Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Trellix, a cybersecurity firm, has reported a data breach after attackers accessed part of its source code repository. The breach raises concerns about the security of the company's software and the potential exposure of sensitive information. While Trellix did not disclose the extent of the data accessed, incidents like this can lead to vulnerabilities in the software products they develop. This situation serves as a reminder for companies to regularly assess their security measures and safeguard their intellectual property. Customers and partners are advised to stay vigilant and monitor for any unusual activity related to Trellix products.

Impact: Trellix source code repository
Remediation: Companies should review their security protocols and enhance access controls to source code repositories.
Read Original

A college student is taking legal action against a dating app for allegedly using her TikTok videos to target men living in her dorm. According to her lawyer, the dating app edited her content to imply she was looking for a 'friend with benefits' and geofenced the posts to reach nearby male users. This raises significant concerns about privacy and consent, as the student did not authorize the app to use her videos in this manner. The case could set a precedent for how dating apps and other platforms handle user-generated content and targeted advertising. It also highlights the potential risks associated with sharing personal videos online, particularly on social media platforms.

Impact: Dating app, TikTok
Remediation: N/A
Read Original

A new botnet is targeting gaming servers by exploiting misconfigured Jenkins installations. Attackers accessed the Jenkins server through a vulnerability in the scriptText endpoint, which allowed them to execute remote code using a Groovy script. This incident raises concerns for gaming companies and server administrators, as it can lead to unauthorized access and potential service disruptions. Organizations using Jenkins need to ensure their configurations are secure to prevent similar attacks. The exploitation of this vulnerability could have significant implications for the security of gaming platforms and user data.

Impact: Jenkins servers, gaming servers
Remediation: Secure Jenkins configurations, disable the scriptText endpoint if not in use, apply security best practices for Jenkins installations
Read Original
Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities

Hackread – Cybersecurity News, Data Breaches, AI and More

At the Wiz ZeroDay.Cloud event, researchers disclosed significant vulnerabilities in PostgreSQL that have existed for 20 years. These flaws, particularly in the pgcrypto module, could allow attackers to exploit the database's security, raising serious concerns for organizations relying on PostgreSQL for data management. The researchers emphasized the urgency of applying patches to mitigate these risks and protect sensitive information. With many systems still using outdated versions, companies should prioritize updating their PostgreSQL installations to safeguard against potential attacks. This incident serves as a stark reminder of the importance of regular security audits and timely updates in maintaining database integrity.

Impact: PostgreSQL, specifically the pgcrypto module
Remediation: Urgent patches are required for affected PostgreSQL versions, specific patch numbers not specified
Read Original

Fraudsters are increasingly targeting credit unions by exploiting standard business processes rather than using traditional hacking methods. According to research from Flare, these criminals use stolen identities to navigate verification systems, allowing them to secure loans fraudulently. This method of structured loan fraud poses a significant risk to credit unions, as it can lead to substantial financial losses and undermine customer trust. By bypassing security measures that are typically relied upon, these fraudsters are able to manipulate systems in ways that may not trigger alarms. It’s essential for credit unions to enhance their verification processes to combat this type of fraud effectively.

Impact: Credit unions, loan systems, identity verification processes
Remediation: Enhance verification processes, implement stricter identity checks
Read Original

DigiCert, a prominent certificate authority, has revoked a number of certificates after a security breach involving its internal support portal. Hackers managed to deliver malware through a customer chat channel, which infected an analyst’s system. This breach allowed them access to sensitive internal systems, raising concerns about the security of the certificates issued by DigiCert. The incident highlights significant vulnerabilities in customer support systems, emphasizing the need for stronger security measures in such environments. Companies relying on DigiCert for SSL certificates may need to assess the implications of this breach on their own security postures.

Impact: DigiCert certificates
Remediation: Revocation of compromised certificates and review of internal security protocols.
Read Original

Stephen Campbell from Team Cymru has expressed concerns that many small defense contractors in the U.S. are not adequately equipped to fend off cyberattacks, particularly those originating from nation-state hackers. These smaller firms often use edge devices, which can be vulnerable entry points for attackers. Campbell emphasizes that without sufficient network data and resources, these companies struggle to detect and mitigate intrusions. This lack of preparedness could have serious implications, not just for the contractors themselves but also for national security, as these companies often handle sensitive defense information. The warning serves as a call for increased investment in cybersecurity measures among smaller firms in the defense sector.

Impact: Small U.S. defense contractors, edge devices used in defense operations.
Remediation: Companies should enhance their cybersecurity infrastructure and invest in monitoring solutions for edge devices.
Read Original

The cybercrime group Silver Fox, based in China, has launched a phishing campaign targeting organizations in India and Russia using a new malware known as ABCDoor. The attackers sent emails posing as communications from the Income Tax Department of India in December 2025, followed by similar attempts aimed at Russian entities. This tactic is concerning as it exploits tax-related themes to gain trust and infiltrate systems. The use of ABCDoor malware can lead to unauthorized access to sensitive information, potentially compromising the security of targeted organizations. As cyber threats continue to evolve, it is crucial for companies in these regions to enhance their security measures and educate employees on recognizing phishing attempts.

Impact: Organizations in India and Russia, specifically those handling tax-related information.
Remediation: Companies should implement robust email filtering, employee training on phishing recognition, and ensure software and systems are updated regularly to defend against such malware.
Read Original

CISA has issued a warning that the 'Copy Fail' vulnerability in Linux systems is being actively exploited by attackers. This flaw was disclosed just one day prior by researchers from Theori, who also released a proof-of-concept exploit. The vulnerability allows attackers to gain root access to compromised Linux systems, putting a wide range of users and organizations at risk. System administrators and users of affected Linux distributions need to take immediate action to secure their systems against potential exploits. The rapid exploitation following the disclosure highlights the urgency for organizations to patch their systems as soon as possible.

Impact: Linux systems vulnerable to the 'Copy Fail' flaw, specifically those versions that allow for root access exploitation.
Remediation: System administrators should apply available patches for their Linux distributions or implement security configurations to mitigate the risk of exploitation. It is advisable to monitor system logs for any unusual activity and consider disabling features that may be exploited until patches are applied.
Read Original

Microsoft has acknowledged that the April 2026 security updates for Windows are causing issues with third-party backup applications that rely on the psmounterex.sys driver. This problem is affecting various backup solutions, preventing users from successfully backing up their data. The situation is significant as it could lead to data loss for individuals and businesses that depend on these backup tools for data protection. Microsoft has not yet released a specific fix or workaround for this issue, leaving users in a precarious position. Companies and users are advised to monitor for updates from Microsoft regarding this ongoing issue.

Impact: Third-party backup applications using psmounterex.sys driver
Remediation: N/A
Read Original

Researchers have identified a new phishing technique that exploits Amazon's Simple Email Service (SES) to send fraudulent emails that appear legitimate. By using this widely trusted cloud email service, attackers can bypass traditional email security measures. Victims may struggle to distinguish these phishing emails from real communications, making them more susceptible to scams. The implications are significant, as this method could lead to increased identity theft and financial loss for individuals and organizations alike. Users are advised to be vigilant and verify the authenticity of unexpected emails, especially those requesting sensitive information or prompting urgent actions.

Impact: Amazon Simple Email Service (SES), email communication systems
Remediation: Users should verify email sources and avoid providing sensitive information in response to unexpected requests. Implementing additional email filtering and security measures could also help mitigate risks.
Read Original

The article discusses the growing importance of data centers as critical infrastructure in today's digital economy, particularly due to the rising reliance on artificial intelligence. As businesses, supply chains, and national security increasingly depend on cloud services, data centers have become attractive targets for cyberattacks. The piece emphasizes that protecting these facilities is essential not just for individual companies but also for national security. It suggests that without proper safeguards, disruptions to data centers could have widespread repercussions, affecting numerous sectors and services that rely on cloud computing. The call to recognize data centers as critical infrastructure underscores the need for enhanced security measures to fend off potential threats.

Impact: Data centers, cloud services
Remediation: Implement enhanced security protocols, conduct regular vulnerability assessments, and establish incident response plans.
Read Original

The UK’s National Cyber Security Centre (NCSC) has issued a warning that advancements in artificial intelligence are leading to faster discovery of software vulnerabilities. This acceleration could result in a surge of urgent software updates, often referred to as a 'patch wave', to address these newly identified flaws. CTO Ollie Whitehouse cautioned that this trend increases the risk of large-scale exploitation by skilled attackers who could take advantage of unpatched vulnerabilities. This situation places pressure on software vendors to quickly develop and deploy fixes, highlighting the need for organizations to remain vigilant and prompt in their patching efforts. As the technology continues to evolve, the implications for cybersecurity could be significant, affecting a wide range of software products and systems across various industries.

Impact: N/A
Remediation: Organizations should prioritize timely software updates and patches as they become available, and maintain robust monitoring of their systems for vulnerabilities.
Read Original

The article discusses the challenges organizations face in transitioning to post-quantum cryptography while managing threats posed by artificial intelligence. Experts like Bobby Ford and HD Moore emphasize that traditional security measures may not suffice against AI-driven attacks, which are becoming more sophisticated and prevalent. Companies and institutions must adapt their defenses to counter these emerging risks effectively. The piece also touches on the need for collaboration among cybersecurity professionals to share knowledge and strategies in this evolving landscape. This is particularly urgent as the timeline for quantum computing advancements accelerates, potentially rendering current encryption methods obsolete.

Impact: Post-quantum cryptography systems, AI-driven security tools
Remediation: Organizations should begin adopting post-quantum cryptographic methods and enhance AI defenses.
Read Original

OpenAI is planning to broaden its Trusted Access for Cyber program, which is designed to assist cyber defenders across various government levels, including federal, state, and local agencies. This initiative aims to enhance the cybersecurity capabilities of these agencies, helping them better protect against cyber threats. By extending its program, OpenAI seeks to provide government entities with advanced tools and resources to strengthen their defenses. This move comes as cyber threats continue to evolve, underscoring the need for robust support for those tasked with safeguarding public information and infrastructure. The collaboration between tech companies like OpenAI and government bodies could lead to improved security measures that benefit all citizens.

Impact: N/A
Remediation: N/A
Read Original
PreviousPage 32 of 214Next