Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Actively Exploited

Hackers have successfully compromised an update server belonging to MicroWorld Technologies, the company behind eScan Antivirus. This breach allowed attackers to inject malicious files into updates that were sent to eScan customers, effectively turning the antivirus software into a delivery mechanism for malware. Users who updated their eScan software during this incident may have inadvertently installed harmful files on their systems. This incident raises significant concerns about the security of software supply chains, highlighting how even trusted software can be weaponized. Users are advised to remain vigilant and consider checking their systems for any signs of compromise.

Read Original

A researcher has found that some private Instagram accounts were inadvertently allowing access to their photo links by users who weren't logged in. This issue raised concerns about user privacy, as it meant that photos intended for private viewing could be seen by anyone with the link. Although Meta, Instagram's parent company, addressed the problem, they classified the report as not applicable and did not respond to requests for further information. This incident highlights ongoing challenges in protecting user data on social media platforms, emphasizing the need for companies to prioritize security and privacy measures to safeguard their users' content.

Read Original
US Seizes $400 Million Linked to Helix Dark Web Crypto Mixer

Hackread – Cybersecurity News, Data Breaches, AI, and More

U.S. authorities have seized over $400 million in cryptocurrency, cash, and property linked to Helix, a prominent Bitcoin mixing service operating on the dark web. This service was widely used by drug markets to obscure the origins of their cryptocurrency transactions, making it difficult for law enforcement to trace illegal funds. The seizure is part of a broader crackdown on illicit activities associated with dark web platforms. By targeting Helix, authorities aim to disrupt the financial networks that support drug trafficking and other criminal enterprises. This action not only affects the operators of Helix but also sends a strong message to other similar services that law enforcement is actively pursuing financial crimes in the digital currency space.

Read Original

A new cyber campaign known as RedKitten is believed to be launched by a Farsi-speaking group linked to the Iranian government. This campaign specifically targets non-governmental organizations and activists who are documenting human rights abuses in Iran, particularly during the ongoing unrest that began in late 2025. Observed by HarfangLab in January 2026, the attacks aim to disrupt the efforts of those advocating for human rights and may involve various forms of cyber espionage or harassment. This targeting of NGOs poses significant risks not only to the organizations themselves but also to the broader landscape of human rights advocacy, as it can deter individuals and groups from speaking out against abuses. The situation underscores the challenges faced by activists in oppressive regimes and raises alarms about the potential for increased state-sponsored cyber activities against dissenters.

Read Original

On December 29, 2025, Poland experienced a wave of cyberattacks that targeted more than 30 wind and solar farms, a manufacturing facility, and a significant combined heat and power (CHP) plant. This CHP plant is crucial as it supplies heat to nearly 500,000 residents. CERT Polska reported that these coordinated attacks disrupted operations, raising concerns about the security of renewable energy sources and critical infrastructure. The impact of these attacks could have far-reaching consequences, not only affecting energy supply but also potentially leading to economic losses and undermining public trust in energy providers. As the world moves towards greener energy solutions, safeguarding these facilities from cyber threats is increasingly important.

Read Original

On December 29, 2025, CERT Polska reported that cyber attacks targeted over 30 wind and solar farms, a manufacturing company, and a significant combined heat and power plant in Poland. These attacks are concerning as they impact crucial energy infrastructure, with the CHP plant alone serving nearly half a million customers. The agency has linked these incidents to a coordinated effort, raising alarms about the security of renewable energy sources and essential utilities in the country. The implications of such attacks could be severe, potentially disrupting energy supply and compromising the stability of the grid. As more energy systems move towards digital management, ensuring their security must become a priority for both operators and regulators.

Read Original

Moltbot, a new AI tool designed to assist with computing tasks, is raising serious security concerns. Experts warn users about several vulnerabilities associated with the application, including potential data leaks and unauthorized access. The AI's charming design may lure users into a false sense of security, but researchers have identified red flags that suggest it could expose sensitive information. As more people consider using this tool, it's crucial to evaluate the risks involved and understand how it may affect personal and organizational security. This situation serves as a reminder that not all AI applications are safe, and users must remain vigilant about the tools they choose to integrate into their workflows.

Read Original

According to Government Technology, the number of recorded data breaches soared to 3,322 last year, marking the highest level ever documented. Alarmingly, about 70% of the breach notices lacked essential details about the incidents, leaving users and stakeholders in the dark about the nature of the breaches and the extent of the data compromised. This lack of transparency is concerning, as it prevents affected individuals from understanding their risks and taking necessary precautions. The surge in breaches indicates a growing vulnerability landscape, which raises questions about the effectiveness of current security measures across various sectors. As organizations continue to face increasing cyber threats, the need for clearer communication and accountability in breach disclosures becomes ever more critical.

Read Original

Marquis Software Solutions, a financial services provider based in Texas, reported that a ransomware attack in August was linked to a breach in its firewall provider, SonicWall. The attack affected several banks and credit unions across the United States. SonicWall's security issues came to light a month after the attack, raising concerns about the vulnerabilities in third-party security providers. This incident illustrates the risks that companies face when relying on external vendors for cybersecurity. It also highlights the necessity for organizations to continuously monitor and assess the security measures of their partners to prevent similar attacks in the future.

Read Original

Matt Noyes, the Cyber Policy and Strategy Director for the U.S. Secret Service, has pointed out that the internet domain registration system is often overlooked as a potential target for cyberattacks. He emphasizes that this system poses significant cybersecurity risks that could be exploited by attackers. The lack of attention to this area means that both businesses and individuals could be vulnerable to domain-related threats, which could lead to issues like domain hijacking or phishing attacks. Noyes's comments serve as a warning for organizations to reassess their security measures around domain registration and management, as neglecting this aspect could have serious consequences for their online presence and data integrity.

Read Original

In December, Cloudflare successfully thwarted a massive distributed denial-of-service (DDoS) attack orchestrated by the Aisuru botnet. The attack peaked at a staggering 31.4 terabits per second, breaking Aisuru's previous record of 29.7 Tbps. Such high levels of attack traffic can overwhelm servers, disrupting services for many online users and businesses. While specific companies targeted in this incident haven't been disclosed, the scale of the attack raises concerns about the evolving capabilities of botnets and their potential to cause significant disruptions. This incident serves as a reminder for organizations to bolster their defenses against increasingly sophisticated DDoS attacks.

Read Original

OpenSSL has patched 12 vulnerabilities, including a critical remote code execution (RCE) flaw that poses a significant risk to users. These vulnerabilities mainly arise from issues related to memory safety, parsing robustness, and resource handling. Affected products include various versions of OpenSSL, which is widely used across different platforms and applications. This is particularly concerning for organizations that rely on OpenSSL for secure communications, as attackers could exploit these flaws to gain unauthorized access or control over systems. Users and administrators are urged to apply the latest patches to mitigate these risks and protect their systems from potential exploitation.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has issued new guidance focusing on insider threats, which pose a serious risk to organizations, particularly within critical infrastructure sectors. CISA emphasizes the need for organizations to form multi-disciplinary teams to effectively manage these threats. This guidance comes amid growing concerns about the potential misuse of artificial intelligence by insiders. By providing an infographic, CISA aims to help organizations understand how to better identify and mitigate these risks, ensuring a more secure operational environment. This is crucial as insider threats can lead to significant data breaches and operational disruption, affecting not only the organizations themselves but also the broader public they serve.

Read Original

In 2025, illicit cryptocurrency transactions surged to an alarming $158 billion, marking a significant increase from $64 billion in 2024. This rise reverses a three-year trend of declining illegal flows, which had been steadily decreasing from $86 billion in 2021. The spike in illicit funds highlights growing concerns over the use of cryptocurrencies for money laundering, fraud, and other criminal activities. Law enforcement agencies and regulatory bodies are likely to intensify their scrutiny of crypto transactions as a result. This situation raises serious questions about the security measures in place to protect users and prevent illegal activities within the cryptocurrency ecosystem.

Read Original

The U.S. Department of Justice has seized three domains linked to piracy sites that were distributing copyrighted material, attracting tens of millions of visitors each year. This action is part of a broader effort to combat online copyright infringement. In Italy, police dismantled an illegal IPTV operation that was also involved in distributing pirated content. These operations highlight the ongoing challenges of managing digital piracy, which affects content creators and legitimate service providers. By targeting these sites, authorities aim to protect intellectual property rights and deter future violations.

Read Original
PreviousPage 293 of 374Next