Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

The FBI has taken significant action against the Russian hacking group APT28, which is linked to the GRU, the Russian military intelligence agency. This operation targeted routers that APT28 had compromised, allowing them to access a range of networks. According to Brett Leatherman, the FBI's cyber chief, this group's ability to propagate attacks from routers made their threat particularly concerning. By disrupting this access, the FBI aims to protect various organizations from potential espionage and data breaches. This incident underscores the persistent risk posed by state-sponsored cyber actors and highlights the importance of securing network infrastructure to prevent similar intrusions in the future.

Impact: Routers, network devices
Remediation: Organizations should ensure their routers are updated to the latest firmware, implement strong security configurations, and regularly monitor network traffic for unusual activity.
Read Original

Sensitive documents from the Los Angeles Police Department have reportedly been leaked online by a group known as World Leaks. The breach has exposed around 7.7 terabytes of data, which includes over 337,000 files. This incident raises serious concerns about the security of law enforcement data and the potential implications for public safety and privacy. With such a large volume of sensitive information now accessible, there is a heightened risk of misuse or further exploitation. The LAPD and other authorities will need to take immediate action to assess the extent of the breach and protect against future incidents.

Impact: Los Angeles Police Department (LAPD) documents and data
Remediation: N/A
Read Original

On April 7, 2026, ChipSoft, a healthcare software vendor based in the Netherlands, suffered a ransomware attack that has been confirmed by Z-CERT, the country's computer emergency response team for the healthcare sector. This incident raises serious concerns about the security of healthcare data, as ransomware attacks can disrupt medical services and compromise sensitive patient information. The attack's timing is particularly alarming given the essential role that healthcare software plays in patient care and operations. Authorities are likely working to assess the full impact of the breach and to assist affected healthcare providers in managing the fallout. This incident underscores the ongoing vulnerabilities in the healthcare sector regarding cybersecurity threats.

Impact: ChipSoft healthcare software systems
Remediation: N/A
Read Original

The Masjesu botnet, also referred to as XorBot, has emerged as a stealthy DDoS-for-hire service that primarily targets Internet of Things (IoT) devices. Unlike many other botnets, Masjesu avoids high-profile targets, such as Department of Defense IP addresses, opting instead for less conspicuous victims. This botnet employs XOR encryption to maintain low visibility and ensure its persistence within compromised systems. As the use of IoT devices continues to rise, the potential for such botnets to disrupt services and cause damage increases, making it crucial for users and organizations to secure their devices against such threats. The activity of Masjesu raises concerns about the growing sophistication of DDoS services that are accessible for hire, which can have widespread implications for network stability and security.

Impact: IoT devices, specifically those vulnerable to DDoS attacks
Remediation: Users should regularly update their IoT devices, change default passwords, and implement network security measures to protect against unauthorized access.
Read Original

Bitcoin Depot recently reported a significant cyber-attack that resulted in the theft of over 50 Bitcoin, valued at approximately $3.66 million. The breach occurred when hackers gained access to the company's internal systems, allowing them to siphon off the cryptocurrency. This incident raises concerns about the security measures in place for cryptocurrency exchanges and wallet services, as they can be prime targets for cybercriminals looking to exploit vulnerabilities. The theft not only affects Bitcoin Depot but also poses risks to users and investors in the cryptocurrency space, highlighting the ongoing challenges of securing digital assets. Companies operating in this sector need to reassess their security protocols to prevent similar incidents in the future.

Impact: Bitcoin Depot, Bitcoin
Remediation: Companies should enhance their internal security measures, conduct thorough audits, and implement multi-factor authentication to protect against unauthorized access.
Read Original
Claude Code Can Be Manipulated via CLAUDE.md to Run SQL Injection Attacks

Hackread – Cybersecurity News, Data Breaches, AI and More

LayerX researchers have found a way to exploit the Claude Code system by manipulating the CLAUDE.md file. This method allows attackers to bypass the platform's safety features, enabling them to execute SQL injection attacks. Such vulnerabilities can lead to unauthorized access to databases, potentially exposing sensitive information. This issue affects users of Claude Code, which is used in various applications for coding assistance. Companies relying on this technology should be aware of the risks and implement necessary precautions to protect their systems from possible exploitation.

Impact: Claude Code system
Remediation: Users should monitor for updates from LayerX and apply any patches or configurations recommended to mitigate the risk of SQL injection attacks.
Read Original

Researchers at RSAC discovered a way to bypass Apple Intelligence's AI guardrails using techniques called Neural Exect and Unicode manipulation. This vulnerability could allow attackers to exploit the AI's systems, potentially leading to unauthorized access or misuse of the technology. The implications of this breach are significant, as it raises concerns about the security and reliability of AI systems used by Apple and possibly other tech companies. Users and developers relying on Apple Intelligence need to be aware of this vulnerability to ensure their systems are secure. The researchers' findings emphasize the importance of ongoing scrutiny and improvement of AI security measures.

Impact: Apple Intelligence
Remediation: N/A
Read Original
Actively Exploited

Edge devices, which connect various networks and serve as points of entry, are increasingly becoming targets for cyber attackers. These devices can be exploited to gain unauthorized access to systems, allowing attackers to persist within networks and pivot to steal sensitive identity information. This trend raises concerns for organizations relying on edge computing, as vulnerabilities in these devices can lead to significant data breaches. Ensuring the security of edge devices is crucial, as they play a pivotal role in the overall security posture of an organization. Companies need to prioritize safeguarding these devices to protect against modern cyber threats.

Impact: Edge devices, perimeter security systems
Remediation: Implement stronger security measures for edge devices, conduct regular security audits, and update firmware to the latest versions.
Read Original

A hack-for-hire campaign has been uncovered, believed to be linked to an actor with possible connections to the Indian government. This campaign has primarily targeted journalists, activists, and officials across the Middle East and North Africa (MENA) region. Notably, two Egyptian journalists known for their criticisms of the government were among the individuals affected. The findings, reported by Access Now, Lookout, and SMEX, raise significant concerns about the safety and privacy of those who report on sensitive issues in these regions. The implications of such targeted attacks extend beyond individual safety, potentially stifling freedom of expression and press in the affected areas.

Impact: Journalists, activists, government officials in MENA region, particularly Egyptian journalists.
Remediation: N/A
Read Original

Eurail B.V., which operates digital passes for 33 national railways in Europe, reported a data breach that occurred in December 2025, affecting over 300,000 individuals. The breach involved the theft of personal information, although specific details about what data was compromised have not been disclosed. This incident raises serious concerns about the security of personal information in the travel industry, especially as digital services become more prevalent. Affected individuals may face risks such as identity theft or fraud. Eurail has not provided specific steps taken to address the breach or protect users going forward, making it crucial for those impacted to monitor their accounts closely.

Impact: Personal information of over 300,000 individuals, including potentially sensitive data.
Remediation: N/A
Read Original

A recent report from the SANS Institute reveals a significant rise in non-human identities (NHIs), with AI agents contributing to a 76% increase. This surge is concerning because NHIs can be used by malicious actors to impersonate legitimate users, leading to potential security breaches and fraud. Organizations are now facing challenges in governance and identity management as these AI-driven identities proliferate. The report emphasizes the need for companies to reassess their identity verification processes to mitigate risks associated with these non-human entities. As AI continues to evolve, understanding its impact on cybersecurity becomes increasingly vital for businesses and security professionals.

Impact: Non-human identities (NHIs), AI-driven systems
Remediation: Organizations should reassess and strengthen their identity verification processes to address risks posed by NHIs.
Read Original

Google's threat intelligence team has identified a new extortion group known as UNC6783, which appears to be linked to the Raccoon persona. This group is specifically targeting Business Process Outsourcing (BPO) companies and helpdesk services, indicating a shift in focus towards sectors that handle sensitive customer data. The group's tactics may involve ransomware or other extortion methods, which poses significant risks to affected organizations. Companies in the BPO sector should be vigilant and enhance their security measures to protect against potential breaches and data leaks. As this threat evolves, understanding the methods and motivations behind it will be crucial for businesses in these industries.

Impact: BPO companies, helpdesk services, enterprises handling sensitive customer data
Remediation: Companies should enhance security protocols, conduct regular security audits, and train staff on recognizing phishing attempts and other social engineering tactics.
Read Original

In December 2025, a data breach at Eurail compromised the personal information of approximately 300,000 individuals. Hackers managed to access sensitive data, including names and passport numbers, from the European travel company's network. This incident raises concerns about the security of personal information and highlights the risks associated with storing such data online. Affected individuals could face identity theft or fraud due to the exposure of their passport details. Companies in the travel sector must enhance their cybersecurity measures to protect customer data and prevent similar breaches in the future.

Impact: Names, passport numbers
Remediation: N/A
Read Original

Bitcoin Depot, a major player in the Bitcoin ATM market, reported that hackers stole approximately $3.665 million worth of Bitcoin from its digital wallets after breaching its systems last month. The attack highlights the ongoing risks associated with cryptocurrency exchanges and ATM networks, which can be particularly vulnerable to cybercriminal activities. As Bitcoin Depot works to secure its systems and recover from the incident, users and investors are reminded to remain vigilant about the security of their digital assets. The event raises concerns about the overall security practices within the cryptocurrency industry, emphasizing the need for stronger defenses against such attacks.

Impact: Bitcoin Depot's cryptocurrency wallets
Remediation: N/A
Read Original
Actively Exploited

A recent hack targeted Bitcoin Depot, a Bitcoin ATM operator, resulting in the theft of over 50 bitcoins, valued at approximately $3.6 million. The attacker gained access to the company’s wallets by stealing login credentials, allowing them to transfer the funds without detection. This incident raises concerns about the security of cryptocurrency operations and the potential risks associated with user credential management. As cryptocurrency continues to gain popularity, incidents like this highlight the need for stronger security measures to protect digital assets. Companies operating in the crypto space must ensure they have robust security practices in place to prevent similar attacks in the future.

Impact: Bitcoin Depot wallets
Remediation: Companies should implement two-factor authentication and monitor for suspicious account activity to enhance security.
Read Original
PreviousPage 67 of 213Next