Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A recent analysis by VulnCheck has revealed a troubling trend in cybersecurity: the percentage of vulnerabilities being exploited before they are publicly disclosed has risen significantly from 23.6% in 2024 to nearly 29% in 2025. This increase indicates that attackers are becoming more adept at identifying and exploiting weaknesses in software and systems before developers have a chance to address them. This situation puts both companies and users at greater risk, as they may be unaware of the vulnerabilities affecting their systems until after an attack occurs. It’s crucial for organizations to prioritize vulnerability management and stay updated on potential threats to safeguard their assets effectively. The rise in zero-day exploits highlights the need for more proactive security measures and timely disclosure by vendors.

Read Original
Actively Exploited

Large language models (LLMs) are increasingly vulnerable to a technique known as prompt injection, where users craft specific requests that trick the models into performing actions they are usually restricted from. For instance, someone could ask an LLM to provide sensitive information or execute unauthorized commands by structuring their prompts cleverly. This issue raises significant concerns as it could lead to unintended data exposure or misuse of the AI’s capabilities. As LLMs are integrated into more applications, understanding and mitigating these types of attacks becomes critical for users and developers alike. The potential for misuse highlights the need for stronger safeguards in AI systems to protect against manipulation.

Read Original

During the second day of the Pwn2Own Automotive 2026 competition, hackers successfully exploited 29 zero-day vulnerabilities, earning a total of $439,250 in rewards. This event highlights the ongoing security challenges in the automotive sector, as researchers and ethical hackers test the resilience of vehicles against cyber threats. The vulnerabilities targeted various systems within automotive technology, but specific details about the affected models or manufacturers were not provided. This incident is significant because it showcases the ease with which skilled attackers can uncover critical flaws, raising concerns about the safety and security of connected vehicles. As the automotive industry increasingly adopts smart technology, it must prioritize robust security measures to protect against such vulnerabilities.

Read Original
Actively Exploited

Recent attacks have targeted FortiGate firewalls, specifically exploiting vulnerabilities in the FortiCloud SSO login system. Hackers are bypassing authentication measures to create unauthorized accounts, which allows them to alter device configurations. This poses a significant risk to organizations using FortiGate products, as attackers can manipulate firewall settings and potentially compromise network security. Security researchers have raised alarms about this issue, urging companies to take immediate action to secure their devices. The situation underscores the need for vigilance in monitoring access to critical security infrastructure.

Read Original

LastPass is warning users about a phishing campaign that is attempting to steal their master passwords. Fraudulent emails are being sent to LastPass users, claiming they need to back up their accounts within 24 hours. The company has confirmed that it would never request such an action, indicating that these emails are not legitimate. This phishing attempt poses a risk as it could lead to unauthorized access to users' sensitive information if they fall for the scam. Users are advised to remain vigilant and to disregard any such messages that ask for urgent account actions.

Read Original

A recent survey conducted by Vodafone reveals that many executives in the UK are deeply concerned about the potential impact of a major cyber-attack on their businesses. The findings indicate that a significant number of leaders believe their companies may not survive such an incident. This sentiment reflects a growing awareness of the vulnerabilities organizations face in an increasingly digital landscape. With cyber threats becoming more sophisticated, the urgency for robust cybersecurity measures is evident. Executives are now recognizing that proactive strategies and investments in security are essential to safeguard their operations and data.

Read Original

Arctic Wolf has reported a surge in automated attacks targeting Fortinet FortiGate devices, which has been ongoing since January 15, 2026. These attacks involve unauthorized changes to firewall configurations, with attackers creating generic accounts to maintain access, enabling VPN capabilities, and exfiltrating sensitive firewall data. This activity mirrors similar attacks identified in December 2025. Organizations using FortiGate firewalls should be vigilant, as these breaches can compromise network security and expose critical information. The situation emphasizes the need for enhanced security measures and monitoring to detect such unauthorized activities.

Read Original

A recent report from DLA Piper shows that over 160,000 companies have reported breaches to European GDPR regulators, marking a 22% increase in notifications compared to previous years. This surge indicates that businesses are becoming more aware of their obligations under the GDPR and are taking steps to comply with reporting requirements. The increase in notifications could also reflect a rise in actual data breaches or a heightened awareness of data privacy issues. Companies that fail to report breaches risk facing significant fines, which can be as much as 4% of their annual global revenue. This trend is crucial because it emphasizes the ongoing challenges organizations face in protecting personal data and maintaining compliance with data protection laws.

Read Original

A newly discovered vulnerability in SmarterTools' SmarterMail email software is currently being exploited just two days after a patch was released on January 15, 2026. This flaw, tracked as WT-2026-0001 by watchTowr Labs, has not yet been assigned a CVE identifier. The issue allows attackers to bypass authentication mechanisms, posing a significant risk to users of the software. Organizations using SmarterMail should prioritize applying the latest patch to protect against potential exploitation. The rapid exploitation of this vulnerability highlights the need for timely updates and vigilance in monitoring for unusual activity.

Read Original

Atlassian, GitLab, and Zoom have recently released security patches addressing more than two dozen vulnerabilities, some of which are classified as critical or high-severity. These updates aim to protect users from potential attacks that could exploit these weaknesses. Affected products include popular collaboration tools and development platforms, which are widely used in various organizations. It's crucial for users of these applications to apply the patches promptly to safeguard their systems against possible exploitation. The vulnerabilities could allow unauthorized access or other malicious activities if not addressed, making timely updates essential for maintaining security.

Read Original
Actively Exploited

Recent research by Pentera has revealed that training applications, designed to teach secure coding and provide hands-on practice, are being left exposed on the public internet. These applications, including OWASP Juice Shop and Damn Vulnerable Web Application, are often used for demos and internal testing. Unfortunately, security teams may not realize that these intentionally vulnerable environments are actively being exploited by attackers. This situation poses a significant risk, as it allows malicious actors to gain access to sensitive information or launch further attacks from these platforms. Organizations using such training tools need to ensure they are properly secured to prevent unauthorized access.

Read Original

NIST has significantly reduced its workforce, cutting over 700 jobs since 2025, which has raised concerns about its ability to manage key projects, including encryption standards. Among the job losses, 89 positions were eliminated from a lab that plays a crucial role in testing and validating encryption methods used by the government. This reduction in staff could hinder NIST's ability to respond to emerging security challenges and develop new standards, potentially putting sensitive government data at risk. The cuts highlight the ongoing struggle within government agencies to balance budgets while maintaining essential cybersecurity functions. The impact of these staff reductions could be felt across various sectors that rely on NIST's guidance for encryption and security protocols.

Read Original
Actively Exploited

Cisco has addressed a serious security flaw in its Unified Communications and Webex Calling platforms, identified as CVE-2026-20045. This vulnerability allows attackers to execute arbitrary commands remotely without authentication, posing a significant risk to users. The flaw has been actively exploited in the wild, which raises concerns for organizations relying on these communication tools. With a CVSS score of 8.2, it is classified as critical, emphasizing the urgency for users to apply the available patches. Companies utilizing Cisco's services should prioritize updating their systems to mitigate potential attacks.

+1 more
Read Original
Actively Exploited

A significant spam wave is hitting users globally, stemming from unsecured Zendesk support systems. Victims are reporting receiving hundreds of unsolicited emails with unusual and sometimes alarming subject lines, raising concerns about the safety and security of their information. This incident indicates a serious lapse in security measures, as attackers are exploiting vulnerabilities in the ticketing system to send out mass spam. The situation is alarming as it not only affects individuals but could also lead to broader security issues if sensitive information is compromised. Companies using Zendesk should review their security protocols to prevent unauthorized access and protect their users from being targeted in this way.

Read Original

Cisco has addressed a serious vulnerability in its Unified Communications and Webex Calling platforms, identified as CVE-2026-20045. This remote code execution flaw was found to be actively exploited by attackers, posing a significant risk to users. The vulnerability could allow unauthorized access to systems, potentially leading to data breaches or service disruptions. Organizations using these Cisco products are urged to apply the latest updates to mitigate the risk. This incident underscores the importance of timely patch management in maintaining cybersecurity hygiene.

Read Original
PreviousPage 308 of 374Next