Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

The Chinese cybercrime group Silver Fox has targeted a Japanese manufacturing company using a sophisticated attack method that involves exploiting vulnerable drivers. This approach, known as bring your own vulnerable driver (BYOVD), allows attackers to bypass security measures and install a remote access tool called ValleyRAT, which enables persistent access to the compromised systems. The campaign marks a notable shift in tactics, as the group is utilizing newly identified vulnerable drivers alongside legitimate software abuse. This incident raises concerns for the industrial sector, highlighting the need for stronger security protocols to protect against such advanced threats. Organizations in manufacturing and similar industries should be particularly vigilant and assess their defenses against these types of attacks.

Read Original

The FCC has expanded its Covered List to include foreign-made advanced robotic devices and power inverters, effectively prohibiting new models from being authorized for use in the U.S. This decision aims to mitigate potential security risks posed by these foreign products, which may be vulnerable to cyber threats. Existing devices that have already been authorized can still receive security updates until 2029, allowing for continued support while the agency assesses the risks of new entries. This move is significant as it reflects growing concerns over national security and the integrity of critical infrastructure. The restriction could impact companies and consumers looking to adopt the latest technology in automation and energy management.

Read Original

A recent analysis by Claroty found that 20% of cyber-physical systems in major data centers are vulnerable to attacks. The study examined 750,000 assets across some of the largest facilities worldwide, revealing that many critical systems are easily accessible to potential attackers. This situation raises concerns for data security, as these systems often manage sensitive information and infrastructure. Companies operating data centers should take immediate action to assess and secure their assets to prevent possible breaches. The findings indicate a pressing need for improved security measures in environments where physical and cyber systems intersect.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability affecting the Cisco Secure Firewall Management Center (FMC) to its Known Exploited Vulnerabilities catalog. This flaw, identified as CVE-2026-20316, has a CVSS score of 5.3, indicating a moderate level of severity. Organizations using Cisco FMC should take this seriously as the vulnerability could potentially be exploited by attackers. CISA's inclusion of this flaw in their catalog signals a heightened risk, urging companies to assess their security measures. It's crucial for users to stay updated and implement necessary patches to protect their systems from potential exploitation.

Read Original

A cyberattack struck over 30 community water utilities in Minnesota on July 26 and 27, affecting their operational technology systems. Minnesota IT Services (MNIT) confirmed the incident on July 28, stating they promptly activated their cybersecurity response capabilities to manage the situation. The agency is collaborating with various partners to contain the intrusion and assess the damage. This attack raises significant concerns about the security of critical infrastructure, as water utilities play a vital role in public health and safety. The incident underscores the ongoing risks posed by cyber threats to essential services and highlights the need for robust cybersecurity measures in public utilities.

Read Original

The UK's National Cyber Security Centre (NCSC) is urging manufacturers of network devices to enhance their forensic observability features. This call to action comes as a response to the increasing complexity of cyber threats, which make it challenging for organizations to investigate incidents effectively. By embedding better forensic capabilities into their devices, vendors can help organizations gather crucial data during security breaches, enabling more thorough investigations and quicker responses. The NCSC's initiative emphasizes the need for improved visibility into network activities, which is essential for cybersecurity efforts. This push aims to bolster the overall security posture of organizations in the UK and beyond.

Read Original

The U.S. and its allies have refreshed their guidance on Software Bill of Materials (SBOM) five years after the initial release. This update includes new elements, removes outdated ones, and revises terminology to better reflect current practices in software security. The push for clearer SBOM guidelines aims to enhance transparency in software supply chains, which is critical for identifying vulnerabilities and improving overall security. By standardizing this documentation, organizations can better manage risks associated with software components. This update is particularly relevant for software developers, cybersecurity professionals, and organizations that rely on third-party software.

Read Original

A recent analysis revealed that eSIM Plus and Nicegram, two popular applications marketed as Lithuanian products, share a codebase linked to Belarus. eSIM Plus, which has over 1 million downloads, routes its data and calls through Russian services, raising concerns about user privacy and data security. Nicegram is even more widely used, boasting over 50 million downloads. The findings were reported by the Mysterium VPN Research Team, who emphasized the potential risks for users in the EU and beyond. This situation highlights the need for users to be cautious about the applications they choose, especially those that may have ties to countries with questionable cybersecurity practices.

Read Original
Actively Exploited

Kaspersky researchers have identified a new strain of ransomware called GenieLocker, which targets Windows, Linux, and ESXi systems. This ransomware is associated with a group known as Toy Ghouls, which is primarily focused on financial extortion. The emergence of GenieLocker is concerning because it indicates a growing trend of customized ransomware that can impact multiple operating systems, making it a versatile threat for various organizations. Companies using affected systems should be vigilant and implement strong security measures to protect their data. With ransomware incidents on the rise, understanding the capabilities of threats like GenieLocker is crucial for effective defense strategies.

Read Original

Google has released Chrome version 151, which addresses 370 security vulnerabilities, including around 80 that are deemed critical or high severity. This update is crucial for users, as it helps protect against potential exploits that could compromise personal data or system integrity. The vulnerabilities patched span various aspects of the browser, which could affect a wide range of users and organizations that rely on Chrome for their internet activities. Regular updates like this are essential in keeping users safe from emerging threats, and it's recommended that all Chrome users install the latest version as soon as possible to ensure their security.

Read Original

Russian hackers have been exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain access to mailboxes even after users change their passwords. This campaign, which started on July 22, 2026, has targeted various sectors including U.S. and European government entities, telecommunications, finance, hospitality, and aerospace. The attackers are using this flaw to bypass credential rotation, which is a common security measure. The exploitation of this vulnerability poses significant risks, as it allows unauthorized access to sensitive information and communication. Organizations need to ensure that they are aware of this issue and take steps to protect their systems against such attacks.

Read Original

A recent report reveals that organizations are facing increasing costs from data breaches, with the average expense reaching nearly $5 million in 2026. Notably, over 25% of these breaches were driven by artificial intelligence, leading to costs that were about $1 million higher than breaches without AI involvement. In response, many companies are integrating AI technology into their security operations, particularly for tasks like threat hunting and automated incident response. This trend reflects a growing recognition of the need to counter sophisticated attacks, especially as AI becomes a tool for cybercriminals. As organizations invest in AI for defense, they must balance its use to protect against its potential misuse by attackers.

Read Original

Cybercriminal syndicates in Southeast Asia are expanding their operations, shifting from trafficking goods to providing illicit services, including human trafficking. These groups are reportedly involved with individuals from at least 80 countries, creating a significant financial burden for nations in the region, with estimated costs reaching $88 billion by 2025. This trend poses serious challenges to law enforcement and public safety, as the criminal networks become more sophisticated and interconnected. The situation highlights the need for international cooperation to combat these syndicates effectively and protect vulnerable populations from exploitation.

Read Original

A new malware-as-a-service called 'Flying Eagle' is gaining traction among various threat groups in China. This service allows cybercriminals to create mobile remote access tools (RATs) that can steal personal information and drain victims' bank accounts. Researchers have identified that these infostealers can target a wide range of mobile devices, making it easier for attackers to exploit unsuspecting users. The rise of such sophisticated malware poses a significant risk to individuals and businesses alike, as it enables criminals to conduct financial fraud and identity theft on a large scale. Users are urged to be vigilant and protect their devices with updated security measures.

Read Original
LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach

Hackread – Cybersecurity News, Data Breaches, AI and More

LeakNet has announced a significant data breach involving NYC Health + Hospitals, claiming to have stolen 11 terabytes of sensitive information. This data reportedly includes medical, financial, and biometric records belonging to over 12 million individuals. If true, this breach could have serious implications for patient privacy and security, as it exposes a vast amount of personal information. The incident raises concerns about the security measures in place at healthcare institutions and highlights the ongoing threat of cyberattacks in the healthcare sector. Authorities and affected individuals will need to respond swiftly to mitigate potential fallout from this breach.

Read Original
PreviousPage 63 of 366Next