Recent reports indicate that several threat groups, including UNC6661, UNC6671, and UNC6240, have intensified their cyber attacks under the ShinyHunters name. These attacks primarily target cloud-based software-as-a-service (SaaS) applications, employing tactics such as voice phishing and creating fake websites to steal user credentials. This surge in extortion-themed intrusions poses a significant risk to organizations relying on SaaS platforms, as attackers aim to exploit vulnerabilities for financial gain. Businesses and users need to be vigilant about potential phishing attempts and ensure their security practices are up to date to safeguard sensitive information.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
A Chinese-speaking cybercrime group known as UAT-8099 has been attacking unsecured Internet Information Services (IIS) servers across Asia, with a focus on Thailand and Vietnam. This campaign started late last year and has raised concerns among cybersecurity experts. The attackers are exploiting vulnerabilities in these servers, which could lead to unauthorized access and data breaches. Organizations using IIS servers in the targeted regions need to prioritize their security measures to prevent exploitation. The ongoing attacks highlight the risks associated with unprotected web servers, especially in areas where cybersecurity practices may not be as stringent.
SCM feed for Latest
A recent report from The Identity Underground points out a concerning gap in how organizations prepare for AI-related identity threats. The findings indicate that while executives recognize the importance of addressing these threats, there is a significant disconnect with the capabilities of their teams on the ground. This misalignment could leave companies vulnerable to attacks that exploit AI for identity fraud and other malicious activities. With AI technology advancing rapidly, organizations must take a closer look at their security measures to ensure they are equipped to handle potential risks. The report serves as a wake-up call for businesses to bridge this gap and strengthen their defenses against emerging threats.
As federal agencies like the Cybersecurity and Infrastructure Security Agency (CISA) scale back their support for election security, state officials are feeling the pressure to fill the gap. Secretaries of State across the country are now seeking alternative cybersecurity services to protect their election systems. This shift comes at a time when many states are still working to bolster their defenses following past election interference incidents. The lack of federal resources means states will need to rely more on their own budgets and local expertise, which could lead to disparities in security measures across the nation. Ensuring safe and secure elections is critical for maintaining public trust in the electoral process.
A new strain of malware known as GlassWorm has been found targeting macOS systems through compromised OpenVSX extensions. This malware aims to steal sensitive information, including passwords, cryptocurrency wallet data, and developer credentials. Users who have installed these extensions may be at risk, highlighting a significant security issue for developers and crypto users on macOS. Researchers emphasize the importance of vigilance when installing third-party extensions and recommend that users ensure their software is up-to-date. This incident underscores the need for better security practices in the software development ecosystem to prevent such attacks.
In 2019, two penetration testers were wrongfully arrested by Iowa police while conducting a security assessment. The incident arose during a red teaming exercise, where they were hired to simulate attacks on a local government system to identify vulnerabilities. This situation illustrates the dangers that cybersecurity professionals face when their work is misunderstood by law enforcement or the public. The county has since settled the case, paying $600,000 to the testers, which raises concerns about how security practices are perceived and the potential legal ramifications for professionals in this field. This case serves as a reminder for organizations to ensure clear communication and understanding of security testing protocols.
Ukraine's Computer Emergency Response Team (CERT) has reported that Russian hackers are taking advantage of a newly patched vulnerability in Microsoft Office, identified as CVE-2026-21509. This flaw affects multiple versions of the software, which could leave users open to various cyberattacks. The exploitation of this vulnerability is concerning, especially as Microsoft Office is widely used in both personal and professional settings. Users and organizations are urged to ensure that their systems are updated with the latest security patches to mitigate the risk of being targeted. The situation underscores the need for vigilance in maintaining software security, especially with ongoing geopolitical tensions.
In a troubling development, researchers have discovered over 230 malicious packages targeting OpenClaw, an AI assistant tool, within just a week. These packages, found on the tool's official registry and GitHub, are designed to steal user passwords. This situation raises concerns as it affects users of OpenClaw who may inadvertently download these harmful packages, putting their sensitive information at risk. The rapid proliferation of these packages indicates a serious security threat to the AI assistant community. Users are urged to be cautious and verify the legitimacy of any packages before installation.
The Hacker News
A recent security audit conducted by Koi Security has revealed that out of 2,857 skills available on ClawHub, 341 were identified as malicious. These harmful skills are designed to steal data from users of OpenClaw, an artificial intelligence assistant platform. The presence of these malicious skills raises significant supply chain risks for users who depend on third-party integrations. As ClawHub serves as a marketplace for these skills, the findings indicate a pressing need for enhanced security measures to protect users from potential data breaches. Users of OpenClaw should be vigilant when selecting skills and consider the implications of using third-party applications that may not be secure.
SCM feed for Latest
According to a report by TRM Labs, illegal cryptocurrency transactions reached a staggering $158 billion in 2025, marking a 145% increase in illicit cryptocurrency flows compared to previous years. Despite this surge, the overall share of illegal activities within the total on-chain volume has slightly decreased to 1.2%. This indicates that while the absolute value of illicit transactions is rising, they represent a smaller fraction of total cryptocurrency activity. This trend raises concerns about the potential for increased criminal activity in the digital currency space and highlights the ongoing challenges in regulating and monitoring cryptocurrency transactions. It is crucial for law enforcement and regulatory agencies to adapt their strategies to address these growing risks effectively.
Latest news
A massive distributed denial-of-service (DDoS) attack has reached a staggering 31.4 terabits per second, setting new records for online attacks. This incident is attributed to a powerful botnet known as the 'apex' botnet, which has been exploiting consumer devices, such as routers and smart home gadgets, to amplify its attack capabilities. As attackers increasingly turn ordinary home devices into tools for cyber warfare, businesses and individuals alike are at risk of service disruptions. The scale of this attack serves as a wake-up call for users to secure their connected devices and for companies to enhance their defenses against such overwhelming assaults. The implications are serious, as these attacks can cripple online services and affect a vast number of users worldwide.
The National Security Agency (NSA) has released new guidelines aimed at helping organizations implement Zero Trust security models effectively. This approach focuses on minimizing trust assumptions within networks, requiring strict verification for every user and device attempting to access resources. The guidelines are designed for organizations looking to reach a target-level maturity in their Zero Trust practices, which is increasingly important as cyber threats evolve. By adopting these recommendations, companies can better protect their sensitive data and systems from unauthorized access. This is particularly relevant for sectors handling critical infrastructure or sensitive information.
A recent report from CTM360 warns of a significant rise in fake high-yield investment platforms globally. These scams typically lure victims with promises of 'guaranteed' returns, which often turn out to be classic Ponzi schemes. Researchers found that these fraudulent schemes are proliferating through social media, using recycled marketing templates and exploiting referral systems to attract more victims. This surge in HYIP scams poses a serious risk to investors, many of whom may be unaware they are being targeted. The findings highlight the need for increased awareness and caution among potential investors, as well as for regulatory bodies to take action against these deceptive practices.
The ShinyHunters group has expanded its extortion activities by using advanced vishing techniques and login harvesting to compromise Single Sign-On (SSO) credentials. This allows them to enroll unauthorized Multi-Factor Authentication (MFA), making it easier for them to access sensitive information. Organizations that rely on SSO for employee access are particularly at risk, as the attackers can bypass standard security measures. This escalation in tactics is concerning for businesses and individuals alike, as it highlights the increasing sophistication of cybercriminals and their methods for gaining unauthorized access. Companies should be vigilant about their security protocols and ensure that their MFA implementations are robust against these types of attacks.
Hackread – Cybersecurity News, Data Breaches, AI, and More
Ivanti has reported two serious vulnerabilities in its Endpoint Manager Mobile (EPMM) software, identified as CVE-2026-1281 and CVE-2026-1340. These flaws allow remote code execution, meaning attackers could potentially take control of affected systems without needing physical access. The company warns that these vulnerabilities are currently being actively exploited, putting users at risk. Organizations using EPMM should prioritize applying the necessary security updates to safeguard their systems. Failure to address these vulnerabilities could lead to significant security breaches, affecting both the integrity of user data and the overall security posture of the organization.