Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Taiwan's National Security Bureau has reported a significant increase in daily cyber intrusion attempts, attributing the surge to what they describe as a Chinese 'cyber army.' The number of attacks rose by 6% in 2025, with the energy and healthcare sectors experiencing the most substantial impacts. This uptick raises concerns about the security of critical infrastructure and sensitive data in Taiwan, especially as these sectors are vital for public welfare and national stability. The situation underscores the ongoing cyber tensions between Taiwan and China, highlighting the need for enhanced cybersecurity measures in the face of persistent threats. Taiwanese authorities are likely to heighten their defenses to safeguard against these intrusions.

Read Original
Critical
Lone Hacker Used Infostealers to Access Data at 50 Global Companies

Hackread – Cybersecurity News, Data Breaches, AI, and More

Actively Exploited

A recent report from Hudson Rock has revealed that an Iranian hacker, known as Zestix, successfully breached 50 global companies, including Iberia Airlines and Pickett & Associates. The hacker gained access by exploiting stolen passwords and taking advantage of the companies' failure to implement multi-factor authentication (MFA). This incident raises concerns about the security practices of major organizations, especially as Zestix's activities highlight vulnerabilities that could be easily mitigated. The breaches not only compromise sensitive data but also pose a significant risk to the reputation and trustworthiness of the affected companies. Organizations should reassess their security measures to prevent similar attacks in the future.

Read Original
Actively Exploited

Attackers are taking advantage of misconfigured email routing to send phishing emails that appear to come from within an organization. This tactic involves using Platforms as a Service (PhaaS), such as Tycoon2FA, to create these deceptive messages aimed at stealing user credentials. The vulnerability lies in the complex routing scenarios and inadequate spoof protections that companies have in place, making it easier for these phishing attempts to bypass security measures. Organizations need to be vigilant about their email configurations and ensure that their spoof protections are properly set up to prevent these types of attacks. Without proper safeguards, employees may unknowingly provide sensitive information to attackers posing as internal communications.

Read Original

ownCloud, a popular file-sharing platform, has issued a warning to its users about potential credential theft that could lead to unauthorized data access. The company emphasized the importance of enabling multi-factor authentication (MFA) as a crucial step to protect accounts from attackers who may have obtained user credentials. This alert comes amid reports of compromised accounts, which can lead to significant data breaches if not addressed promptly. Users are urged to take immediate action to secure their accounts, as the risk of exploitation remains high. This incident serves as a reminder of the vulnerabilities associated with relying solely on passwords for account security.

Read Original
Critical
Why Legitimate Bot Traffic Is a Growing Security Blind Spot

Hackread – Cybersecurity News, Data Breaches, AI, and More

Security teams have made significant advancements in identifying and blocking harmful bots, but a new concern is emerging: legitimate bot traffic. This type of traffic, often used for various business functions, is becoming a security blind spot. While these bots can enhance user experience, they also pose risks as they can be exploited by attackers to bypass security measures. Companies may inadvertently allow these bots to operate unchecked, leaving systems vulnerable to abuse. As organizations increasingly rely on automation and bots, it's crucial for them to improve their detection capabilities to differentiate between helpful and harmful bot activity.

Read Original

The article discusses the potential use of cyberattacks as part of a military operation in Venezuela, referencing comments made by former President Trump about the ability to disrupt the power grid in Caracas. While the specifics of any cyber operations remain unclear, the notion that cyber capabilities could be employed in military actions raises significant concerns. This could affect not only Venezuela but also signal a shift in how nations might integrate cyber warfare into conventional military strategies. The implications of such actions could lead to increased tensions and instability in the region, as well as a reevaluation of cybersecurity measures by nations monitoring these developments.

Read Original

In 2025, Taiwan reported an alarming increase in cyber intrusion attempts on its critical infrastructure, averaging 2.63 million per day, primarily attributed to Chinese attackers. This surge has raised significant concerns about the security of Taiwan's energy sector and other vital systems, as such attacks could lead to disruptions in services and pose risks to national security. The frequency and intensity of these cyber intrusions suggest a coordinated effort to undermine Taiwan's infrastructure, which could have serious implications for the region's stability. As the situation evolves, it is crucial for Taiwanese authorities and organizations to bolster their defenses against these persistent cyber threats to protect their critical assets.

Read Original

Researchers have identified a severe vulnerability in n8n, a widely-used workflow automation platform, allowing unauthenticated attackers to take full control of affected instances. This flaw, tracked as CVE-2026-21858 and given a maximum CVSS score of 10.0, has been named Ni8mare by Cyera Research Labs. The issue poses a significant risk as it could enable attackers to manipulate workflows and access sensitive data without any authentication. Users of n8n need to take this threat seriously, as the implications of such a breach could be extensive, impacting data integrity and privacy. Immediate action is recommended to safeguard systems until a patch is made available.

Read Original

Veeam Backup & Replication has recently patched four vulnerabilities that could allow attackers to execute arbitrary code. These flaws affect users of the Veeam Backup & Replication software, which is widely used for data backup and recovery. If exploited, these vulnerabilities could lead to unauthorized access or manipulation of backup data, posing significant risks to data integrity and security. Users are strongly encouraged to update to the latest version of the software to close these security gaps and protect their systems from potential attacks. Keeping software up to date is crucial for maintaining a secure environment, especially for applications that handle sensitive data.

Read Original

Veeam has issued security updates to address several vulnerabilities in its Backup & Replication software, including a significant remote code execution (RCE) flaw. This critical vulnerability could allow attackers to gain control over backup servers, posing a serious risk to organizations relying on this software for data protection. The flaws affect various versions of the Backup & Replication software, potentially exposing many users to exploitation if they do not update promptly. This situation is concerning as backup servers are vital for data recovery and integrity, and any compromise could lead to severe operational disruptions. Users are urged to apply the latest patches to safeguard their systems.

Read Original
Actively Exploited

A newly discovered vulnerability in discontinued D-Link devices poses a serious risk, allowing attackers to execute arbitrary shell commands without authentication. This critical-severity flaw affects users of these outdated devices, which may still be in use despite not being supported or receiving updates from the manufacturer. The fact that the vulnerability is being actively exploited means that users should take immediate action to safeguard their networks. If left unaddressed, this could allow attackers to gain control over affected devices, potentially leading to larger network breaches. Users of D-Link products are advised to assess their device usage and consider replacing unsupported hardware to mitigate these risks.

Read Original

The UK government has rolled out a new cybersecurity initiative aimed at enhancing defenses across public sector institutions, investing over £210 million ($283 million) in the process. This strategy will focus on improving the security of government departments and other public services to better protect against cyber threats. The funding will support various projects, including the development of new technologies and training programs for staff. With increasing cyber attacks targeting public services, this move is seen as crucial for safeguarding sensitive data and maintaining public trust. The government emphasizes the need for a stronger defense mechanism as cyber threats continue to evolve and pose risks to national security.

Read Original

Wegman’s supermarket chain in New York City has been reported to collect biometric information from its customers, specifically through the use of facial recognition technology. This practice raises significant privacy concerns, as many shoppers may not be aware that their images are being captured and analyzed. The implications of this surveillance include potential misuse of personal data and the erosion of trust between consumers and retailers. As more businesses adopt such technologies, it becomes crucial for customers to understand how their information is being used and to advocate for transparency in data collection practices. The issue also highlights the need for regulations governing biometric data to protect consumer rights.

Read Original

Veeam has addressed a serious remote code execution (RCE) vulnerability in its Backup & Replication software, identified as CVE-2025-59470, which has a high severity score of 9.0 on the CVSS scale. This flaw allows Backup or Tape Operators to execute arbitrary code remotely as the postgres user, potentially leading to significant security breaches. Alongside this critical issue, Veeam also patched several other vulnerabilities in the same software suite. Users of Veeam Backup & Replication should prioritize applying these patches to safeguard their systems from potential exploitation. The swift response by Veeam reflects the importance of maintaining updated software to prevent unauthorized access and data breaches.

Read Original

Cybercriminals are exploiting complex routing and misconfigurations to spoof legitimate domains in phishing attacks. By masquerading as trusted internal sources, these attackers trick users into believing the emails are from their organization, increasing the likelihood of successful scams. This tactic can lead to unauthorized access to sensitive information and financial loss for businesses. Organizations need to be vigilant about their domain configurations and educate employees on recognizing such phishing attempts. The implications of these attacks are significant, as they can compromise entire networks if not addressed promptly.

Read Original
PreviousPage 328 of 375Next