Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Actively Exploited

In October 2025, researchers identified a new malware strain named LucidRook, which is targeting non-governmental organizations (NGOs) in Taiwan. The malware is delivered through RAR or 7-Zip archives that use social engineering tactics to entice users into executing a dropper called LucidPawn. This method of distribution raises concerns about the security of NGOs, which often handle sensitive information and may not have the same level of cybersecurity resources as larger organizations. The attacks reflect a growing trend of cybercriminals focusing on specific groups, potentially aiming to disrupt their operations or steal valuable data. As these organizations face increasing risks, the need for heightened security measures becomes more critical.

Impact: NGOs in Taiwan
Remediation: Organizations should implement rigorous security training for employees, use advanced email filtering, and ensure that antivirus software is up to date. Regularly backing up data and monitoring network traffic for unusual activity are also recommended.
Read Original

The article discusses the ongoing concerns among cryptographers about the potential impact of quantum computing on current encryption methods. As quantum computers become more powerful, they could potentially decrypt data that is currently secured by traditional algorithms. This has prompted the US National Institute of Standards and Technology (NIST) to work on developing post-quantum cryptography (PQC) to address these vulnerabilities. The timing of when quantum computers will reach this level of capability remains uncertain, but experts are actively preparing for the implications. This situation is significant as it could affect the security of sensitive data across various sectors, highlighting the need for organizations to begin transitioning to quantum-resistant encryption methods.

Impact: Current encryption algorithms, legacy systems, sensitive data protection
Remediation: Transition to post-quantum cryptography (PQC) methods
Read Original

Chevin Fleet Solutions has confirmed that its FleetWave environments, hosted in Azure in both the UK and the US, were taken offline due to a cybersecurity incident. This precautionary measure was implemented to ensure the safety and integrity of user data and services. While specific details about the nature of the incident have not been disclosed, the downtime affects users who rely on FleetWave for fleet management solutions. The decision to take the systems offline suggests that the company is taking the threat seriously and prioritizing security over service availability. Users and organizations that utilize FleetWave should stay updated on the situation and follow any guidance provided by Chevin regarding service restoration and data security.

Impact: FleetWave environments hosted in Azure (UK and US)
Remediation: N/A
Read Original

ChipSoft, a prominent Dutch healthcare IT firm, experienced a ransomware attack that led to the shutdown of its HiX platform, impacting numerous hospitals and healthcare providers across the Netherlands and Belgium. This incident has disrupted access to electronic health records (EHR) for both medical staff and patients, raising concerns about patient care and data security. As a major provider of EHR systems, ChipSoft's services are critical for managing patient information and facilitating healthcare operations. The attack underscores the vulnerability of healthcare systems to cyber threats, which can have serious implications for patient safety and operational continuity. Authorities and healthcare organizations are now tasked with addressing the fallout and restoring services as quickly as possible.

Impact: ChipSoft's HiX platform, EHR services for hospitals in the Netherlands and Belgium
Remediation: N/A
Read Original

A recent analysis of one billion remediation records from the Cybersecurity and Infrastructure Security Agency (CISA) has found that many critical vulnerabilities are being exploited by attackers before organizations have a chance to patch them. The research conducted by Qualys indicates that the speed at which cyber threats evolve outpaces the ability of security teams to respond effectively. This situation leaves companies vulnerable to breaches and other security incidents, as they struggle to address known flaws quickly enough. The findings emphasize the growing need for enhanced security measures and automated solutions to keep pace with the increasing number of threats. Without these improvements, organizations risk significant exposure to attacks that can have devastating impacts.

Impact: N/A
Remediation: Organizations should prioritize automation in their patch management processes and consider implementing continuous monitoring solutions to address vulnerabilities more effectively.
Read Original

Juniper Networks has released patches for multiple vulnerabilities in its Junos OS, including a critical flaw that could allow attackers to remotely take control of affected devices without needing authentication. This vulnerability poses a serious risk to organizations using Junos OS, as it could lead to unauthorized access and potential data breaches. The company has not specified which specific products are affected, but users of Junos OS should prioritize applying these updates. The presence of such a critical flaw emphasizes the need for regular software updates and vigilance in network security practices. Companies relying on Junos OS are encouraged to check for the latest patches and ensure they are implemented promptly to mitigate the risks associated with these vulnerabilities.

Impact: Junos OS and potentially all devices running affected versions
Remediation: Patches have been released, specific versions not detailed.
Read Original

The US government has issued a warning about the increasing targeting of programmable logic controllers (PLCs), a type of industrial control system crucial for managing various processes in manufacturing and other sectors. Research has identified 179 vulnerable operational technology (OT) devices that could be at risk. These vulnerabilities could allow attackers to disrupt operations, potentially leading to significant financial and safety repercussions for affected industries. As cyber conflicts escalate, companies that rely on these technologies need to assess their security posture and take necessary precautions to protect against potential exploitation. This situation is particularly urgent given the critical role that OT devices play in essential infrastructure.

Impact: 179 vulnerable operational technology devices, programmable logic controllers (PLCs)
Remediation: Companies should assess their security measures and update their systems to mitigate vulnerabilities.
Read Original

Anthropic's Mythos Preview model is raising concerns as it reportedly has the capability to identify and exploit critical zero-day vulnerabilities. While the company claims to have implemented controls to prevent misuse, the potential for this technology to fall into the wrong hands is alarming. Zero-day vulnerabilities are particularly dangerous because they are unknown to the software vendor and can be exploited before a patch is available. This situation poses a risk not only to users of the software that could be targeted but also to the broader cybersecurity landscape, as malicious actors could leverage such AI models to automate attacks. Companies need to consider the implications of AI in cybersecurity and take steps to safeguard against possible abuses.

Impact: Mythos Preview model by Anthropic
Remediation: N/A
Read Original
UNC6783 Hackers Use Fake Okta Pages in Corporate Breach Campaign

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Hackers identified as UNC6783 are targeting corporations by impersonating support staff and creating fake Okta login pages. They use social engineering techniques to trick employees into providing access to corporate systems, leading to the theft of sensitive data. This tactic raises concerns for companies relying on Okta for identity management, as it demonstrates how attackers can exploit trust and established processes. Organizations need to enhance their security awareness training and implement stronger verification measures to protect against such deceptive practices. The implications of these breaches could be severe, affecting not just the companies involved but also their customers and partners.

Impact: Okta login systems, corporate systems
Remediation: Companies should implement stronger verification measures and enhance security awareness training for employees.
Read Original

In March, three ransomware groups—Qilin, Akira, and Dragonforce—were responsible for a significant portion of cyberattacks, accounting for 40% of the 672 ransomware incidents reported, according to research from Check Point. This spike emphasizes the ongoing challenge organizations face from these malicious actors. The rise in activity from these specific gangs suggests a concentrated threat that could impact various sectors, as ransomware continues to be a lucrative avenue for cybercriminals. Companies and users need to stay vigilant and enhance their cybersecurity measures to protect against potential attacks. This situation serves as a reminder of the importance of regular system updates and employee training on recognizing phishing attempts, which are often the gateway for these types of attacks.

Impact: N/A
Remediation: Organizations should implement regular system updates, employee training on phishing recognition, and robust backup solutions to mitigate the risk of ransomware attacks.
Read Original

In the latest update, Chrome version 147 has addressed a total of 60 vulnerabilities, including two that are classified as critical. These critical flaws are linked to the browser's WebML component and were reported by anonymous researchers. The vulnerabilities are significant enough that they come with a combined bounty of $86,000 for anyone who can exploit them. Users of Chrome should ensure they are using the updated version to protect against potential attacks. Regular updates like this are crucial as they help safeguard users from newly discovered security risks.

Impact: Chrome version 147 and earlier versions
Remediation: Update to Chrome version 147 or later
Read Original

MITRE has released a new framework aimed at combating fraud by outlining the tactics and techniques commonly used by fraudsters. This behavior-based model provides insights into how fraud operates, helping organizations better understand and defend against these deceptive practices. The framework is particularly relevant for businesses that deal with online transactions and sensitive user data, as it can assist in identifying fraudulent activities before they escalate. By mapping out specific behaviors associated with fraud, MITRE's framework equips companies with the knowledge to bolster their security measures and protect their customers. This initiative is crucial for enhancing the overall integrity of digital transactions in an era where online fraud is increasingly sophisticated.

Impact: N/A
Remediation: N/A
Read Original
Actively Exploited

A serious vulnerability in Marimo, an open-source Python notebook designed for data science, has been exploited within just 10 hours of being made public. The flaw, identified as CVE-2026-39987, allows attackers to execute remote code without needing authentication, affecting all versions of Marimo up to and including the latest release. Researchers from Sysdig reported this rapid exploitation, underscoring the urgency for users to address this security gap. Organizations using Marimo need to prioritize patching their installations to avoid potential breaches, as the high CVSS score of 9.3 indicates a significant risk. The swift exploitation of this vulnerability serves as a reminder of the importance of timely updates and security practices in software development.

Impact: All versions of Marimo prior to and including the latest release
Remediation: Users should immediately update to the latest version of Marimo to mitigate the risk associated with this vulnerability.
Read Original

Attackers have compromised the update system for the Smart Slider 3 Pro plugin, a widely used tool for WordPress and Joomla, allowing them to distribute a malicious version containing a backdoor. This incident affects users of Smart Slider 3 Pro version 3.5.1.35 for WordPress, which has over 800,000 active installations. The backdoor could potentially allow unauthorized access to affected websites, putting sensitive data at risk. Users are urged to check their installations and ensure they are using a secure version of the plugin to prevent exploitation. This incident serves as a reminder of the vulnerabilities in third-party update systems and the importance of maintaining software security.

Impact: Smart Slider 3 Pro version 3.5.1.35 for WordPress
Remediation: Users should update to the latest version of Smart Slider 3 Pro to ensure they are not using the compromised version.
Read Original

Researchers have discovered a new malware known as LucidRook, which is written in Lua and is being deployed in targeted spear-phishing campaigns aimed at non-governmental organizations (NGOs) and universities in Taiwan. This malware is particularly concerning because it represents a shift in tactics, focusing on sectors often involved in sensitive and impactful work. Attackers are leveraging deceptive emails to compromise their targets, potentially leading to data breaches or other security incidents. The targeting of educational and humanitarian organizations indicates that attackers are seeking valuable information that could be exploited for various malicious purposes. Organizations in these sectors need to be vigilant and enhance their security measures to defend against such threats.

Impact: Non-governmental organizations, universities
Remediation: Organizations should enhance email filtering and employee training on recognizing phishing attempts. Regular software updates and security audits are also recommended.
Read Original
PreviousPage 65 of 213Next