The U.S. Senate hearing has highlighted a significant political divide regarding the response to China's Salt Typhoon cyber intrusions, which have compromised major telecommunications networks. This ongoing campaign raises concerns about national security and the integrity of critical infrastructure.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
The article discusses a cybersecurity campaign by MuddyWater that targeted various sectors in Israel using a new backdoor known as MuddyViper. The attack, which occurred between September 30, 2024, and March 18, 2025, poses significant risks to critical infrastructure and organizations in engineering, government, and technology sectors.
A critical flaw in the widely used React code library has been identified, affecting approximately 39% of cloud environments. Developers are urgently addressing this vulnerability to protect major applications from potential exploitation.
Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Cybersecurity researchers have identified a serious attack involving a fake ChatGPT Atlas browser, which is being used in ClickFix attacks to steal user passwords. This highlights the increasing threat posed by such malicious tactics in the cybersecurity landscape.
A new wave of spear-phishing attacks has been identified, attributed to the Russia-based hacking group Star Blizzard. This threat poses significant risks to organizations, particularly targeting the French NGO Reporters Without Borders, highlighting the ongoing cybersecurity challenges faced by non-profits and media organizations.
Infosecurity Magazine
The UK's new cyber defense service has successfully thwarted nearly one billion early-stage cyber-attacks over the past year, according to British Security Minister. This initiative highlights the growing importance of proactive cybersecurity measures for telecommunications companies in protecting against emerging threats.
Yearn Finance's yETH pool experienced a significant security breach due to a critical vulnerability, resulting in the theft of approximately $9 million. This incident highlights the ongoing risks associated with decentralized finance platforms and the need for robust security measures.
SCM feed for Latest
Researchers have identified a potential cybersecurity threat where attackers could create and distribute a malicious Skill that can stealthily retrieve external scripts. This poses a significant risk as it could lead to unauthorized access and exploitation of systems using such Skills.
The Aisuru botnet has executed over 1,300 DDoS attacks in three months, with one attack reaching a staggering 29.7 terabits per second, setting a new record. This level of attack highlights the increasing capabilities of botnets and poses significant risks to online services and infrastructure.
The article discusses the increased risk of ransomware attacks targeting enterprises during off-hours, weekends, and holidays when security teams are less available. This trend highlights the vulnerability of organizations to cyber threats during periods of reduced staffing and response capabilities, emphasizing the need for continuous security measures and preparedness.
The article highlights a critical shortage in the U.S. cybersecurity workforce, driven by failures in education and retention. It calls for urgent reforms and increased collaboration between public and private sectors to ensure a robust pipeline of future cyber defenders.
Security Affairs
Researchers have uncovered a scheme involving the Lazarus APT group, linked to North Korea, utilizing remote IT workers to conduct cyber operations. This highlights the evolving tactics of cybercriminals and the ongoing threat posed by state-sponsored hacking groups. The investigation underscores the importance of vigilance in cybersecurity as these actors adapt to new methods of operation.
SCM feed for Latest
The article highlights the growing concern among security professionals as they face global threats and vulnerabilities without a clear national strategy from the federal government. This lack of guidance leaves local governments and private sector entities to navigate complex security challenges on their own, raising questions about the adequacy of current support systems. The implications suggest a potential increase in security incidents and vulnerabilities due to insufficient federal oversight.
Arizona has filed a lawsuit against Temu and its parent company PDD Holdings, alleging that the online retailer is involved in the theft of customer data. This legal action underscores growing concerns over data privacy and security in e-commerce, particularly regarding foreign companies operating in the U.S.
SCM feed for Latest
The article highlights significant gaps in Web Application Firewall (WAF) protection that leave parts of enterprise applications unprotected, posing a serious risk to application security. This inconsistency in security measures can lead to vulnerabilities being exploited, potentially compromising sensitive data and systems. Organizations must address these gaps to ensure comprehensive security coverage.