Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Critical
Zenitel TCIV-3+

All CISA Advisories

The Zenitel TCIV-3+ device has critical vulnerabilities, including OS Command Injection and Cross-site Scripting, with a CVSS v4 score of 10.0, indicating a severe risk of arbitrary code execution and denial-of-service. Users are strongly advised to upgrade to version 9.3.3.0 or later to mitigate these risks.

Read Original
Critical
Rockwell Automation Arena Simulation

All CISA Advisories

Rockwell Automation's Arena Simulation software has a stack-based buffer overflow vulnerability that could allow local attackers to execute arbitrary code. The vulnerability, identified as CVE-2025-11918, has a CVSS v4 score of 7.1, indicating a significant risk for affected installations, particularly in critical manufacturing sectors.

Read Original

ToddyCat, a threat actor, has developed a new tool called TCSectorCopy to steal Outlook emails and Microsoft 365 access tokens by exploiting the OAuth 2.0 authorization protocol through users' browsers. This poses a significant threat to corporate email security, as it allows unauthorized access to sensitive information outside the compromised infrastructure.

Read Original

The article highlights the imminent shift in cybersecurity as threat actors increasingly leverage AI for attacks by 2026, posing significant risks to security teams. This evolution in tactics necessitates urgent adaptations in security strategies to combat the sophisticated use of AI in cyber threats.

Read Original

The article highlights a significant increase in fraud driven by AI and deepfake technologies, indicating a shift in the sophistication of identity fraud tactics. Despite a stagnation in overall identity fraud rates, the rise of these advanced methods poses serious challenges for cybersecurity efforts and requires heightened awareness and adaptive strategies from organizations.

Read Original

Cybersecurity researchers have identified a campaign that exploits Blender Foundation files to distribute StealC V2, a data-stealing malware. This operation has been ongoing for at least six months, posing significant risks to users who download infected .blend files from platforms like CGTrader.

Read Original
Actively Exploited

CISA has issued a warning regarding the use of commercial spyware and remote access trojans (RATs) targeting users of popular messaging apps like WhatsApp and Signal. This threat highlights the increasing risk to user privacy and security in mobile communications, necessitating heightened vigilance and protective measures.

Read Original
Actively Exploited

The new Shai-Hulud worm has infected numerous npm packages, significantly disrupting continuous integration and continuous deployment (CI/CD) workflows globally. This incident poses a serious threat to developers and organizations relying on npm for their software development processes.

Read Original
Actively Exploited

Canon has reported that one of its subsidiaries has been affected by the Oracle EBS hack, which has resulted in over 100 alleged victims being listed on the Cl0p ransomware website. This incident highlights the significant impact of the Oracle EBS campaign and raises concerns about the security of affected organizations.

Read Original

The Shai-Hulud worm has emerged as a significant cybersecurity threat, infecting nearly 500 open-source packages and compromising over 26,000 GitHub repositories within a 24-hour period. This incident highlights the increasing automation and strength of self-replicating malware, raising concerns about the security of open-source software ecosystems.

Read Original
Actively Exploited

The ShadowRay 2.0 threat actor is exploiting a vulnerability in the Ray framework to commandeer AI infrastructure globally, creating a self-propagating botnet for cryptomining and data theft. This poses a significant risk to AI systems and could lead to extensive data breaches and financial losses.

Read Original

The article highlights the exploitation of CVE-2025-61757, which follows a breach of Oracle Cloud and an extortion campaign targeting Oracle E-Business Suite customers. This indicates a significant security threat that could impact numerous organizations relying on Oracle's services.

Read Original
PreviousPage 369 of 375Next