A recently exposed database belonging to SISVISA, Brazil's Health Surveillance Information System, has leaked over 102,000 health records. Researcher Jeremiah Fowler discovered the database, which contained sensitive information such as identification numbers, tax data, and regulatory documents, all accessible without any authentication. This incident raises serious concerns about the security of personal health information and the potential for identity theft or fraud. The exposed records could affect individuals who rely on Brazil's health services, highlighting the need for better data protection practices. The findings were shared with ExpressVPN, who then reported them to Hackread for further dissemination.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
The Hacker News
This week’s cybersecurity incidents reveal various vulnerabilities and attack vectors that could be exploited by malicious actors. Researchers have identified issues that allow remote code execution (RCE) and one-click takeovers, particularly affecting software configurations that are too trusting by default. For instance, a seemingly harmless PDF file can execute harmful actions without user consent, and exposed servers continue to be a primary target for attackers. This situation underscores the need for organizations to tighten their security measures and for users to be vigilant about the software they interact with. These threats are not just theoretical; they pose real risks to users and organizations alike, emphasizing the importance of regular updates and monitoring for unusual activity.
SecurityWeek
Connor Riley Moucka, a hacker linked to the Snowflake cyber incident, has pleaded guilty in a U.S. court. Moucka was extradited from Canada in July 2025 after being arrested on charges related to his involvement in a significant data breach. The Snowflake hack raised concerns over the security of sensitive information stored by companies using the Snowflake platform, which is widely used for data warehousing and analytics. His guilty plea underscores the ongoing challenges organizations face in protecting their data from cybercriminals. The outcome of this case may serve as a warning to others involved in similar activities, highlighting the legal consequences of cybercrime.
Oligo Security has traced TeamPCP back to a cryptojacking operation that has been active since 2020. This group has been linked to the ShadowRay 2.0 malware, which is designed to hijack computing resources for cryptocurrency mining without the owner's consent. The researchers' findings indicate that the infrastructure used by TeamPCP has been operating for several years, raising concerns about the long-term impact on affected systems. Users and organizations need to be vigilant, as cryptojacking can lead to degraded system performance and increased energy costs. Understanding the history and tactics of such groups is crucial for improving defenses against these types of cyber threats.
A new mobile ad fraud scheme known as Papyrus has been discovered, involving several novel-reading apps that operate on users' phones without their knowledge. According to researchers from IAS Threat Lab, while users are engrossed in reading stories, the apps are secretly loading and interacting with websites in a hidden browser window. This means that the apps generate fake ad traffic, which can mislead advertisers and inflate ad revenue for the fraudsters behind this scheme. This issue not only affects users' devices by consuming resources but also raises concerns about the integrity of online advertising. Users of these specific novel-reading apps should be aware of the potential for such hidden activities and consider their app choices carefully.
A recent analysis by Skyhigh Security reveals that artificial intelligence has brought attention to existing security vulnerabilities in web browsers, rather than creating new ones. As organizations increasingly rely on browsers for data management and AI interactions, these vulnerabilities pose significant risks. Browsers are now seen as essential points for controlling data flow, which means any weaknesses can lead to data leaks or breaches. Companies need to reassess their browser security measures to protect sensitive information, especially as remote work continues to be prevalent. This situation underscores the importance of proactive security practices in the face of evolving technology.
Researchers at Zenity have identified a serious vulnerability affecting AI browser applications, specifically Anthropic's Claude and OpenAI's ChatGPT Atlas. This issue allows attackers to hijack these platforms through seemingly harmless emails and posts on social media, particularly X (formerly Twitter). Despite reporting their findings to the companies involved in late 2025 and early 2026, the vulnerabilities remain unpatched, putting users at risk. This situation raises concerns about the security of AI tools that many people rely on for various tasks. Users of these applications should be cautious and stay informed about potential exploits until a fix is implemented.
A recent study by 1Password has revealed that artificial intelligence tools are failing to effectively patch software vulnerabilities 74% of the time. This raises concerns for organizations relying on AI to enhance their cybersecurity measures. The research suggests that while AI can assist in identifying flaws, it often struggles to implement effective fixes. This shortfall could leave systems vulnerable to attacks, as timely and accurate patching is crucial for maintaining security. Companies should critically evaluate their reliance on AI for patch management and consider maintaining human oversight to ensure proper security measures are in place.
A recent study by researchers at 1Password reveals that about 75% of AI-generated patches for real vulnerabilities fail to provide a complete fix. The researchers evaluated 6,080 patches for six newly disclosed Common Vulnerabilities and Exposures (CVEs). While the AI-generated patches often resemble human-written fixes and can pass tests, they frequently leave unaddressed issues that could still be exploited. This finding raises concerns about the reliability of AI in cybersecurity, particularly as organizations increasingly rely on automated solutions to address vulnerabilities. The study suggests that companies should exercise caution when implementing AI-generated fixes and ensure thorough manual reviews before deployment.
Forescout has identified a significant number of Rockwell Automation programmable logic controllers (PLCs) that are exposed to the internet, with a total of 4,407 found globally. Among these, 2,844 are located in the United States, including 22 in cities that have recently experienced cyberattacks on water utilities. Notably, 19 of these controllers are using the same mobile carrier network. While Forescout's scan raised concerns about the potential risks, they could not confirm any instances of these devices being compromised. This situation is alarming as it highlights the vulnerabilities in critical infrastructure, particularly in areas that have already been targeted by cyber threats, raising questions about the security measures in place to protect essential services.
In 2026, a surge in violent physical thefts of cryptocurrency, referred to as 'wrench attacks', has led to losses totaling $30 million, according to Chainalysis. These attacks typically involve assailants using physical force to steal hardware wallets or other devices that store digital currency. Victims include individuals and businesses that rely on these wallets for securing their crypto assets. The rise in these incidents raises concerns about personal safety and the security measures people need to take when handling cryptocurrencies. As attackers become more brazen, it is crucial for users to be aware of these threats and consider additional security strategies to protect their assets.
A vulnerability has been discovered in Medixant's RadiAnt DICOM software that could allow attackers to exploit specially crafted DICOM files. Versions 2025.2 and earlier of the software are affected, which could lead to application crashes or even remote code execution due to an out-of-bounds write triggered by malicious JPEG-compressed pixel data. Users are advised to upgrade to version 2026.1 to mitigate this risk. The vulnerability is particularly concerning for healthcare and public health sectors worldwide, as it could compromise patient data and system integrity. While there are currently no reports of this vulnerability being actively exploited, users should remain cautious and only open DICOM files from trusted sources.
A recently discovered vulnerability in Johnson Controls Inc.'s TL280 device could allow attackers to access sensitive information. Specifically, versions of the TL280 prior to 5.63 are impacted due to the use of hardcoded credentials in the device's firmware. This presents a significant risk, particularly for sectors such as critical manufacturing, government services, and energy. To mitigate the threat, Johnson Controls recommends updating to firmware version 5.63 and implementing several network security measures, such as restricting access to trusted VLANs and monitoring device access logs for unusual activity. Although no active exploitation of this vulnerability has been reported, organizations should take proactive steps to protect their systems.
ABB Ability Zenon is facing significant vulnerabilities that could allow attackers to bypass security measures, crash systems, and compromise data. The issues primarily affect the IIoT services bundled with MongoDB version 4.2 across all versions of ABB Ability Zenon. Notably, vulnerabilities such as improper handling of length parameters and exploitation of uninitialized memory could lead to unauthorized actions. ABB has recommended urgent remediation steps, including replacing the bundled MongoDB with a supported version and uninstalling IIoT services if they are not needed. Given that these vulnerabilities impact critical infrastructure sectors like energy and healthcare, organizations using ABB Ability Zenon must act quickly to secure their systems.
A recent survey revealed that 75% of European businesses are concerned about their reliance on a few major technology providers, fearing they could be abruptly cut off from critical services. This dependency poses a significant risk, as it could leave companies vulnerable to disruptions in their operations. The article suggests that American businesses should be equally cautious, as the interconnectedness of the tech industry means that a 'kill switch' could impact them as well. The potential for a sudden loss of access to essential technology raises alarms about business continuity and the need for diversified tech partnerships. Companies are urged to reassess their vendor relationships to mitigate these risks.