Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

The European Commission has confirmed a data breach linked to its mobile device management platform, prompting an investigation into the incident. While specific details about the number of affected staff or the nature of the exposed data have not been released, the breach raises concerns about the security of sensitive information held by the Commission. This incident is particularly significant given the Commission's role in managing policies and regulations across the European Union. Officials are working to understand the scope of the breach and are likely to implement measures to prevent future incidents. The situation underscores the ongoing challenges organizations face in protecting their data against cyber threats.

Read Original

Researchers from SecurityScorecard have discovered that over 40,000 instances of OpenClaw, a software tool, are exposed to potential attacks. This exposure raises significant security concerns, as it could allow attackers to exploit these deployments for unauthorized access or data breaches. OpenClaw is used in various applications, and organizations relying on it need to ensure their systems are secure. The large number of exposed instances suggests that many users may not be aware of the vulnerabilities associated with their deployments. Companies should prioritize reviewing their OpenClaw configurations and take steps to secure their systems against possible exploitation.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that all federal agencies must decommission any edge devices that are no longer supported within the next 12 months. This directive aims to mitigate risks associated with these outdated devices, which are more susceptible to exploitation by cyber attackers. End of support devices lack critical security updates, making them a target for those looking to breach federal networks. By enforcing this rule, CISA is taking proactive steps to enhance the security posture of government systems and protect sensitive data from potential threats. Agencies must now prioritize replacing or upgrading these devices to comply with the new directive and safeguard their networks.

Read Original

Romania’s national oil pipeline operator, Conpet, recently experienced a cyberattack that disrupted its business systems and caused its website to go offline temporarily. As a state-controlled company responsible for transporting crude oil and liquid petroleum products, any disruption in its operations can have significant implications for the country's energy supply. The incident highlights the vulnerabilities that critical infrastructure companies face, especially in the current digital landscape where such attacks are increasingly common. While Conpet has not disclosed specific details about the attack or the extent of the damage, the incident raises concerns about the security measures in place to protect essential services from cyber threats.

Read Original

Researchers have identified a significant cyber campaign known as the TeamPCP worm, which has been targeting cloud-native environments since late December 2025. This worm exploits vulnerabilities in widely used technologies, including exposed Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers. By hijacking these services, attackers are able to create a malicious infrastructure for further exploitation. This situation is alarming as it can potentially affect numerous organizations that rely on these cloud services for their operations. Companies need to ensure their cloud environments are properly secured against such vulnerabilities to prevent unauthorized access and data breaches.

Read Original

The European Commission is currently investigating a potential cyberattack that has targeted its mobile device management systems. Initial indications suggest that unauthorized access may have occurred, raising concerns about the security of sensitive data managed by the EU's main executive body. This incident could have implications for the integrity of communications and operations within the EU, particularly as cyber threats continue to evolve. The investigation aims to determine the extent of the breach and implement necessary security measures to protect against future attacks. As the situation develops, the EU will likely increase its focus on cybersecurity protocols to safeguard its systems and data.

Read Original
Critical
UK Construction Firm Hit by Prometei Botnet Hiding in Windows Server

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

A UK construction firm has fallen victim to an attack by the Russian Prometei botnet, as detailed by cybersecurity firm eSentire. The attack involved the use of TOR for anonymity, and attackers focused on stealing passwords and employing decoy tactics to mislead security measures. This incident raises concerns about the security of critical infrastructure in the construction sector, which may not be as fortified against cyber threats as other industries. The implications are significant, as compromised systems can lead to operational disruptions and financial losses for businesses. Companies in similar sectors should take note and assess their own cybersecurity defenses to prevent similar attacks.

Read Original

Researchers have introduced an open-source tool named Tirith, designed to combat homoglyph attacks in command-line environments. These attacks occur when malicious commands use visually similar characters to disguise themselves as legitimate commands, tricking users into executing harmful actions. Tirith works by analyzing URLs within typed commands and preventing their execution if they are deemed suspicious. This tool is particularly relevant for developers and system administrators who rely on command-line interfaces, as it provides an additional layer of security against deceptive tactics used by attackers. By implementing Tirith, users can better protect their systems from these types of impersonation attacks, which can lead to unauthorized access and potential data breaches.

Read Original

La Sapienza, a prominent university in Italy, is currently offline as a precautionary measure after suffering a cyber attack. The institution has taken this step to mitigate any further damage while they assess the situation and secure their systems. This incident has raised concerns about the security of educational institutions, which are often targets for cybercriminals. The attack underscores the need for universities to bolster their cybersecurity defenses to protect sensitive information and ensure the continuity of their operations. While details about the nature of the attack are still emerging, the university's proactive approach highlights the importance of readiness in the face of such threats.

Read Original

Researchers at Cisco Talos have identified a toolkit called DKnife that has been in use since 2019 to hijack router traffic for cyber-espionage purposes. This Linux-based toolkit allows attackers to inspect and alter data as it travels through routers and edge devices. It can also install malware on various devices, including PCs and smartphones. The implications of this toolkit are significant, as it poses a threat to the confidentiality and integrity of sensitive data transmitted over networks. Users and organizations relying on affected routers should be particularly vigilant about their network security practices to mitigate potential risks.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to take action on outdated edge network devices. Under the new Binding Operational Directive 26-02, agencies must improve the management of these devices and replace any that are no longer supported within the next 12 to 18 months. This directive aims to mitigate risks associated with using unsupported technology, which can be vulnerable to cyberattacks and security breaches. By addressing these outdated devices, CISA is pushing for better security practices to protect federal networks and sensitive information. The move emphasizes the need for agencies to stay current with technology and avoid potential exploitation by cybercriminals.

Read Original

Recent reports indicate that nearly 7.1% of skills associated with the open-source AI agent OpenClaw on the ClawHub marketplace may be exposing sensitive information such as API keys, credentials, and credit card details. This vulnerability arises from issues in the SKILL.md instructions, which guide developers on how to create and use these skills. The exposure of such critical data can lead to unauthorized access and financial fraud, impacting both developers and users who rely on these AI capabilities. It's crucial for developers to review their implementations and ensure they are safeguarding sensitive information to prevent potential exploitation. This incident serves as a reminder of the importance of secure coding practices in open-source projects.

Read Original
Actively Exploited

A recent investigation uncovered over 150 domains impersonating law firms as part of a scam that uses artificial intelligence. These fake websites are designed to deceive individuals and businesses by mimicking legitimate legal services. The scammers aim to exploit unsuspecting victims, potentially leading to financial losses and legal complications for those who engage with these fraudulent sites. This incident raises concerns about the effectiveness of current cybersecurity measures and the challenges of identifying AI-generated content. As cybercriminals increasingly utilize advanced technology, it becomes essential for both users and legal professionals to remain vigilant against such impersonation schemes.

Read Original

Researchers from SafeBreach have reported that an Iranian hacking group known as Infy APT has adapted its tactics by using Telegram for command and control (C2) operations. This shift comes after a period of internet restrictions imposed by the Iranian government, which has since ended, allowing the group to re-establish its online presence. The use of Telegram for C2 indicates a strategic change, making it easier for attackers to communicate and coordinate their activities while potentially evading detection. This development is concerning for organizations that may be targeted by these tactics, as it suggests a more sophisticated approach to cyber espionage and attacks. Keeping an eye on these evolving methods is crucial for cybersecurity professionals in order to protect sensitive information.

Read Original

The Department of Homeland Security (DHS) is facing a privacy investigation that will focus on the use of biometric tracking by its Immigration and Customs Enforcement (ICE) and the Office of Biometric Identity Management (OBIM). Auditors have indicated that the probe might expand to other DHS components, examining how the agency utilizes biometric markers in immigration enforcement activities. This scrutiny comes as concerns grow over privacy rights and the implications of increased surveillance. The outcome of this investigation could impact DHS's practices and policies regarding biometric data collection and usage, raising questions about transparency and accountability in immigration enforcement.

Read Original
PreviousPage 283 of 374Next