Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Microsoft's August Patch Tuesday updates address several vulnerabilities, with CVE-2026-62878 standing out due to its severity. This remote code execution vulnerability in Windows DNS Server has a high CVSS score of 9.8 and can be exploited without user interaction. This means attackers could potentially take control of affected systems easily, posing a significant risk to organizations relying on Windows DNS servers for their operations. It’s crucial for system administrators to prioritize applying this patch to protect their networks from potential exploitation. The updates are part of Microsoft's ongoing efforts to enhance security across its products, but this particular flaw underscores the importance of timely patch management.

Read Original

Hackers linked to the Russian group Sandworm have been targeting IT professionals and system administrators by sending fake job offers that include a malicious version of the WireGuard VPN client. This tactic has been in play since at least May, allowing attackers to compromise systems under the guise of a legitimate hiring process. Once installed, the trojanized VPN client can give hackers access to sensitive network information and potentially lead to larger security breaches. This incident is particularly concerning as it exploits the trust between job seekers and employers, highlighting the need for heightened vigilance among IT professionals regarding unsolicited job offers and software downloads. Organizations should ensure their employees remain cautious and verify the authenticity of any job-related communications or software.

Read Original

The article discusses various cybersecurity threats and vulnerabilities, including new malware variants and attack techniques. Notably, 'Ghostjacking' is highlighted as a technique used by attackers to take control of devices remotely without user consent. This poses a significant risk to users as it can lead to unauthorized access to personal information and devices. Additionally, the article covers the importance of Software Bill of Materials (SBOMs) in enhancing software security by providing transparency about software components. Companies need to prioritize implementing SBOMs to mitigate risks associated with supply chain attacks. Overall, these emerging threats underline the necessity for users and organizations to stay vigilant and adopt stronger security practices.

Read Original

Microsoft has released its monthly security updates, addressing a total of 398 vulnerabilities, including a serious zero-day flaw that is currently being exploited in attacks. This particular vulnerability, tracked as CVE-2026-68820, affects a core Windows kernel driver responsible for network socket operations. Attackers who already have code running on a targeted machine can exploit this flaw to gain elevated privileges, potentially allowing them to execute commands with SYSTEM-level access. Given the active exploitation, users and organizations should prioritize applying the patch to mitigate the risk of unauthorized access. The patch is crucial for maintaining system security and preventing further attacks.

Read Original

Researchers from Palo Alto Networks Unit 42 have identified a new version of the Kimwolf botnet, known as Kimwolf v7, which targets Android devices and Internet of Things (IoT) devices. This upgraded botnet enhances its ability to launch distributed denial-of-service (DDoS) attacks by disguising its HTTP/2 traffic to resemble legitimate web browsing. This makes it harder for security systems to detect and mitigate the attacks. The discovery of Kimwolf v7 raises concerns for users of vulnerable Android and IoT devices, as attackers can exploit these weaknesses to disrupt services and potentially gain unauthorized access to sensitive information. Companies and users need to be vigilant and ensure their devices are secured against such threats.

Read Original

A serious flaw in Zoom's annotation tool has been discovered, allowing participants in a meeting to potentially take control of each other's computers without any interaction from the victim. This vulnerability affects anyone sharing their screen, as well as those viewing the shared content, posing a significant risk during virtual meetings. Attackers could exploit this weakness without requiring the target to click anything or accept any prompts, making it particularly dangerous. The implications are severe, as it could lead to unauthorized access to sensitive information or malicious actions during meetings. Users and organizations should be aware of this risk and take necessary precautions while using Zoom for meetings.

Read Original

The Computer Emergency Response Team of Ukraine (CERT-UA) has reported a new social engineering scam linked to Russian threat actors known as UAC-0145, a subgroup of Sandworm. The attackers are posing as recruiters and targeting IT professionals in Ukraine, attempting to convince them to install a malicious VPN. This VPN is designed to execute commands on the victims' systems, effectively compromising their security. The campaign is particularly concerning given the ongoing tensions in the region and the potential for sensitive information to be exploited. IT workers should be cautious of unsolicited job offers and verify the legitimacy of any communications they receive.

Read Original

Delta Air Lines is currently looking into an unauthorized Wi-Fi network that emerged on a flight from Las Vegas to Atlanta, which was carrying passengers from the DEF CON hacker convention. This incident involved a deauthentication attack, a technique often used by attackers to disrupt legitimate Wi-Fi connections. The presence of such an attack on a commercial flight raises serious concerns about passenger safety and the potential for malicious activities in-flight. Delta is investigating the situation to determine the source and implications of this unauthorized network. Passengers on the flight, particularly those with knowledge from the hacker convention, may have heightened awareness of such threats, making this incident particularly noteworthy in the context of aviation security.

Read Original

Delta Airlines is currently investigating an incident involving in-flight Wi-Fi spoofing that occurred on a flight returning from DEF CON, a well-known cybersecurity conference in Las Vegas. The airline's crew noticed irregularities in the in-flight network, prompting them to shut it down for safety. The Federal Bureau of Investigation (FBI) is also looking into the matter to determine the extent of the interference and identify any potential perpetrators. This incident raises concerns about the security of in-flight systems, particularly as they become more interconnected and reliant on technology. Passengers and airlines alike need to be aware of the risks associated with in-flight networks, especially in the context of events like DEF CON where cybersecurity discussions are prevalent.

Read Original

Zoom has addressed a serious vulnerability in its software that could allow a participant in a video meeting to execute malicious code on another user’s device via the annotation feature. This flaw, known as CVE-2026-53413, is categorized as a zero-click vulnerability, meaning it does not require any interaction from the victim to be exploited. Discovered by A Security, the issue is part of a broader update where Zoom patched a total of four vulnerabilities. The existence of such a flaw raises significant concerns about user safety and privacy during online meetings, as it could potentially lead to unauthorized access to sensitive information. Users are advised to update their Zoom applications to the latest version to protect themselves from possible exploitation.

Read Original

U.S. officials from the FBI and CISA have issued a warning that artificial intelligence (AI) is enhancing the capabilities of cyber attackers. They believe that AI can make it easier for these criminals to launch more sophisticated and effective cyberattacks. In response, federal agencies are stepping up efforts to strengthen cybersecurity defenses across the nation. This concern comes as organizations increasingly rely on technology and AI in their operations, making them potential targets for malicious actors. The growing use of AI in cybercrime could lead to more significant breaches and data theft, affecting both businesses and individuals.

Read Original

Adobe has issued a warning for users of its ColdFusion and Campaign Classic products to address serious security flaws that could allow attackers to execute arbitrary code or cause denial-of-service attacks. These vulnerabilities pose significant risks, as they could let malicious actors take control of systems or disrupt services. Users of these applications are urged to prioritize patching to protect their data and ensure operational continuity. The company has not specified if these vulnerabilities are currently being exploited in the wild, but the urgency of the advisory indicates a pressing need for action. Patching is essential to mitigate the risks posed by these flaws.

Read Original

Researchers have discovered a serious vulnerability in Microsoft SharePoint that allows unauthorized access to servers, including administrative functions, without a valid account. This flaw, known as CVE-2026-55040, has a CVSS score of 9.1, indicating its severity. It affects various versions of SharePoint, specifically SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. The researchers utilized an AI agent to help identify this exploit chain, which raises concerns about the potential for widespread abuse. Organizations using these SharePoint versions should take immediate action to secure their systems to prevent unauthorized access.

Read Original
Actively Exploited

ExfilSquad, a new cybercrime group that surfaced in mid-2026, has targeted 13 organizations by exploiting cloud portals to steal sensitive data. Unlike traditional ransomware attacks, this group focuses on data theft and then threatens to release the stolen information to amplify the damage. They have started distributing the stolen data through torrents, making it more difficult for affected organizations to contain the breach. Researchers from Resecurity are actively monitoring ExfilSquad's activities as they announce new victims. This incident raises concerns about the security of cloud services and the need for organizations to strengthen their defenses against data theft.

Read Original

Iranian hackers have expanded their cyberattacks on U.S. water infrastructure, recently targeting facilities in New Jersey and Alabama. This brings the total number of affected states to at least 12 since late July. While the attacks have caused limited disruption so far, they raise significant concerns about the security of essential public services. The ongoing campaign emphasizes the vulnerabilities in critical infrastructure, making it crucial for state and local governments to enhance their cybersecurity measures. As these incidents become more frequent, the potential for more serious consequences increases, highlighting the need for vigilance in protecting water supply systems.

Read Original
PreviousPage 30 of 363Next