Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Actively Exploited

KT Corporation, South Korea's largest telecommunications company, has been hit with a hefty fine of $39 million due to a year-long security breach associated with compromised femtocells. Femtocells are small cellular base stations that help improve mobile service in homes and offices. The breach reportedly allowed attackers to exploit these devices, potentially affecting the security and privacy of users connected to them. The incident raises concerns about the vulnerability of telecommunications infrastructure and the need for stronger security measures in devices that are integral to everyday communication. As this breach comes to light, it serves as a reminder for telcos and users alike to prioritize security in their network devices.

Read Original

The Police National Legal Database (PNLD) has reported a data breach that resulted in sensitive contact information being leaked on the dark web. This incident, discovered on July 26, exposed names, organizations, and work email addresses of police officers, police staff, criminal justice professionals, government partners, and customers. The breach raises significant concerns about the privacy and security of individuals working within law enforcement and government, as their details could be misused for malicious purposes. The availability of this information on the dark web poses risks not only to the individuals directly affected but also to broader public safety and trust in these institutions. Authorities are likely to investigate the breach further and implement measures to prevent future incidents.

Read Original

Recent reports indicate that hackers with links to Iran have targeted water systems in several U.S. states, including Michigan, South Dakota, and Georgia, in addition to Minnesota. These attacks raise significant concerns about the security of critical infrastructure, as water systems play a vital role in public health and safety. The ongoing cyberattacks demonstrate a troubling trend where essential utilities are becoming attractive targets for foreign adversaries. Authorities are urging water system operators to enhance their cybersecurity measures to protect against these types of intrusions. The situation remains dynamic, and further details about the extent of the attacks are still emerging.

Read Original
Actively Exploited

A significant security breach has hit Coldcard Bitcoin wallet users, resulting in the theft of nearly $89 million. The attackers exploited a previously known vulnerability in the wallet's software, allowing them to drain funds from multiple accounts. This incident raises serious concerns about the security measures in place for cryptocurrency wallets, particularly those that rely on outdated code. Users of Coldcard wallets need to be vigilant and consider reviewing their security practices. The breach not only affects individual users but also sends a chilling message to the broader cryptocurrency community about the risks associated with digital asset storage.

Read Original

Thermo Fisher Scientific has addressed a significant vulnerability in its Applied Biosystems human identification software. The flaw, tracked as CVE-2026-17583, could allow unauthorized alterations to DNA data files (.fsa and .hid) before they are processed by analysis software, potentially making tampering nearly undetectable. This issue arises when laboratory controls are bypassed, posing risks to the integrity of DNA analysis results, which can have critical implications in forensic and clinical settings. The company issued a security bulletin on July 31, highlighting the urgency of applying the patch to prevent misuse. Users of the affected software need to ensure they have the latest updates to protect against this vulnerability.

Read Original

CrowdStrike reports that artificial intelligence (AI) is increasingly being used as both a tool for cyberattacks and a target for defense. The company noted that AI generates 2.5 times more signals than human-triggered actions, making it a significant area for analysis. Attackers are leveraging AI to exploit vulnerabilities more quickly than organizations can address them, raising concerns about the effectiveness of current cybersecurity measures. This trend poses a serious risk to businesses, as the rapid pace of AI-driven attacks can outstrip the ability of companies to patch their systems. Understanding this dynamic is crucial for organizations aiming to bolster their defenses against evolving threats.

Read Original

N-able reported that attackers exploited an authentication bypass vulnerability in its N-central platform, allowing unauthorized remote administrative access to customer systems. This issue, tracked as CVE-2026-18577, affects all N-central builds prior to version 2026.3.1.7. The initial fix released by N-able was incomplete, leading to successful exploitation of the flaw. The company released the first unaffected version on August 2, 2023, which highlights the critical need for users to ensure they are running the latest version to protect their systems. Organizations using N-central should take immediate action to update to version 2026.3.1.7 or later to mitigate the risk of these attacks.

Read Original

Hugging Face's Diffusers library has three serious security vulnerabilities that could let malicious model repositories run arbitrary code on users' machines. This situation arises from flaws that bypass the 'trust_remote_code' feature, which is supposed to prevent unreviewed code from executing. Researchers have indicated that these vulnerabilities pose a significant risk to the AI supply chain, potentially impacting developers and organizations that rely on this library for their AI applications. The ability to execute arbitrary code could lead to unauthorized access and various forms of exploitation, making it crucial for users to stay informed about these risks. Companies using Hugging Face's tools should assess their exposure and implement necessary precautions to protect their systems.

Read Original

Ruby on Rails has addressed a serious vulnerability in its Active Storage component, identified as CVE-2026-66066. This issue could allow unauthenticated attackers to read arbitrary files from servers running vulnerable applications, posing a significant risk of remote code execution. The vulnerability has a high severity rating, with a CVSS score of 9.5, meaning that it could be exploited easily if not patched. Applications that generate image variants are particularly at risk, as they may inadvertently expose sensitive files. Developers using Ruby on Rails should ensure they update their applications to mitigate this risk and protect sensitive data.

Read Original

CrowdStrike's 2026 Threat Hunting Report reveals that as artificial intelligence becomes more prevalent, the window of opportunity for attackers to exploit vulnerabilities is closing. Researchers have observed that the integration of AI tools in cybersecurity is helping companies detect and respond to threats more swiftly. This shift means that while cybercriminals are adapting their techniques, defenders are also enhancing their capabilities. The report emphasizes the need for businesses to stay updated on potential vulnerabilities and invest in AI-driven security measures to bolster their defenses. With the landscape of cyber threats evolving, organizations must prioritize proactive strategies to safeguard their data and systems.

Read Original

Buying followers, likes, or views on TikTok might seem like a quick way to boost online presence, but it comes with serious risks. According to Malwarebytes, services that sell social media engagement often engage in deceptive practices that can lead to scams, account theft, and financial loss. Users who purchase these services may unknowingly expose themselves to compromised accounts and other security issues. This situation not only affects the buyers but can also pose risks to other users on the platform. The allure of instant engagement masks the potential dangers lurking behind these services, making it crucial for users to be cautious about their online activities.

Read Original

CareCloud, a health tech company based in New Jersey, has revealed that a data breach has compromised the medical and financial information of 345,000 individuals. The breach occurred in systems hosted on Amazon Web Services (AWS) and involves patient records from over 45,000 healthcare providers across the United States. Although CareCloud first reported the breach back in March, they are now notifying those affected. This incident raises concerns about the security of sensitive health information and the potential risks for identity theft or fraud for the individuals involved. As data breaches become more common in the healthcare sector, it's crucial for companies to strengthen their security measures to protect patient data.

Read Original

The latest Malware newsletter from Security Affairs covers several significant developments in malware tactics. Notably, the DPRK's BlueNoroff group has upgraded its MaaS (Malware as a Service) ecosystem, introducing modular tools that enhance its capabilities. Additionally, a new threat called SourTrade has emerged, leveraging malvertising to deliver browser-assembled malware. Another concerning development is MedusaHVNC, which functions as a hidden desktop tool designed to capture live Windows sessions, potentially exposing sensitive information. The newsletter also includes an analysis of a malware strain named 'Cruciferra', though details on its specific impact are not provided. These findings underscore the evolving nature of cyber threats and the need for users and companies to stay informed and vigilant against such attacks.

Read Original

Russian hackers have reportedly hijacked hotel Wi-Fi networks to steal Microsoft 365 authentication tokens from unsuspecting users. This technique allows attackers to gain access to sensitive accounts without needing the users' passwords. The incident primarily affects travelers and guests using hotel Wi-Fi, who may unknowingly expose their credentials while accessing their Microsoft accounts. This type of attack raises significant concerns about the security of public internet connections and the potential for widespread account takeovers. Users should be cautious when connecting to hotel Wi-Fi and consider using a VPN to protect their data.

Read Original

Google is set to introduce a new feature in Chrome that will automatically block extensions installed via policy from taking control of the New Tab page or altering the default search engine settings. This change aims to enhance user security by preventing potentially unwanted modifications that could arise from malicious or poorly designed extensions. Users, particularly in enterprise environments where policy-installed extensions are common, may benefit from this added layer of protection. The move comes as part of Google’s ongoing efforts to ensure a safer browsing experience amid rising concerns over browser security. This feature is expected to roll out in the near future, making it harder for hijackers to manipulate users' browser settings.

Read Original
PreviousPage 54 of 364Next