Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Instructure, the company behind the popular Canvas learning management system used by many educational institutions, suffered a significant breach attributed to the hacker group ShinyHunters. This incident raises serious concerns about how much trust schools place in their vendors' security practices. The attack not only compromises sensitive information but also highlights the vulnerability of educational institutions that rely heavily on third-party services. As these platforms become integral to online learning, the implications of such breaches can affect students, educators, and administrative operations alike. Schools may need to reassess their vendor relationships and security protocols to better protect their data in the future.

Impact: Instructure's Canvas learning management system
Remediation: Schools using Instructure should review their security measures and consider additional safeguards when relying on third-party vendors.
Read Original

Roku is facing a lawsuit after numerous users reported that their Roku TVs have become unusable, either getting stuck in boot loops or displaying black screens. This issue affects several models, leading to frustration among customers who rely on these devices for streaming. Users have taken to social media and forums to express their dissatisfaction, prompting legal action against the company. The situation raises concerns about the reliability of Roku devices and the potential need for better customer support and product durability. As these issues continue, affected users are encouraged to seek alternatives while the lawsuit unfolds.

Impact: Roku TVs, specific models not detailed
Remediation: N/A
Read Original

A serious vulnerability in the vm2 library, widely used for sandboxing in Node.js applications, has been discovered. This flaw allows attackers to escape the sandbox environment and execute arbitrary code on the host system, posing a significant risk to applications relying on vm2 for security. Developers and organizations using this library need to take immediate action to safeguard their systems, as this vulnerability could lead to severe breaches. The issue affects multiple versions of vm2, making it critical for users to update their systems promptly. Failure to address this vulnerability could leave systems exposed to potential attacks.

Impact: vm2 library, Node.js applications using vm2
Remediation: Users should update to the latest version of vm2 as soon as possible to mitigate the risk. Specific patch numbers or versions were not mentioned.
Read Original
ShinyHunters’ Instructure Canvas LMS and Vimeo Breaches Impact Millions of Users

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

ShinyHunters, a known hacking group, has breached both Instructure and Vimeo, leading to the exposure of millions of records belonging to students and users. The attacks utilized both direct methods and supply chain vulnerabilities, raising serious concerns about the security of educational and video platform data. Millions of individuals may have had their personal information compromised, which can lead to identity theft and other malicious activities. This incident underscores the need for organizations to enhance their security measures, particularly in protecting sensitive user information. As the investigation unfolds, affected users are advised to monitor their accounts closely for any suspicious activity.

Impact: Instructure Canvas LMS, Vimeo
Remediation: Organizations should enhance security protocols, conduct thorough audits of their systems, and monitor for unauthorized access.
Read Original

A recent study by Ipsos, commissioned by Optus, reveals that one in three small businesses in Australia have faced a cyber incident. Despite this alarming statistic, many of these businesses are not adequately prepared for future attacks. The research indicates a significant gap in cybersecurity planning among small enterprises, which could leave them vulnerable to more sophisticated threats. This lack of readiness is concerning, as cyber incidents can lead to severe financial and reputational damage. Small businesses need to prioritize developing and implementing effective cybersecurity strategies to protect their operations and customer data.

Impact: N/A
Remediation: N/A
Read Original
Actively Exploited

A serious vulnerability in MetInfo CMS, labeled CVE-2026-29014, has been discovered that allows unauthenticated attackers to execute arbitrary PHP code remotely. This flaw has a high severity rating of 9.8, indicating a significant risk to users of the platform. Organizations using MetInfo should be particularly vigilant, as this could lead to unauthorized access and control over their websites. As of now, there are concerns that this vulnerability is being actively exploited, which underscores the urgency for users to take action. It is crucial for affected users to apply any available patches and review their security measures to protect against potential intrusions.

Impact: MetInfo CMS versions affected by CVE-2026-29014.
Remediation: Users of MetInfo CMS should apply the latest security patches provided by the vendor, ensure their systems are updated to the most recent version, and review their code for any potential vulnerabilities. Additionally, implementing strict input validation and monitoring for unusual activity can help mitigate risks.
Read Original

Recently, a supply chain attack targeted DAEMON Tools, a popular disk imaging software. Attackers compromised three key components: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. This tampering can potentially allow malicious activities on systems that install these altered files. Users of DAEMON Tools are at risk, especially if they download the software from unverified sources. It's crucial for users to ensure they are using legitimate versions and to stay updated on any security advisories regarding the software.

Impact: DAEMON Tools components: DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe
Remediation: Users should download the software only from the official DAEMON Tools website and verify their current version. They should also regularly check for updates and security patches.
Read Original

A recent report from the Department of Homeland Security's inspector general reveals significant security issues with mobile applications used by the agency's intelligence office. Out of 650 apps assessed, over 75% were found to either pose security risks or were banned altogether. This raises serious concerns about the data protection measures in place for mobile devices that handle sensitive information. The presence of these risky apps could potentially expose critical national security data to unauthorized access or cyberattacks. The findings suggest a need for immediate review and improvement of mobile device security protocols within the DHS.

Impact: 650 mobile applications within the Department of Homeland Security's intelligence office
Remediation: Immediate review and improvement of mobile device security protocols within the DHS
Read Original

The Federal Trade Commission (FTC) has banned Kochava, a data broker, from selling geolocation data without user consent. The FTC's complaint revealed that Kochava collected and sold location data from hundreds of millions of mobile devices, allowing clients to monitor users' movements to sensitive locations like health clinics and places of worship. This practice raised significant privacy concerns, as it involved tracking individuals without their knowledge or approval. The ruling emphasizes the need for stronger protections around personal data and could set a precedent for how data brokers handle user information in the future. Consumers are increasingly wary of how their data is used, and this decision reflects a growing push for accountability in the industry.

Impact: Kochava, mobile devices, geolocation data
Remediation: N/A
Read Original

Ransomware attacks are increasingly successful even when organizations have backups, primarily because attackers often target and destroy these backups before encrypting the main data. Acronis explains that this tactic leaves victims with little to no options for recovery, as the backups become unusable. This highlights a significant vulnerability in many organizations' cybersecurity strategies, as they may rely too heavily on backups without considering their protection. Companies need to bolster their defenses by securing backup systems and implementing strategies that can withstand ransomware attacks, ensuring they have a path to recovery even if their primary data is compromised.

Impact: Backup systems, data recovery solutions
Remediation: Organizations should secure backup systems against unauthorized access, implement regular backup testing, and consider offline or immutable backup solutions.
Read Original

CISA has launched the CI Fortify initiative, urging critical infrastructure operators to develop plans to stay operational in the event of a cyber-attack. This initiative is designed to help these operators create systems for isolating affected areas and recovering from attacks quickly. The focus is on ensuring that essential services, such as power, water, and transportation, remain functional even when targeted by cyber threats. The call to action comes as cyber threats continue to evolve, making it crucial for these operators to have effective response strategies in place. CISA emphasizes that preparation can significantly mitigate the impact of potential attacks on public safety and national security.

Impact: Critical infrastructure sectors including energy, water, transportation, and telecommunications.
Remediation: Operators should develop isolation and recovery plans, conduct risk assessments, and implement incident response strategies.
Read Original

The article discusses a potential issue with AI agents acting as 'confused deputies,' which means they may perform unintended actions based on users' requests. This can lead to security vulnerabilities where the AI might execute commands that the user did not intend, potentially exposing sensitive data or causing other negative consequences. The implications of this problem are significant, as it raises concerns about the reliability and safety of AI systems in various applications. Users and developers need to be aware of these risks to ensure that AI implementations are secure and do not inadvertently compromise user intentions. As AI technology becomes more prevalent, addressing these issues will be crucial for maintaining trust and safety in digital environments.

Impact: AI agents and systems utilizing user commands
Remediation: Developers should implement stricter validation of user commands and ensure that AI systems have clear boundaries on what actions can be executed.
Read Original

Apache has released updates to address multiple vulnerabilities in its HTTP Server, including a serious flaw identified as CVE-2026-23918. This vulnerability, which has a CVSS score of 8.8, is a double-free error in the handling of HTTP/2 requests. If exploited, it could allow attackers to execute arbitrary code on affected systems. Organizations using Apache HTTP Server, particularly those enabling HTTP/2, should prioritize updating their software to mitigate this risk. The nature of the flaw makes it critical for system administrators to be proactive in applying the latest patches to safeguard against potential attacks.

Impact: Apache HTTP Server versions with HTTP/2 enabled.
Remediation: Users should update to the latest version of Apache HTTP Server that includes the patch for CVE-2026-23918. Specific version numbers were not provided, so checking the official Apache website for the latest updates is recommended.
Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has released guidance aimed at helping operators of critical infrastructure bolster their defenses against potential cyberattacks from foreign adversaries. This guidance stresses the importance of mastering isolation and recovery strategies to mitigate damage from attacks. Given the rising number of cyber threats targeting vital systems, this advice is particularly relevant for sectors like energy, transportation, and public health. By implementing these practices, organizations can better prepare for incidents, ensuring that they can maintain operations and recover swiftly after an attack. This proactive approach is essential for safeguarding national security and economic stability.

Impact: Critical infrastructure sectors including energy, transportation, and public health.
Remediation: Implement isolation and recovery strategies as outlined by CISA guidance.
Read Original

Proton Mail has rolled out an optional feature called post-quantum protection for all users, including those on the free plan. This new capability generates encryption keys that aim to secure future emails from potential quantum computer attacks. To use this feature, users must update their Proton Mail apps, as older versions do not support the new encryption keys. This move is significant because it prepares users' email communications for a future where quantum computing could compromise traditional encryption methods. By enabling post-quantum protection, users can enhance the security of their encrypted emails against evolving threats.

Impact: Proton Mail accounts across all plans
Remediation: Users need to update to the latest version of Proton Mail apps to enable post-quantum protection.
Read Original
PreviousPage 27 of 213Next