Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

The U.S. Senate is set to discuss a series of bills aimed at enhancing online safety for children, with a focus on the Kids Online Safety Act. This legislation seeks to establish stricter guidelines on how minors interact with the internet, aiming to protect them from potential dangers associated with online platforms. The proposed measures come in response to growing concerns about children's safety in the digital age, especially regarding privacy and exposure to harmful content. If passed, these bills could significantly reshape how tech companies operate with respect to young users, making it crucial for parents, educators, and industry stakeholders to stay informed about these developments. The outcome of this debate will have lasting implications for online privacy and safety standards for minors.

Read Original
CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access

Security Affairs

A serious vulnerability in cPanel, tracked as CVE-2026-58048, has been discovered, allowing authenticated users to execute SQL commands with root privileges. This flaw, which has a CVSS score of 9.4, poses a significant risk to shared hosting environments where multiple users have access. Essentially, if you're running a shared hosting box, this bug could enable an ordinary user to gain full database administrator access, potentially compromising sensitive data. cPanel has issued patches to address this issue, and users are strongly advised to update their systems immediately to prevent exploitation. Given the nature of shared hosting, the implications of this vulnerability could be far-reaching, affecting not just individual sites but the entire server.

Read Original

A recent analysis highlights how attackers are exploiting cloud services to bypass multi-factor authentication (MFA) using a technique called Account in the Middle (AitM). This involves leveraging service workers and platforms like Ultraviolet to host phishing sites on legitimate cloud infrastructure, making them harder to detect. Major platforms identified include Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS, which are being misused to create convincing phishing pages. This tactic poses a significant risk to users who might unknowingly provide their credentials, as it undermines the security measures intended to protect them. Companies utilizing these services should be aware of this vulnerability and take steps to secure their users against such phishing schemes.

Read Original

Researchers from Forescout have identified 15 vulnerabilities within the TP-Link Omada networking ecosystem. These weaknesses could potentially allow attackers to take complete control of affected networks. The Omada platform is widely used in enterprise environments for managing network devices, making this discovery particularly concerning for businesses relying on these tools. The vulnerabilities stem from the Zero Touch Provisioning (ZTP) feature, which, if exploited, could enable unauthorized access and manipulation of network settings. Companies using TP-Link Omada devices should prioritize patching these vulnerabilities to protect their networks from potential attacks.

Read Original

A serious vulnerability has been identified in several Thermo Fisher Applied Biosystems Genetic Analyzers, which could allow attackers to tamper with DNA data by modifying output files. This flaw affects multiple versions of their software, including the 3500 Series, 3730 Series, SeqStudio, and GeneMapper ID-X, among others. The risk is significant because altered DNA test results could lead to incorrect diagnoses and treatments in healthcare settings. To mitigate the issue, Thermo Fisher has released security updates that implement digital signatures to ensure data integrity. Users are advised to update their software to the latest versions as soon as possible and to follow interim measures to secure their data until the updates can be applied.

Read Original
Critical
Acrisure KARR BT and DR-100

All CISA Advisories

Acrisure's KARR BT and DR-100 vehicle security systems have a serious vulnerability that could allow attackers to control vehicles remotely. The issue stems from a hard-coded Bluetooth authentication key shared among affected devices, which could let someone within range unlock doors or disable the engine. This affects all KARR BT firmware versions before July 20, 2026, and DR-100 firmware versions before the same date. While no public exploitation of this vulnerability has been reported yet, users are urged to update their devices to mitigate the risk. A firmware update has been released on July 20, 2026, to address this flaw, and users can find detailed instructions for the update on the KARR Security website.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, signaling active exploitation. The vulnerabilities include a code injection issue in IBM Langflow (CVE-2026-9198), an authentication bypass in N-able N-central (CVE-2026-18556), and a lack of encryption for sensitive data in Apache Tomcat (CVE-2026-34486). These vulnerabilities are significant threats to federal agencies and other organizations, as they can allow attackers to gain control over affected systems. CISA's Binding Operational Directive 26-04 emphasizes the need for rapid remediation of these high-risk vulnerabilities, urging federal agencies to act promptly. While the directive specifically targets federal agencies, CISA encourages all organizations to prioritize addressing these vulnerabilities to enhance their security posture.

Read Original

Ollie Whitehouse, the Chief Technology Officer at the National Cyber Security Centre (NCSC), recently addressed concerns surrounding security issues linked to frontier AI evaluations. His statement comes after a series of incidents that raised alarms about the safety of AI systems and their potential misuse. The NCSC is emphasizing the need for robust safety measures and regulatory frameworks to ensure that AI technologies are developed and deployed responsibly. This is particularly important as AI becomes more integrated into various sectors, potentially affecting everything from personal data privacy to national security. The agency is calling for collaboration between governments, researchers, and industry leaders to mitigate risks associated with advanced AI development.

Read Original
Actively Exploited

Recent research indicates that cloud and Software as a Service (SaaS) platforms have become prime targets for cyber attackers. As more companies shift their operations to these environments, threat actors are increasingly exploiting vulnerabilities related to identity management. This trend raises significant concerns for businesses and users, as it exposes sensitive data to breaches and unauthorized access. Companies need to enhance their security protocols and remain vigilant against identity-based attacks, which are on the rise. Failing to do so could lead to severe financial and reputational damage.

Read Original

Recent discussions in the cybersecurity field are shifting the focus from traditional assessments of attacker sophistication to a new threat: 'vibe hacking.' This term describes how artificial intelligence (AI) is being used by less experienced attackers, allowing them to execute sophisticated attacks without extensive technical knowledge. As AI tools become more accessible, even those labeled as 'script kiddies' can leverage these technologies to enhance their hacking capabilities. This evolution in the threat landscape could make it harder for security teams to predict and counteract attacks, as the barrier to entry for launching effective cyberattacks continues to drop. Businesses and organizations need to adapt their security strategies to account for this new wave of AI-enabled threats, which could lead to more frequent and varied attacks.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a significant vulnerability, tracked as CVE-2026-18577, to its Known Exploited Vulnerabilities catalog. This flaw affects N-able N-central, a platform used for IT management and monitoring. With a CVSS score of 8.2, the vulnerability allows attackers to bypass authentication, potentially granting them unauthorized access to sensitive systems. Organizations using N-able N-central should be particularly vigilant as this vulnerability poses a serious risk to their operations and data security. It's crucial for affected users to take immediate action to mitigate any potential exploitation.

Read Original

cPanel has addressed a serious vulnerability that allowed authenticated users to execute SQL commands with root database privileges. This flaw, tracked as CVE-2026-58048 and rated 9.4 on the CVSS scale, breaks the security boundary between individual cPanel accounts and the server's administrative database identity. The issue was fixed in a recent security update, which also addressed two other privilege escalation paths. Hosting customers who use cPanel should be aware of this vulnerability, as it could have allowed unauthorized access to sensitive data or manipulation of critical database functions. It's crucial for users to ensure they are using the latest version of cPanel to mitigate any potential risks associated with this flaw.

Read Original

Interpol has reported a significant rise in cybercrime across Africa, attributing this surge to the use of artificial intelligence by attackers. The agency noted that the financial losses related to these crimes have doubled, indicating a troubling trend in the region. This increase in cybercriminal activity is particularly concerning for businesses and individuals, who may face heightened risks from sophisticated AI-driven attacks. The implications are serious, as greater reliance on technology can expose vulnerabilities and lead to more severe consequences for victims. As cybercriminals harness AI capabilities, law enforcement and cybersecurity professionals will need to adapt their strategies to counter these evolving threats.

Read Original

A long-standing vulnerability in Baseboard Management Controllers (BMC) has been discovered, exposing over 24,000 server-management interfaces to potential attacks. This flaw allows unauthorized users to access sensitive authentication hashes before login, significantly increasing the risk of a breach. Data centers that utilize these interfaces, which are common in many server setups, are particularly vulnerable. This situation raises serious concerns about the security of critical infrastructure, as attackers could exploit these weaknesses to gain control over systems. Organizations need to assess their BMC configurations and take immediate action to protect their data centers from possible exploitation.

Read Original

Uptime Kuma, a self-hosted monitoring tool that checks the status of various services, has introduced a significant change in its latest version 2.5.0. This update implements a 14-day waiting period before the software trusts any new npm packages. This measure aims to enhance security by preventing the immediate adoption of potentially malicious or untested packages, which could compromise the integrity of the monitoring tool. With Uptime Kuma's popularity, having over 89,800 stars on GitHub, this change is particularly important as it may protect a large number of users from risks associated with newly published npm packages. By prioritizing caution, Uptime Kuma seeks to ensure a more secure experience for its users and their monitored services.

Read Original
PreviousPage 50 of 364Next