Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Researchers from the University of Birmingham and Fuzzware have discovered a serious security flaw involving compromised SIM cards that can hijack smartphones and other cellular devices. These malicious SIMs can issue commands that allow attackers to steal sensitive information, disrupt communication, and even downgrade devices to the less secure 2G network. This vulnerability arises from a legitimate feature in the cellular specification known as Proactive SIM, which enables a SIM card to send commands to the device. This discovery raises significant concerns for users of affected devices, as it can lead to unauthorized access and data theft. The researchers stress the importance of addressing this issue to protect users from potential exploitation.

Read Original

Mozilla has revoked the cryptographic signing key for its Firefox and Thunderbird applications on Linux after a copy of the key was mistakenly uploaded to a private code repository without encryption. This key is essential for verifying that downloaded versions of the browsers are authentic and have not been altered. As a result of this incident, users and Linux distributions will need to deal with the fallout of not having a valid key to confirm the integrity of their downloads. Mozilla's decision to scrap the key raises concerns about trust and security for users relying on these popular open-source applications. The company will need to issue a new signing key and ensure that users are informed about the changes to maintain the security of their software.

Read Original

Researchers at Kaspersky have identified a cybersecurity threat involving the Head Mare APT group, which is exploiting vulnerabilities in unpatched TrueConf servers. This group is using malicious software installers to deliver two backdoors, PhantomCore and PhantomGraph, to users participating in video conferences. The attack specifically targets systems that have not updated their TrueConf software, making them susceptible to these exploits. This situation raises significant concerns for organizations that rely on video conferencing tools for communication, as attackers could gain unauthorized access to sensitive information. Users and companies should prioritize patching their TrueConf installations to mitigate this risk.

Read Original

Suisan City, California, has been hit by a cyber attack that has disrupted police and fire department operations. This incident is part of a worrying trend, as two other local government agencies in the U.S. also experienced cyber incidents in the past week. The attack raises concerns about the security measures in place for local governments, which are increasingly targeted by cybercriminals. The impact on emergency services highlights the potential dangers such incidents pose to public safety. Authorities are likely assessing the situation to restore services and prevent future attacks.

Read Original

The UK's National Cyber Security Centre (NCSC) has introduced new guidance for the water sector, marking the first content created by the Industrial Control System Community of Interest (COI) on their website. This guidance focuses on establishing secure connectivity principles for water utilities, which are critical in maintaining the integrity and availability of water services. As cyber threats targeting critical infrastructure continue to rise, this initiative aims to help organizations better protect their systems from potential attacks. The guidance serves as a resource for water companies to improve their cybersecurity practices, ensuring that they can safeguard essential services against disruptions. This development is particularly relevant given the increasing sophistication of cyber threats faced by essential service providers.

Read Original
Critical
Pulsetto Vagus Nerve Stimulator

All CISA Advisories

A significant vulnerability has been identified in the Pulsetto Vagus Nerve Stimulator, affecting all versions of the device. This flaw allows attackers to exploit hidden commands via Bluetooth Low Energy (BLE) without any authentication or encryption. If successfully exploited, attackers could disable safety mechanisms or alter stimulation settings, posing serious risks to patients who rely on this medical device. Pulsetto has not collaborated with CISA to address the issue, leaving users vulnerable. It's crucial for users to contact Pulsetto directly for assistance and take defensive measures to protect their devices from potential exploitation.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are actively exploited in the wild. The vulnerabilities include a heap inspection flaw in Cisco Secure Firewall Adaptive Security Appliance (CVE-2026-20349), a use-after-free vulnerability in Microsoft Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a SQL injection vulnerability in Metabase (CVE-2026-72898). These vulnerabilities pose significant risks, especially to federal agencies, prompting CISA to emphasize the need for rapid remediation of high-risk vulnerabilities. While the Binding Operational Directive 26-04 applies specifically to federal agencies, CISA encourages all organizations to adopt similar risk-based approaches to vulnerability management. Organizations aware of other exploited vulnerabilities can submit them for potential inclusion in the KEV Catalog.

Read Original

Security researchers created a fake cryptocurrency startup to investigate potential threats from North Korea. They advertised developer positions and hired three individuals they suspect are North Korean operatives. Throughout the onboarding process, every virtual machine provided was monitored to gather information. One of the hires presented conflicting identification, claiming to reside in Pasadena, Texas, while providing a California driver's license and a New York bank account. This incident raises concerns about the lengths to which state-sponsored hackers might go to infiltrate legitimate businesses and underscores the need for companies to be vigilant in their hiring practices and background checks.

Read Original

At DEF CON 34, researchers demonstrated a new attack method dubbed 'GhostJacking,' which targets integrations with popular services like Cloudflare, DataDog, and Sentry. This technique exploits error logs to perform indirect prompt injections, potentially allowing attackers to manipulate how these services respond to user inputs. The implications of this attack could be significant, as it could lead to unauthorized access or data leakage in systems relying on these integrations. As organizations increasingly rely on cloud services for their operations, understanding and mitigating such vulnerabilities becomes essential. Companies using these platforms should review their error handling practices to safeguard against this type of attack.

Read Original

Ceva Logistics, a major player in the supply chain industry, has reported a significant data breach that affects its European clients. The breach appears to be the result of a supply chain attack, which typically targets third-party vendors to gain access to larger networks. Although specific details about the data compromised have not been disclosed, the scale of the breach suggests a wide-ranging impact, potentially affecting numerous businesses relying on Ceva's logistics services. This incident raises concerns about the security of supply chain operations, as attackers increasingly exploit vulnerabilities in third-party providers. Companies associated with Ceva need to assess their data security measures and respond appropriately to protect sensitive information.

Read Original

Researchers have discovered a method where malicious servers connected to AI coding assistants can stealthily exfiltrate sensitive information like SSH keys, environment secrets, source code, and customer data. This technique involves splitting requests into smaller parts that appear benign, allowing them to pass through security checks unnoticed. Even if a straightforward theft attempt is blocked, the fragmented requests can still succeed by using existing communication channels. This poses a significant risk for organizations relying on AI tools, as attackers could potentially access critical data without triggering alarms. Companies need to be vigilant about the security of their AI tools and implement robust monitoring to detect unusual activity.

Read Original

A recent report from Dragos reveals that ransomware attacks targeting industrial organizations are on the rise, with 1,140 incidents recorded in the second quarter of 2026, a 12% increase from the previous quarter. Notably, attackers do not need direct access to industrial control systems (ICS) to cause significant disruptions; targeting the IT systems that support these environments can be sufficient. The manufacturing sector was particularly hard hit, accounting for 747 of the reported incidents. This trend raises concerns about the vulnerability of industrial operations, as disruptions can lead to production delays and financial losses. Companies need to bolster their cybersecurity measures to protect against these types of attacks, which are increasingly common and damaging.

Read Original

A vulnerability in OpenSSH versions prior to 10.5 allowed users to inadvertently expose local-only keys when locking the ssh-agent. In OpenSSH 10.4, locking the agent disabled a security check that determined whether connection requests came from the local machine or a remote, forwarded connection. This flaw meant that if users locked their ssh-agent, it could still respond to requests that shouldn't be permitted. The issue was addressed in the recently released OpenSSH 10.5, which restores the proper functionality of the lock feature. Users relying on ssh-agent for secure connections should update to this version to ensure their private keys remain protected.

Read Original

OpenAI has decided to pause some testing of its upcoming Astra model due to emerging security concerns. This model is part of their efforts to advance artificial intelligence, but potential vulnerabilities have raised alarms about its safety. The company is implementing tighter controls on how and when the model can be tested, aiming to ensure that security risks are adequately addressed before further development continues. This move is significant as it reflects growing awareness in the tech community about the implications of AI systems and their potential misuse. OpenAI's decision highlights the need for careful consideration of security in AI development, which could have broad implications for users and developers alike.

Read Original

In a recent article, Rishi Sharma discusses how large language models (LLMs) can be utilized to discover vulnerabilities in software systems. Researchers are exploring the potential of LLMs to automate the identification of security flaws, which could significantly enhance the efficiency of vulnerability assessments. This approach may help security teams prioritize and address vulnerabilities more effectively, potentially reducing the risk of exploitation. As organizations increasingly rely on complex software, the ability to quickly and accurately discover vulnerabilities is crucial in protecting sensitive data and maintaining system integrity. This emerging use of AI in cybersecurity underscores the need for continuous innovation in threat detection.

Read Original
PreviousPage 32 of 363Next