Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Actively Exploited

A serious security vulnerability has been discovered in Open WebUI Direct Connections, which could allow attackers to take over user accounts and compromise servers. This flaw poses a significant risk to organizations using the platform, as it could lead to unauthorized access and data breaches. Users of Open WebUI should be especially cautious, as the vulnerability may be actively exploited. It’s crucial for those affected to stay informed about updates and patches from the developers. Companies relying on this software need to prioritize security measures to protect their systems and data from potential attacks.

Read Original

Researchers have successfully set up a honeypot to attract members of the Lapsus$ hacking group, which has been known for its high-profile cyberattacks. By creating fake accounts and using synthetic data, they were able to gather valuable information about the hackers' infrastructure and tactics. This operation sheds light on the methods used by Lapsus$ and provides insights that could help in defending against their future attacks. The findings may be useful for cybersecurity professionals looking to enhance their defenses against similar threats. Overall, this initiative illustrates the ongoing cat-and-mouse game between hackers and security researchers.

Read Original

AI coding assistants, like the one integrated with Claude Code, are starting to manage software dependencies through plugins, which has raised new concerns about supply-chain security. When these automation tools are compromised, attackers could manipulate the dependencies that developers rely on, potentially injecting malicious code into software projects. This situation poses a significant risk for developers and companies that use these AI tools, as they might unknowingly include vulnerable or harmful libraries in their applications. The implications extend beyond individual developers to the broader software ecosystem, making it crucial for teams to stay vigilant and assess the security of their dependencies regularly. As reliance on AI tools grows, so does the need for heightened awareness of these emerging risks.

Read Original

Resecurity has published extensive documentation related to John Erin Binns, a hacker with ongoing activities who remains at large. The release includes over 1,000 messages that reveal Binns' communications with a woman in Turkey and an associate known as 'S.M.' This information could provide valuable insights into his operations and potential targets. The fact that Binns is not currently in U.S. custody raises concerns about the effectiveness of law enforcement efforts to track and capture cybercriminals. Resecurity’s actions may help inform other cybersecurity professionals and law enforcement about the methods and connections used by hackers, potentially leading to better prevention strategies against similar threats.

Read Original

A serious vulnerability in Dolby's software for Android devices has been identified, tracked as CVE-2025-54957. Discovered by Google researchers in October 2025, this flaw could potentially allow attackers to exploit the Dolby audio processing capabilities on affected devices. Users of Android devices utilizing Dolby technology should be particularly cautious, as the vulnerability poses risks to their audio functionality and overall device security. Immediate action is recommended to ensure that devices are updated to the latest software versions that include the necessary patches to fix this issue. This discovery emphasizes the need for regular updates and vigilance among users and security teams alike.

Read Original

The UK government has launched a new Cyber Action plan aimed at strengthening the nation's defenses against cyber threats. This initiative is designed to offer more direct support for organizations in protecting themselves from cyber incidents and improving their response strategies. The plan emphasizes collaboration between public and private sectors, ensuring that resources and expertise are shared effectively. This move responds to the increasing frequency and sophistication of cyberattacks, which pose risks to both national security and the economy. By enhancing the country's cyber resilience, the government aims to better protect businesses and individuals from potential breaches and disruptions.

Read Original

A single threat actor, identified as an initial access broker (IAB), has been linked to numerous significant data breaches across various organizations. This actor uses stolen credentials obtained through information stealers to gain unauthorized access to systems. Many companies are at risk as these breaches can lead to extensive data exposure and financial loss. Security researchers are urging organizations to bolster their defenses against credential theft, as the actor's methods highlight vulnerabilities that can be exploited. The widespread nature of these breaches emphasizes the need for improved security protocols and user awareness to protect sensitive information.

Read Original

Cybersecurity researchers at Securonix have reported a new campaign targeting the European hospitality sector, known as PHALT#BLYX. This campaign uses fake booking emails to trick hotel staff into clicking on links that lead to counterfeit blue screen of death (BSoD) error pages. By doing so, attackers aim to install a remote access trojan called DCRat on the victims' systems. This type of malware allows hackers to gain unauthorized access to sensitive information and control over the infected devices. The incident underscores the need for heightened vigilance among hotel employees regarding suspicious emails and links, as these tactics can lead to severe security breaches.

Read Original

Microsoft has responded to concerns raised by a security engineer regarding potential prompt injection vulnerabilities in its Copilot AI assistant. The engineer pointed out issues related to how the AI processes inputs, which could allow malicious prompts to bypass security measures. However, Microsoft disagrees, stating that these issues do not qualify as vulnerabilities. This disagreement reflects a broader debate between tech companies and security researchers about what constitutes a risk in generative AI systems. As AI technology becomes more integrated into various applications, understanding these distinctions is crucial for both developers and users, as it impacts how security measures are implemented and perceived.

Read Original

A serious vulnerability has been found in n8n, an open-source workflow automation platform, which could allow authenticated users to run arbitrary system commands on the server. This vulnerability, identified as CVE-2025-68668, has a high severity score of 9.9 according to the CVSS system, indicating a significant risk. It stems from a failure in the protection mechanisms that should keep the system secure. Users of n8n should be particularly concerned as this issue could lead to unauthorized control over their systems. The affected versions include all versions prior to the patch that addresses this vulnerability, making it crucial for users to update their installations promptly to prevent potential exploitation.

Read Original
Actively Exploited

Email continues to be the main entry point for cyber attackers, with significant increases in various types of email threats. Malware delivered through email surged by over 130% year-over-year, while phishing scams rose by more than 20% and other scams increased by 30%. These alarming trends expose vulnerabilities across different industries, indicating that many security teams are still missing critical gaps in their defenses. As attackers increasingly exploit email for impersonation and account takeover, companies must reassess their email security strategies to better protect sensitive information and prevent breaches. The growing reliance on email as a communication tool makes it essential for organizations to prioritize security measures in this area.

Read Original

A threat actor named Zestix has reportedly stolen corporate data from numerous companies after breaching their cloud file-sharing services, specifically ShareFile, Nextcloud, and OwnCloud. This attack highlights the vulnerabilities present in these platforms, which are widely used for storing and sharing sensitive business information. Companies that rely on these services should be particularly vigilant, as the stolen data is being offered for sale on dark web forums. The incident raises concerns about the security measures in place for protecting corporate data in cloud environments. Organizations are urged to review their security protocols and consider additional protections to safeguard against similar attacks.

Read Original
Actively Exploited

A new social engineering attack called ClickFix is targeting the hospitality industry in Europe by using fake Windows Blue Screen of Death (BSOD) screens. This scheme tricks users into believing their systems have crashed, prompting them to manually compile and run malicious software. The attackers are specifically focusing on employees in hotels and related businesses, making this a significant threat to sensitive customer data and operational continuity. Companies in this sector need to raise awareness among staff and implement training to recognize such scams. The use of a familiar error screen is particularly deceptive, as it plays on users' fears of system failures, leading them to take harmful actions without realizing the risks.

Read Original

A serious security flaw known as 'MongoBleed' has been identified in MongoDB servers, allowing attackers who are not authenticated to access sensitive information like passwords and tokens. This vulnerability is currently being exploited in the wild, raising significant concerns for organizations using MongoDB. The issue stems from a memory leak that can be exploited by attackers to extract confidential data directly from the servers. Companies running affected versions of MongoDB should prioritize patching their systems to mitigate the risk of unauthorized data access. Given the potential for serious data breaches, immediate action is essential for any organization relying on MongoDB for data storage.

Read Original

Ilya Lichtenstein, who was convicted for laundering Bitcoin stolen from the 2016 Bitfinex hack, has been released from prison after serving less than a year of his five-year sentence. His early release is attributed to a change in the law during the Trump administration that allows for reduced sentences for certain non-violent offenders. Lichtenstein and his wife were arrested in 2022 after authorities uncovered a significant amount of Bitcoin linked to the stolen funds. This release raises questions about the effectiveness of current laws in deterring cybercrime and the broader implications for cryptocurrency regulation. It also highlights the ongoing challenges law enforcement faces in addressing financial crimes related to digital currencies.

Read Original
PreviousPage 330 of 375Next