Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A recent study by the Information Systems Security Association (ISSA) reveals that a significant majority of security professionals—over two-thirds—are finding it increasingly difficult to manage cybersecurity threats. One key challenge identified is the involvement of colleagues from other departments in cybersecurity efforts, which can complicate security practices. As more employees are engaged in cybersecurity, the potential for miscommunication and inadequate training grows. This situation raises concerns about the overall effectiveness of security measures within organizations. It emphasizes the need for better collaboration and education among all staff to enhance the organization's security posture.

Impact: N/A
Remediation: Companies should improve training and communication regarding cybersecurity practices among all employees.
Read Original

California Water Service is currently investigating claims made by Iranian hackers regarding potential breaches of its water and wastewater systems. However, the company has stated that there is no evidence of any operational disruptions at this time. This situation raises concerns about the security of critical infrastructure, especially as cyber threats to public utilities continue to grow. Authorities and customers alike are watching closely to see if these claims lead to any actual security incidents that could impact water supply or safety. The investigation is ongoing, and Cal Water is taking the matter seriously to ensure the integrity of their systems.

Impact: Water and wastewater systems operated by California Water Service
Remediation: N/A
Read Original
Actively Exploited

Police departments across the United States are reportedly using Flock surveillance cameras in ways that raise serious privacy concerns. In over a dozen cases, officers have allegedly stalked individuals without legal justification, utilizing the camera system to track their movements obsessively. This misuse of technology not only breaches ethical standards but also raises alarms about the potential for abuse of surveillance tools meant to enhance public safety. The impact of these actions could undermine trust in law enforcement and lead to calls for stricter regulations on surveillance practices. Advocates for privacy rights are urging for greater oversight to prevent such incidents from occurring in the future.

Impact: Flock surveillance camera system
Remediation: Calls for greater oversight and regulation of surveillance practices; not specified.
Read Original

Chainguard, JPMorgan, and BNY Mellon have joined forces to create a new coalition called Athena, aimed at addressing vulnerabilities in open source software that could be exploited by artificial intelligence. This initiative seeks to identify and fix weaknesses in AI models before they can be targeted by malicious actors. The collaboration comes as the reliance on open source components in software development grows, raising concerns about security. By proactively addressing these vulnerabilities, the coalition aims to enhance the security of software that many organizations depend on. This move is particularly significant given the increasing sophistication of cyber threats related to AI technology.

Impact: Open source software components
Remediation: N/A
Read Original

Cisco has issued a warning about a vulnerability in its Catalyst SD-WAN Manager, designated CVE-2026-20262. This flaw allows attackers to write arbitrary files through the web interface, potentially compromising the system's integrity. Cisco confirmed that this vulnerability is currently being actively exploited, which raises significant concerns for organizations using affected systems. The vulnerability has a CVSS score of 6.5, indicating a moderate level of risk. Companies utilizing the Catalyst SD-WAN Manager should prioritize assessing their systems for this vulnerability and implement necessary security measures to protect against potential attacks.

Impact: Cisco Catalyst SD-WAN Manager
Remediation: Organizations should apply security patches provided by Cisco for the Catalyst SD-WAN Manager. Additionally, administrators are advised to review access controls and monitor logs for any suspicious activity related to file writes. Regular updates and security assessments should be conducted to ensure the system's integrity.
Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited vulnerability in the LiteSpeed cPanel user-end plugin, identified as CVE-2026-54420. This flaw poses a significant risk to U.S. government servers, prompting CISA to give agencies just three days to secure their systems. Attackers can exploit this vulnerability to gain unauthorized access, which could lead to data breaches or other malicious activities. The urgency of the warning highlights the need for prompt action to protect sensitive information and maintain system integrity. Agencies are advised to take immediate steps to patch their systems against this threat.

Impact: LiteSpeed cPanel user-end plugin
Remediation: CISA has instructed U.S. government agencies to secure their servers within three days, implying that patches or updates should be applied as soon as possible. Specific patch numbers or versions are not mentioned, but agencies should prioritize updating the LiteSpeed cPanel plugin as part of their remediation efforts.
Read Original

The DragonForce ransomware group has been found using a custom malware called 'Backdoor.Turn' to conceal their command-and-control traffic within Microsoft Teams relays. This tactic allows them to mask their activities, making it harder for security measures to detect their malicious actions. By leveraging the infrastructure of a widely-used collaboration tool, they are able to blend in with legitimate traffic, posing a significant challenge for cybersecurity professionals. This development raises concerns for organizations that utilize Microsoft Teams, as it highlights the potential for trusted platforms to be exploited for harmful purposes. Companies should remain vigilant and enhance their monitoring efforts to detect any unusual activities that could indicate an attack.

Impact: Microsoft Teams, DragonForce ransomware, Backdoor.Turn malware
Remediation: Organizations should implement advanced threat detection systems, regularly monitor network traffic for anomalies, and educate employees about potential phishing attempts that could lead to ransomware infections.
Read Original

Cybersecurity researchers have discovered new Windows versions of a backdoor known as SprySOCKS, which was previously thought to be limited to Linux systems. The variants, labeled WIN_DRV and WIN_PLUS, contain hard-coded command-and-control configurations and can communicate over TCP and UDP protocols. This development raises concerns as it indicates that attackers, likely linked to China, are expanding their malware capabilities to target Windows users. The existence of these variants could pose significant risks to organizations using Windows operating systems, as they may be vulnerable to unauthorized access and control. Users and companies should remain vigilant and update their security measures to prevent potential exploitation.

Impact: Windows operating systems
Remediation: Users should implement security updates and enhance monitoring of network traffic for unusual activity.
Read Original

Researchers at Defused have reported that attackers are actively exploiting multiple serious vulnerabilities in Fortinet's FortiSandbox, a platform designed for detecting cyber threats. These flaws could allow unauthorized access to systems that rely on FortiSandbox for security measures, potentially leading to significant breaches. Organizations using FortiSandbox should be particularly vigilant as these vulnerabilities are now being targeted in the wild. It's crucial for affected users to assess their exposure and implement recommended security measures promptly. The situation highlights the ongoing risks associated with cybersecurity tools, where vulnerabilities can be exploited by malicious actors.

Impact: Fortinet FortiSandbox
Remediation: Organizations should apply the latest patches released by Fortinet for FortiSandbox. Regularly update systems and conduct thorough security assessments to mitigate risks.
Read Original
Actively Exploited

The FBI has issued a warning about a new trend in cryptocurrency scams where couriers are being used to pick up cash payments. This method is being exploited by scammers to bypass traditional banking systems and facilitate fraudulent investments. Victims are often lured into these schemes with promises of high returns, only to find themselves out of pocket after sending cash to a courier. This tactic not only complicates tracking the flow of money but also makes it easier for scammers to evade law enforcement. The warning serves as a crucial reminder for individuals to be cautious and verify the legitimacy of any investment opportunities, especially those involving cryptocurrency.

Impact: Cryptocurrency investment schemes
Remediation: Individuals should verify investment opportunities and avoid sending cash to couriers.
Read Original

iRhythm Holdings, a digital healthcare company, recently reported a data breach involving the theft of personal and health information of patients. The breach occurred through third-party-hosted business applications, raising concerns about data security in healthcare environments. Affected individuals may have had their sensitive information compromised, which could lead to identity theft or other privacy violations. This incident emphasizes the need for healthcare providers to strengthen their data protection measures, especially when relying on external services to manage patient information. As healthcare continues to digitize, incidents like this highlight the vulnerabilities that come with storing sensitive data online.

Impact: Patient personal and health information
Remediation: Companies should review third-party security practices and enhance their data encryption and access controls.
Read Original

Cisco has issued security updates to address a medium-severity vulnerability in its Catalyst SD-WAN Manager, previously known as SD-WAN vManage. The flaw, identified as CVE-2026-20262, has a CVSS score of 6.5 and has been reported as actively exploited in the wild. This vulnerability affects the web user interface, allowing authenticated remote attackers to create files, which could lead to further compromise of the system. Given that this software is widely used for managing SD-WAN deployments, organizations utilizing this product should prioritize applying the latest updates to mitigate potential risks. The active exploitation of this flaw emphasizes the importance of maintaining up-to-date security measures in network management solutions.

Impact: Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage)
Remediation: Cisco has released security updates that should be applied to all affected systems. Specific patch numbers or versions were not mentioned in the article.
Read Original

The U.S. Department of Justice recently seized the websites CFAKE.com and SOCFAKE.com, which were reportedly hosting nonconsensual AI-generated nude images and videos of women. This action marks a significant enforcement step under the TAKE IT DOWN Act, aimed at combating the spread of harmful deepfake content. The seizure reflects growing concerns about the misuse of artificial intelligence to create explicit material without consent, impacting the privacy and safety of individuals, particularly women. The move is part of a broader effort to hold accountable those who exploit technology for malicious purposes and to provide victims with legal recourse. As deepfake technology continues to advance, the implications of this action may resonate throughout the digital landscape, prompting discussions on regulation and ethical use of AI.

Impact: CFAKE.com, SOCFAKE.com
Remediation: N/A
Read Original

A vulnerability in SimpleHelp's remote management software has been discovered, allowing attackers to create unauthorized technician accounts without needing to authenticate. This flaw exploits the OpenID Connect (OIDC) authentication protocol, which is widely used for secure logins. As a result, any server running this software could be compromised, leading to unauthorized access and potentially sensitive data exposure. This is particularly concerning for organizations relying on SimpleHelp for remote support, as it puts their systems and data at risk. Users and administrators should take immediate action to secure their systems and stay informed about any forthcoming patches.

Impact: SimpleHelp remote management software
Remediation: Users should apply any available patches from SimpleHelp and review their security configurations for OIDC authentication.
Read Original

Researchers at Proofpoint have identified two phishing campaigns linked to a North Korean hacking group known as Contagious Interview, also referred to as Famous Chollima. These campaigns are cleverly disguised as recruitment efforts for developer roles or as requests for code reviews. The tactics used by these attackers demonstrate a sophisticated approach to lure potential victims into providing sensitive information. This is particularly concerning for software developers and companies in the tech sector, who may be targeted due to their access to valuable intellectual property and sensitive data. The rise in these types of campaigns serves as a reminder for organizations to remain vigilant about phishing threats and to educate employees about identifying suspicious communications.

Impact: N/A
Remediation: Companies should implement robust phishing awareness training and consider using advanced email filtering solutions to detect and block malicious campaigns.
Read Original
PreviousPage 6 of 226Next