Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A new malware framework called VoidLink has been identified as a sophisticated threat targeting Linux systems. Research from Check Point indicates that this framework was likely developed by an individual with the help of artificial intelligence. The malware has reached an impressive 88,000 lines of code, showcasing its complexity and potential for damage. The findings also reveal operational security mistakes made by the author, which provided insights into its creation. This development is concerning for Linux users and organizations, as it points to an increasingly advanced and potentially widespread malware landscape.

Read Original

USB drives pose a significant security risk for enterprises, as they can easily introduce malware into corporate networks. Researchers warn that these small devices often go unchecked and can lead to data breaches or unauthorized access. Many organizations still rely on USB drives for data transfer, making them an attractive target for cybercriminals. The ease of use and widespread availability means that employees might unwittingly use infected drives, compromising sensitive information and systems. Companies should implement strict policies regarding the use of USB drives and consider investing in security solutions that can monitor and control their use.

Read Original

Deloitte's latest report warns that businesses are rapidly adopting agentic AI systems without adequate safety measures in place. While these AI tools promise to enhance productivity, they also introduce significant risks that many companies may not fully understand. The report emphasizes that the pace of AI deployment is outstripping the development of necessary safety protocols, which could lead to serious security vulnerabilities. This situation raises concerns for organizations that might be exposing themselves to cyber threats as they integrate these technologies. As the reliance on AI grows, it's crucial for businesses to prioritize safety and implement comprehensive security frameworks to protect against potential risks.

Read Original

SK Telecom, a leading telecommunications company in South Korea, is challenging a hefty $91 million fine imposed by the Personal Information Protection Commission. This penalty was a result of a cyberattack in April that compromised the personal data of all 23 million of the company's users. The breach raised significant concerns about data security and the responsibilities of companies to protect customer information. By contesting the fine, SK Telecom is not only seeking to mitigate financial repercussions but also potentially setting a precedent for how data breaches are handled in the future. This incident serves as a reminder of the ongoing risks companies face in safeguarding sensitive user data.

Read Original
Actively Exploited

A malicious Visual Studio Code extension has been identified as a vehicle for distributing the Evelyn information-stealing malware. Cybersecurity researchers have found that this multi-stage attack can compromise sensitive information from affected users. Developers and users of Visual Studio Code are particularly at risk, as the extension can infiltrate systems through the widely used code editor. This incident underscores the need for caution when installing extensions from unverified sources. Users should ensure they only use trusted extensions and maintain updated security software to protect against such threats.

Read Original

A new infostealer malware called SolyxImmortal has emerged, believed to be developed by a Turkish-speaking hacker. This malware allows attackers to covertly monitor users and steal sensitive data by utilizing legitimate application programming interfaces (APIs) and third-party libraries, making detection more difficult. The exact targets of this malware have not been specified, but its stealthy nature poses a significant risk to individuals and organizations that rely on affected software. As cybercriminals continuously evolve their tactics, it’s crucial for users to remain vigilant and ensure their systems are secure against such threats.

Read Original
Everest Ransomware Claims McDonalds India Breach Involving Customer Data

Hackread – Cybersecurity News, Data Breaches, AI, and More

The Everest ransomware group has claimed responsibility for a data breach involving McDonald's India, potentially affecting customer information. This incident raises significant concerns about the security of customer data, as ransomware attacks often lead to sensitive information being stolen or compromised. McDonald's India has not yet confirmed the breach or provided details about the extent of the data involved. Ransomware attacks like this can damage a company's reputation and erode customer trust, especially in a market where data privacy regulations are becoming stricter. As the situation unfolds, customers and stakeholders will be closely monitoring how McDonald's responds and what measures are put in place to prevent future incidents.

Read Original
Actively Exploited

A new cybersecurity threat involves a malicious browser extension called NexShield, which uses social engineering tactics to crash users' browsers. This attack is designed to deliver a Python-based Remote Access Trojan (RAT), putting users' systems at risk of further compromise. The method relies on tricking users into installing the extension, which then takes control of their browsers. As a result, individuals and organizations that fall victim could face significant data theft or system damage. Users are advised to be cautious about browser extensions and ensure they are from trusted sources to avoid falling prey to such scams.

Read Original

HackerOne has introduced a new voluntary framework aimed at providing legal protections for researchers investigating artificial intelligence systems. This framework is designed to support third-party researchers who study the safety and unexpected behaviors of AI technologies. By clarifying legal boundaries, it encourages more researchers to engage in 'good faith' AI research without fear of legal repercussions. This initiative is significant as it could lead to more thorough safety assessments of AI systems, ultimately benefiting developers and users alike. The framework aims to foster a collaborative environment where researchers can share findings and improve AI reliability.

Read Original

The European Union is moving forward with plans to phase out high-risk telecom suppliers, which many observers see as a direct response to security concerns linked to Chinese companies. New regulations will make cybersecurity measures for 5G networks mandatory, aiming to reduce potential vulnerabilities that could be exploited by foreign entities. This decision affects various telecom operators and equipment manufacturers who may rely on these suppliers. By implementing stricter guidelines, the EU hopes to strengthen its telecom infrastructure and safeguard against espionage and cyberattacks. The proposed rules are part of a broader strategy to enhance digital sovereignty and security across member states.

Read Original

Researchers have discovered a new malware framework named VoidLink, which is designed for cloud environments. This malware appears to have been created by an individual using artificial intelligence tools, indicating a shift in how cybercriminals may develop their software. The framework has specific capabilities that could potentially target various cloud services, posing a risk to organizations that rely heavily on cloud technologies. The emergence of AI-generated malware raises concerns about the accessibility of sophisticated attack methods for less experienced hackers, which could lead to more widespread and damaging cyberattacks. Companies using cloud services should be on high alert and review their security measures to guard against this new threat.

Read Original

The European Commission is pushing for new cybersecurity legislation aimed at enhancing the security of telecommunications networks. This proposal focuses on the removal of high-risk suppliers, particularly those linked to foreign nations, to protect against threats from state-sponsored actors and cybercriminal groups targeting critical infrastructure. The initiative comes in response to increasing concerns about security vulnerabilities in supply chains and the potential for attacks on essential services. By strengthening these regulations, the EU aims to create a safer digital environment for its member states and reduce reliance on potentially unsafe technology providers. The move is significant as it could reshape how telecommunications are managed across Europe, impacting various vendors and service providers.

Read Original

Congressional appropriators are moving forward with legislation that aims to extend an information-sharing law designed to enhance cybersecurity collaboration between the government and private sector. The proposed legislation also allocates funds to the Cybersecurity and Infrastructure Security Agency (CISA), ensuring it can maintain adequate staffing levels. Additionally, it mandates funding for election security and continues a grant program for state and local governments to bolster their cyber defenses. This initiative is crucial as it aims to strengthen the country's overall cybersecurity posture, especially in light of ongoing threats to critical infrastructure and election systems. By securing funding and support for CISA, the legislation seeks to enhance response capabilities and resilience against cyber attacks.

Read Original

Researchers have identified vulnerabilities in the Chainlit AI framework, which is widely used for building AI chatbots. These security flaws could allow attackers to gain unauthorized access to cloud systems, posing significant risks to organizations that rely on this technology. The vulnerabilities are not new, suggesting that they have been present for some time and may have gone unnoticed by many users. This situation is particularly concerning as it raises the potential for data breaches or misuse of AI capabilities. Companies utilizing the Chainlit framework should take immediate action to assess their systems and implement necessary security measures to protect against potential exploitation.

Read Original

Ingram Micro, a major technology distributor, experienced a data breach that compromised the personal information of approximately 42,000 individuals. The breach was detected on July 3, 2025, prompting the company to initiate an investigation with cybersecurity experts to assess the extent of the incident. The affected data may include sensitive details, although specifics about what information was accessed have not been disclosed. This incident raises concerns about the security practices in place at Ingram Micro and the potential risks faced by those whose information was exposed. As the investigation continues, affected individuals should remain vigilant for any signs of identity theft or phishing attempts.

Read Original
PreviousPage 311 of 374Next