Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Actively Exploited

Gen's H1 2026 Threat Report reveals two distinct attack chains targeting businesses. The first attack involved hackers gaining access to business email accounts and manipulating web browsers to install banking malware, which could lead to unauthorized access to financial information. The second attack utilized clipboard hijacking techniques to redirect cryptocurrency payments, potentially siphoning funds from unsuspecting users. These tactics not only compromise sensitive financial data but also undermine trust in online transactions. Businesses and individuals who handle financial information or cryptocurrency should be particularly vigilant against these types of attacks, as they can result in significant financial losses.

Read Original

The North Carolina Ports Authority has confirmed that a cyberattack has disrupted IT systems, causing slowdowns at several key facilities, including the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. This incident has raised concerns about the security of critical infrastructure, as ports play a vital role in trade and logistics. The attack has affected operations significantly, although specific details about the nature of the attack and the extent of the disruption have not been disclosed. As ports are crucial for the economy, such incidents can lead to delays in shipping and increased costs for businesses relying on timely deliveries. Authorities are likely working to restore normal operations while assessing the full impact of the attack.

Read Original
Critical
The Good, the Bad and the Ugly in Cybersecurity – Week 32

Cybersecurity Blog | SentinelOne

Actively Exploited

A hacker has pleaded guilty to their role in a massive data breach involving Snowflake, which compromised around 100 million records. This incident raises concerns about data security and user privacy, as the breach potentially exposes sensitive information belonging to millions of individuals. In another incident, a group called Mythos 5 spent over 34 hours attempting to inject a backdoor into legitimate software code, which could have led to further exploitation if successful. Additionally, a new worm named ChainDrop is spreading through npm, a popular package manager for JavaScript, posing risks to developers who use the platform. These events highlight ongoing vulnerabilities in software supply chains and the need for heightened security measures in the tech industry.

Read Original

WordPress has addressed a serious vulnerability in its login screen that affects all versions of the platform. This flaw, known as CVE-2026-64638 and rated with a CVSS score of 8.9, allows for pre-authentication reflected cross-site scripting (XSS). Researchers from pwn.ai have demonstrated that this vulnerability could potentially be exploited to execute PHP code on the server, particularly if an administrator interacts with a malicious page. As this issue impacts every WordPress installation, users and website administrators are strongly encouraged to apply the patch immediately to secure their sites and prevent potential exploitation.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability, identified as CVE-2026-8037, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects the Progress LoadMaster and allows for command injection, which can grant attackers total control over the affected system. CISA emphasizes that federal agencies must prioritize the rapid remediation of such high-risk vulnerabilities, especially those that are actively exploited. While this directive specifically targets Federal Civilian Executive Branch agencies, CISA encourages all organizations to adopt similar risk-based approaches to managing vulnerabilities. Organizations aware of other exploited vulnerabilities not listed in the KEV Catalog can submit them for consideration through CISA's nomination process.

Read Original
Critical
CPDLC over ATN-B1 Vulnerabilities

All CISA Advisories

Recent research has identified several vulnerabilities in the Controller-Pilot Data Link Communications (CPDLC) system that operates over the Aeronautical Telecommunications Network (ATN-B1). These vulnerabilities stem from the use of legacy, unauthenticated radio frequency links, which could allow attackers to inject unauthorized messages, disrupt communications, and reset sessions. Although these issues do not directly compromise aircraft safety, they could create confusion and increase the workload for pilots and air traffic controllers, potentially impacting operational safety. The vulnerabilities affect all versions of CPDLC over ATN-B1, with several specific CVEs (CVE-2025-71409 to CVE-2025-71413) documented. Currently, there are no available mitigations or patches for these vulnerabilities, and while they can be exploited in laboratory settings, there have been no reports of active exploitation in the wild.

Read Original

A long-standing vulnerability in the Linux SCTP networking code, present since 2008, has been discovered to allow local users to gain root access on the host system. Tencent researchers demonstrated that this use-after-free bug could enable an attacker to escape from a container and access the underlying machine. This issue affects users running older Linux kernels that have SCTP enabled. Fortunately, patches have been released for multiple stable kernel versions, including 7.1.6 and 6.6.148, as of August 3. It's crucial for anyone using affected kernels to update promptly to prevent potential exploitation.

Read Original

A vishing extortion group known as UNC6671 has rebranded several times, initially operating under the name BlackFile. The group has expanded its operations by adopting new names including Redact, Pink, Helix, and Falcon, reportedly making millions through their schemes. Vishing, or voice phishing, involves using phone calls to trick individuals into revealing sensitive information or transferring money. This group's activities raise concerns for both individuals and businesses, as they can lead to significant financial losses and a breach of personal data. The ongoing evolution of this group’s branding suggests they are attempting to evade detection while continuing their extortion efforts.

Read Original

Beacon, a customer relationship management provider for charities, has reported a significant security incident affecting around 1,500 of its client organizations. Unauthorized individuals accessed and likely exfiltrated data from Beacon's CRM databases. This breach puts sensitive information at risk, which could include personal details of charity beneficiaries and staff. Since these charities often handle vulnerable populations, the implications of this breach could be severe, leading to potential identity theft or fraud. Beacon's clients now face the challenge of assessing the impact of this incident and communicating with their stakeholders about the breach.

Read Original

U.S. Immigration and Customs Enforcement (ICE) is reportedly purchasing access to credit card records through data brokers. This means that personal information provided by individuals when they apply for credit cards can be accessed by ICE, raising significant privacy concerns. The data includes details like names, addresses, and transaction histories, which can be used for tracking individuals. This practice affects anyone who has ever applied for a credit card, as their sensitive information may be exposed to government scrutiny without their consent. The implications of this access are serious, as it blurs the line between lawful enforcement and invasive surveillance.

Read Original

Researchers from VulnCheck have discovered a hidden backdoor in 20 router models, specifically those manufactured by Zbtlink, that allows remote servers to execute commands with root privileges. This backdoor poses a significant risk, as it could allow attackers to take control of affected devices without user consent or knowledge. The issue came to light when Jacob Baines noticed that his router was attempting to connect to an external server unexpectedly. This situation raises concerns for users of these routers, as their devices could be compromised, leading to potential data breaches or unauthorized access to home networks. Users are advised to check if their routers are among the affected models and take necessary precautions to secure their devices.

Read Original

A recent safety recall for the Bendix EC80 brake controller has turned out to be more than just a precaution; it also addresses serious security flaws. Researchers from the National Motor Freight Traffic Association (NMFTA) discovered that the recall not only targets safety issues but also fixes vulnerabilities that could allow remote code execution and denial of service (DoS) attacks. This is a significant concern for fleet operators and truck manufacturers, as these vulnerabilities could potentially be exploited by attackers, compromising the safety and functionality of vehicles. The recall highlights the importance of addressing cybersecurity threats in automotive systems, especially as vehicles become increasingly connected. Users of the Bendix EC80 brake controller are urged to take immediate action to ensure their systems are updated and secure.

Read Original
Critical
Ransomware Surges in July After Q2 Lull

Infosecurity Magazine

Actively Exploited

In July 2023, ransomware attacks surged significantly following a quieter second quarter. The finance, technology, and healthcare sectors were the primary targets, with attackers increasingly focusing on these industries due to their sensitive data and critical operations. Comparitech's analysis indicates that the uptick in incidents could pose serious risks to the affected organizations, potentially leading to data breaches and operational disruptions. Companies in these sectors should be particularly vigilant and enhance their cybersecurity measures to protect against these threats. The rise in ransomware activity underscores the ongoing challenges organizations face in safeguarding their systems from malicious actors.

Read Original

Unlimited Technology Systems experienced a significant data breach that has affected approximately 3.8 million individuals. Hackers accessed sensitive personal information, including medical records and health insurance details, from the company's data center. This incident raises concerns about the security of personal health information and the potential misuse of such data. Affected individuals may face risks related to identity theft and privacy violations, making it crucial for them to monitor their accounts closely. The breach also highlights the need for companies handling sensitive information to strengthen their cybersecurity measures to prevent similar attacks in the future.

Read Original
Actively Exploited

Scammers are using AI-generated deepfakes to impersonate popular OnlyFans creators, deceiving fans into sending money for promised live chats that never happen. This scheme targets social media platforms like TikTok, where these fake identities can easily attract followers. After collecting payments, the fraudsters disappear, leaving victims without any recourse. This incident is concerning as it not only exploits the trust of fans but also raises broader questions about the authenticity of online personas. As deepfake technology becomes more accessible, users need to be vigilant about whom they interact with online.

Read Original
PreviousPage 40 of 363Next