The article discusses a critical vulnerability in React, identified as CVE-2025-55182, which affects only instances utilizing a newer feature. The researcher warns that exploitation of this vulnerability is expected in the wild, emphasizing the urgency for affected users to take action.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Infosecurity Magazine
The Information Commissioner’s Office has opted to reprimand the Post Office following a significant data breach in 2024, which involved sensitive information related to postmasters. This decision to forgo a £1 million fine raises concerns about accountability and the protection of personal data in the organization.
The Hacker News
GoldFactory, a financially motivated cybercriminal group, has launched new attacks targeting mobile users in Southeast Asia, specifically Indonesia, Thailand, and Vietnam. They are distributing modified banking applications that serve as conduits for Android malware, leading to over 11,000 infections since October 2024, posing significant risks to users' financial security.
Cloudflare successfully mitigated a record-breaking 29.7 Tbps DDoS attack originating from the AISURU botnet, lasting for 69 seconds. The attack marks a significant escalation in the scale of DDoS threats, highlighting the ongoing challenges faced by cybersecurity firms in protecting against such massive assaults.
The article discusses a new partnership between the Center for Internet Security, Astrix Security, and Cequence Security to create cybersecurity guidance specifically for AI and agentic systems. This initiative aims to address the unique risks posed by autonomous decision-making and automated threats in AI environments, building on the existing CIS Critical Security Controls.
The article discusses the cybersecurity challenges posed by the modernization of decentralized smart grids, emphasizing the need for utilities to rethink their security strategies in light of new threats. Sonia Kumar highlights the importance of integrating security measures across all layers, from edge devices to cloud systems, to address the evolving risks associated with smart grid technologies.
The Hacker News
Cloudflare has reported the largest DDoS attack ever recorded, reaching 29.7 Tbps, attributed to the AISURU botnet, which has been linked to multiple significant attacks over the past year. This incident underscores the growing threat posed by botnets and the need for robust cybersecurity measures to mitigate such high-volume attacks.
The article discusses indirect prompt injection attacks as a significant cybersecurity threat to AI systems, highlighting how these attacks can manipulate AI outputs by exploiting the interaction between users and AI models. The severity lies in the potential for these attacks to undermine the reliability and integrity of AI applications across various sectors.
The Arizona Attorney General has filed a lawsuit against the Chinese retailer Temu, alleging that its app unlawfully accesses and collects users' sensitive information without their consent. This raises significant concerns about user privacy and data security, highlighting the potential risks associated with mobile applications that handle personal data.
SCM feed for Latest
Palo Alto Networks has launched a free digital literacy toolkit in collaboration with Cyberlite to help educators teach students about AI-driven threats. This initiative aims to combat the rising use of artificial intelligence by cybercriminals, emphasizing the importance of digital literacy in recognizing and resisting such threats.
The U.S. Senate hearing has highlighted a significant political divide regarding the response to China's Salt Typhoon cyber intrusions, which have compromised major telecommunications networks. This ongoing campaign raises concerns about national security and the integrity of critical infrastructure.
The article discusses a cybersecurity campaign by MuddyWater that targeted various sectors in Israel using a new backdoor known as MuddyViper. The attack, which occurred between September 30, 2024, and March 18, 2025, poses significant risks to critical infrastructure and organizations in engineering, government, and technology sectors.
A critical flaw in the widely used React code library has been identified, affecting approximately 39% of cloud environments. Developers are urgently addressing this vulnerability to protect major applications from potential exploitation.
Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Cybersecurity researchers have identified a serious attack involving a fake ChatGPT Atlas browser, which is being used in ClickFix attacks to steal user passwords. This highlights the increasing threat posed by such malicious tactics in the cybersecurity landscape.
A new wave of spear-phishing attacks has been identified, attributed to the Russia-based hacking group Star Blizzard. This threat poses significant risks to organizations, particularly targeting the French NGO Reporters Without Borders, highlighting the ongoing cybersecurity challenges faced by non-profits and media organizations.