Original

Researchers have discovered a new campaign dubbed 'City-Forum' that targets Salesforce and ServiceNow platforms. This attack takes advantage of unauthenticated guest access to silently gather and extract sensitive data from these services. The attackers use a specialized toolset to carry out their operations, which raises concerns about the security of user information on these widely used platforms. Since Salesforce and ServiceNow host critical business data for many organizations, this incident could have serious implications for data privacy and security. Companies using these platforms are urged to review their access controls and security measures to prevent unauthorized data access.

Read Original
Actively Exploited

On August 10, 2026, cybersecurity officials from the US and South Korea issued a joint alert regarding a notable rise in Gunra ransomware attacks. This ransomware is targeting various sectors, including healthcare and critical infrastructure, posing a significant risk to organizations that may not be adequately prepared. The advisory emphasizes the need for improved cybersecurity measures to defend against these evolving threats. Companies are encouraged to enhance their security protocols, perform regular backups, and educate employees about phishing tactics that often facilitate these attacks. The rise in Gunra ransomware underscores the ongoing challenges organizations face in safeguarding their data and systems from malicious actors.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has launched new resources aimed at enhancing cybersecurity for K-12 schools and districts. These tools include a comprehensive guide to help educators identify potential risks and implement effective security measures. The initiative comes in response to a rising trend of cyberattacks targeting educational institutions, which can disrupt learning and compromise sensitive student data. By providing these resources, CISA aims to empower schools to better protect themselves against cyber threats. This move is particularly important as schools increasingly rely on digital platforms for education, making them more vulnerable to attacks.

Read Original
Critical
Siemens RUGGEDCOM APE1808

All CISA Advisories

Siemens has alerted users to vulnerabilities affecting its RUGGEDCOM APE1808 device due to issues in Fortinet's FortiOS software. Two specific vulnerabilities, identified as CVE-2026-23573 and CVE-2026-59839, can allow attackers to execute unauthorized commands or access restricted files if they have the necessary privileges. These vulnerabilities could potentially impact critical sectors such as manufacturing, energy, and transportation. Siemens advises affected users to contact their customer support for more details on mitigation measures and to follow Fortinet's advisory for workarounds. This situation underscores the need for robust network security measures to safeguard critical infrastructure.

Read Original

A recent report from Picus Labs reveals that while enterprise defenses are performing well against noisy attacks, they are struggling against more subtle, stealthy tactics used by attackers. Analyzing over 338 million real attack simulations in early 2026, the report shows that many defenses are tuned to detect loud, obvious threats, allowing quieter attacks to slip through unnoticed. This trend raises concerns for businesses, as it indicates that organizations may be overconfident in their security measures, potentially leaving them vulnerable to sophisticated intrusions. The findings suggest that companies need to reassess their security strategies to address these less visible threats, which could lead to significant breaches if not managed properly.

Read Original
PreviousPage 27 of 362Next