Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Critical
Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

The Shai-Hulud npm worm has resurfaced, infecting over 1,280 npm packages that collectively receive around 2 billion downloads each month. This malware is designed to steal sensitive credentials from various platforms, including npm, GitHub, cloud services, and continuous integration (CI) tools, in real-time. The worm spreads through Keyv and other related packages, posing a significant risk to developers and organizations that rely on these tools for their software development processes. With the potential for widespread credential theft, users need to be vigilant and consider enhancing their security measures to protect their accounts. The incident serves as a reminder of the vulnerabilities that can arise within popular development ecosystems.

Read Original

Five Democratic senators have expressed their concerns over the Trump administration's approach to managing artificial intelligence (AI) security risks. They argue that the administration has been inconsistent, sometimes too passive and at other times overreaching, which they believe has created an environment where China could gain an advantage in AI development. The senators are urging for a more balanced and proactive strategy to address the growing security challenges posed by AI technologies. This situation is critical as AI continues to evolve rapidly, impacting various sectors, including defense and cybersecurity. The senators' critique highlights the need for a clear and effective policy to mitigate potential risks associated with AI advancements.

Read Original

The phishing-as-a-service toolkit known as Greatness has added a new feature that allows attackers to use device code phishing to bypass Multi-Factor Authentication (MFA). This technique exploits the OAuth 2.0 Device Authorization Grant, a legitimate protocol, to gain unauthorized access to user accounts. By doing so, attackers can steal authentication tokens and control user accounts without needing to compromise passwords directly. This development is concerning as it poses risks to a wide range of applications and services that rely on MFA for security, making it easier for cybercriminals to execute their plans. Organizations and users must be vigilant and update their security practices to mitigate the risks associated with this evolving threat.

Read Original
Actively Exploited

A recent supply chain attack known as Keyv has affected over 400 npm packages, potentially putting numerous developers and projects at risk. This attack is believed to be linked to a group or technique referred to as Mini Shai-Hulud. The compromised packages could allow attackers to inject malicious code into applications that rely on these libraries, creating vulnerabilities that could be exploited in various ways. As npm is a widely used package manager in the JavaScript ecosystem, the scale of this attack raises significant concerns for developers and companies that depend on these packages for their applications. The incident underscores the ongoing challenges in securing software supply chains and the need for vigilance among developers to ensure their dependencies are safe.

Read Original

The article discusses the risks associated with overprivileged AI agents in organizations. It points out that when these AI systems have more access than necessary, they can lead to significant security incidents. Researchers emphasize the importance of implementing a 'least privilege' approach, which restricts AI agents to only the permissions they need to function. This strategy, combined with a unified identity management system, can help minimize risks. The article serves as a warning for companies to reassess their AI security protocols to prevent potential breaches or misuse of sensitive information.

Read Original

A new self-propagating malware called 'ChainDrop' has infected over 1,300 packages in the Node Package Manager (npm) registry, which collectively see around 2 billion downloads each month. This attack allows the malware to spread rapidly across various software projects that rely on npm packages. Developers and companies using these compromised packages are at risk of introducing vulnerabilities into their applications. The incident raises significant concerns about supply chain security, as it demonstrates how a single attack can impact a vast number of users and systems. Those affected should take immediate steps to identify and remove the compromised packages from their projects to mitigate potential damage.

Read Original

The INC ransomware group has been linked to recent attacks exploiting zero-day vulnerabilities in SonicWall products. While they weren't the first to take advantage of these flaws, their aggressive tactics in combining both vulnerabilities have made them particularly effective at stealing and encrypting sensitive data for ransom. This situation poses a significant risk for organizations using affected SonicWall devices, as it can lead to severe data breaches and financial losses. Users and companies relying on SonicWall's security products need to be vigilant and implement necessary precautions to protect their systems. The ongoing threat from INC highlights the importance of timely updates and monitoring for unusual activity in network environments.

Read Original
Actively Exploited

A recent WhatsApp scam has exploited the app's Linked Devices feature to take control of user accounts without needing to steal passwords. This method allows attackers to gain access to someone's WhatsApp by tricking them into providing a verification code. Victims are often misled into thinking they are verifying their own devices, making it easier for scammers to hijack accounts. This incident raises significant concerns about the security of user accounts on popular messaging platforms, especially as more people rely on these apps for personal and professional communication. Users should be cautious and verify any unexpected requests for verification codes to protect their accounts.

Read Original

Researchers have found that built-in email chatbots could be weaponized by attackers to impersonate trusted employees, potentially leading to account hijacking and financial fraud. These AI assistants, often designed to make email communication more efficient, can be exploited to bypass security measures and compromise executive accounts. This poses a significant risk to organizations, as attackers could manipulate these tools to send deceptive messages that appear legitimate to recipients. The implications are serious, as companies may face not only financial losses but also damage to their reputations. Users and organizations need to be aware of these vulnerabilities and take steps to secure their email systems against such tactics.

Read Original

The INC Ransomware group is actively exploiting vulnerabilities in SonicWall's Secure Mobile Access (SMA) 1000 series devices. This campaign has been marked by aggressive tactics, including phone calls and emails aimed at pressuring victims into paying ransoms. Resecurity researchers have identified this group as the primary threat actor taking advantage of these recently disclosed flaws. Organizations worldwide that utilize SonicWall products may be at risk, as the group has ramped up its operations in response to these vulnerabilities. It’s crucial for companies to assess their security measures and consider immediate actions to prevent potential breaches and data loss.

Read Original

A credential-stealing worm linked to the npm package 'keyv' has spread to hundreds of packages since it was first identified on August 4, 2026. This malware has affected at least 868 packages according to Aikido, with SafeDep confirming 353 poisoned versions across 79 package names in the npm registry. The worm is designed to steal user credentials and has also incorporated hooks for the Claude code and Visual Studio Code environments. This incident raises serious concerns for developers and organizations using these packages, as compromised libraries can lead to significant security breaches and data loss. Users are urged to audit their dependencies and ensure they are using safe versions of affected packages.

Read Original

Researchers from Talos have discovered that cybercriminals are finding ways to bypass AI safety controls by splitting malicious activities across multiple sessions. They found that the AI's guardrails, designed to prevent harmful actions, fail when attackers claim ownership of the tasks. This technique allows them to evade detection and continue their malicious activities without triggering security alerts. The implications are significant, as it shows that existing safety measures can be manipulated, potentially leading to increased risks for organizations relying on AI for security. Companies need to reassess their AI systems and strengthen their defenses against such tactics.

Read Original

The U.S. Senate is set to discuss a series of bills aimed at enhancing online safety for children, with a focus on the Kids Online Safety Act. This legislation seeks to establish stricter guidelines on how minors interact with the internet, aiming to protect them from potential dangers associated with online platforms. The proposed measures come in response to growing concerns about children's safety in the digital age, especially regarding privacy and exposure to harmful content. If passed, these bills could significantly reshape how tech companies operate with respect to young users, making it crucial for parents, educators, and industry stakeholders to stay informed about these developments. The outcome of this debate will have lasting implications for online privacy and safety standards for minors.

Read Original
CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access

Security Affairs

A serious vulnerability in cPanel, tracked as CVE-2026-58048, has been discovered, allowing authenticated users to execute SQL commands with root privileges. This flaw, which has a CVSS score of 9.4, poses a significant risk to shared hosting environments where multiple users have access. Essentially, if you're running a shared hosting box, this bug could enable an ordinary user to gain full database administrator access, potentially compromising sensitive data. cPanel has issued patches to address this issue, and users are strongly advised to update their systems immediately to prevent exploitation. Given the nature of shared hosting, the implications of this vulnerability could be far-reaching, affecting not just individual sites but the entire server.

Read Original

A recent analysis highlights how attackers are exploiting cloud services to bypass multi-factor authentication (MFA) using a technique called Account in the Middle (AitM). This involves leveraging service workers and platforms like Ultraviolet to host phishing sites on legitimate cloud infrastructure, making them harder to detect. Major platforms identified include Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS, which are being misused to create convincing phishing pages. This tactic poses a significant risk to users who might unknowingly provide their credentials, as it undermines the security measures intended to protect them. Companies utilizing these services should be aware of this vulnerability and take steps to secure their users against such phishing schemes.

Read Original
PreviousPage 49 of 364Next