Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

French prosecutors are investigating a suspected cyberattack on the GNV ferry Fantastic, which operates between Sète, France, and North Africa. Authorities are particularly concerned about the possibility of a remote hijack, indicating that attackers may have attempted to gain control over the vessel's systems. The investigation is ongoing, and details about how the attack was executed or the extent of the compromise have not been disclosed yet. This incident raises alarms about the security of maritime transportation, highlighting vulnerabilities that could potentially threaten passenger safety and disrupt services. The situation is being closely monitored as more information becomes available.

Impact: GNV ferry Fantastic
Remediation: N/A
Read Original

In October 2025, Kaspersky reported a new wave of phishing attacks linked to a group known as Operation ForumTroll, specifically targeting Russian scholars. These attackers are using fake emails that appear to come from a legitimate eLibrary service to lure victims into providing sensitive information. This shift from targeting organizations in the spring to focusing on individuals in the fall raises concerns about the attackers' evolving strategies. The origins of the threat actor remain unclear, but the targeted approach suggests a calculated effort to exploit the academic community. Such incidents can lead to significant data breaches and have serious implications for both personal and institutional security.

Impact: Russian scholars, academic institutions
Remediation: Users should verify email sources before clicking links or providing personal information and consider using security training to recognize phishing attempts.
Read Original

Researchers at Arctic Wolf have reported that attackers are actively exploiting a vulnerability in Fortinet's FortiGate firewalls, identified as CVE-2025-59718. This flaw allows unauthorized access to the firewalls, enabling attackers to export sensitive system configuration files. These files can reveal critical information about the network, security policies, and even encrypted passwords, which could facilitate further attacks. Organizations using FortiGate firewalls should take immediate action to protect their systems, as the risk of a security breach is significant due to the data that can be accessed through this vulnerability. The situation underscores the importance of timely updates and security measures to safeguard network infrastructure.

Impact: Fortinet FortiGate firewalls, specifically affected by CVE-2025-59718 and CVE-2025-59719.
Remediation: Organizations should apply any available patches from Fortinet for CVE-2025-59718 and CVE-2025-59719. Regularly updating firewall configurations and ensuring strong authentication practices are also recommended to mitigate risks.
Read Original

The National Motor Freight Traffic Association (NMFTA) has issued a warning about a significant increase in cyber-enabled cargo theft targeting the trucking industry. Their 2026 Transportation Industry Cybersecurity Trends Report indicates that attackers are using more sophisticated methods to steal cargo, which not only affects the freight companies but also poses risks to supply chain integrity and consumer safety. This rise in theft could lead to higher costs for transportation and logistics firms, potentially impacting prices for consumers. As these cyber threats evolve, the NMFTA stresses the need for enhanced cybersecurity measures within the industry to protect against these growing risks.

Impact: Trucking industry, freight companies, supply chain systems
Remediation: Enhanced cybersecurity measures, employee training on phishing and security protocols
Read Original

Askul, a major Japanese e-commerce and logistics company, has reported a significant data breach following a ransomware attack by a group called RansomHouse. This incident has compromised over 700,000 records, raising concerns about the security of sensitive information related to both businesses and consumers who rely on Askul for office supplies and logistics services. The attack underscores the ongoing risks faced by companies in the e-commerce sector, particularly as cybercriminals increasingly target organizations with ransomware. As a result, affected individuals and businesses may be at risk of identity theft and other cyber threats. Companies should take this incident as a wake-up call to bolster their cybersecurity measures and ensure they have effective data protection strategies in place.

Impact: Over 700,000 records from Askul's customer database
Remediation: Companies should enhance cybersecurity protocols and consider implementing more stringent data protection measures.
Read Original
Hackers Claim Stealing 94GB of Pornhub Premium User Watch Histories

Hackread – Cybersecurity News, Data Breaches, AI, and More

Actively Exploited

A hacking group known as ShinyHunters has reportedly stolen 94GB of data from former Pornhub Premium users, which includes their watch histories. This breach is part of an extortion campaign aimed at these users, raising significant privacy concerns. The attackers utilized a smishing attack, where they sent phishing messages via text to lure victims into revealing personal information. While the specifics of the breach are still being investigated, conflicting reports have emerged about the extent and security of the data involved. This incident underscores the ongoing risks associated with online platforms, particularly regarding user data security and the potential for exploitation by cybercriminals.

Impact: Pornhub Premium user watch histories
Remediation: Users should monitor their accounts for suspicious activity and consider changing passwords. Enabling two-factor authentication can also help enhance security.
Read Original

LKQ, a US autoparts manufacturer, has confirmed a data breach affecting over 9,000 individuals. The breach involved unauthorized access to personal data, raising concerns about the security of sensitive information. This incident highlights the vulnerabilities that companies face, especially those relying on systems like Oracle EBS. Those affected may be at risk for identity theft and other forms of fraud, emphasizing the need for individuals to monitor their accounts and consider additional security measures. Companies are urged to review their security protocols to prevent similar incidents in the future.

Impact: Personal data of over 9,000 individuals
Remediation: N/A
Read Original

A recent operation led by Eurojust has dismantled a call center fraud ring based in Ukraine, which was responsible for defrauding victims of approximately $12 million. The operation involved multiple European law enforcement agencies working together to target the network of scammers who deceived individuals, often by impersonating legitimate companies. This crackdown is significant as it not only disrupts the financial gains of the fraudsters but also aims to protect vulnerable populations from ongoing scams. The investigation highlights the collaborative efforts across borders to combat organized crime, especially in the realm of online fraud. As these types of scams continue to evolve, law enforcement agencies emphasize the need for public awareness and vigilance against such fraudulent schemes.

Impact: N/A
Remediation: N/A
Read Original

Kaspersky's GReAT team has reported an increase in cyberattacks from the ForumTroll APT group, which is specifically targeting Russian political scientists. The attackers are using a tool known as the Tuoni framework to infiltrate their devices. This situation is concerning as it shows a focused attempt to compromise the devices of individuals involved in political research, potentially to gather sensitive information or disrupt their work. The targeting of political scientists indicates a strategic move to influence or monitor political discourse in Russia. These incidents serve as a reminder of the ongoing risks faced by academics and researchers in politically sensitive environments.

Impact: Devices of Russian political scientists, potentially including personal computers and academic networks.
Remediation: N/A
Read Original

The Chinese cyber espionage group known as Ink Dragon has reportedly infiltrated European government networks to conduct its operations. Researchers have found that this group is using these networks to mask its activities, making it challenging for authorities to detect their movements. This situation raises concerns about national security, as sensitive information may be at risk. The infiltration of government systems not only threatens the integrity of those networks but also poses risks to the safety of citizens and international relations. As the group continues its activities, it underscores the need for improved cybersecurity measures within government infrastructures.

Impact: European government networks
Remediation: Strengthening cybersecurity protocols, monitoring network traffic for unusual activity, and implementing stricter access controls.
Read Original

LKQ, a major player in the auto parts industry, has confirmed a breach involving their Oracle EBS system, compromising the personal information of thousands of individuals. The attack raises serious concerns about data security, as sensitive information could be misused by cybercriminals. While LKQ has not disclosed the exact number of affected individuals, the incident underscores the vulnerabilities that can exist in enterprise resource planning systems. Companies using similar platforms should take this as a wake-up call to assess their security measures and ensure that personal data is adequately protected. The breach serves as a reminder of the increasing risks businesses face from cyberattacks in today's digital landscape.

Impact: Oracle EBS system, personal data of thousands of individuals
Remediation: N/A
Read Original

Afripol is addressing regional cybersecurity challenges stemming from rapid digital growth, a lack of cybersecurity expertise, and the rise of organized cybercrime. These issues are putting pressure on law enforcement and prosecutors who are struggling to keep up with the evolving threat landscape. The organization is focusing on enhancing cooperation among countries in Africa to better combat cybercriminal activities. This collective approach aims to strengthen the region's defenses against cyber threats, making it crucial for the safety and security of businesses and individuals in the area. As cybercriminal syndicates become more sophisticated, regional collaboration is essential for effective law enforcement and prosecution.

Impact: N/A
Remediation: N/A
Read Original

Illusory Systems has reached a settlement with the Federal Trade Commission (FTC) regarding a 2022 hack that compromised its Token Bridge software. The FTC charged the company for misrepresenting the security measures in place, stating that the executives did not implement adequate safeguards to protect user assets. As a result of the breach, attackers were able to exploit vulnerabilities, leading to significant financial losses. This incident underscores the need for companies in the cryptocurrency space to maintain transparent and effective cybersecurity practices. The settlement may also serve as a warning to other firms about the importance of accurately representing their security capabilities to users and regulators.

Impact: Token Bridge software
Remediation: N/A
Read Original

The outgoing chief of the Government Accountability Office (GAO) has raised concerns about the Cybersecurity and Infrastructure Security Agency (CISA) potentially easing its efforts in cybersecurity. In a recent statement, he emphasized the need for continued vigilance in the face of increasing cyber threats. He warned that any reduction in focus could leave critical infrastructure vulnerable to attacks. The comments come amid ongoing discussions about the role and funding of CISA, which is tasked with protecting the nation’s cybersecurity. As CISA navigates its priorities, the former GAO chief's remarks serve as a reminder of the persistent risks in the digital landscape and the importance of maintaining robust security measures.

Impact: CISA, critical infrastructure sectors
Remediation: N/A
Read Original

Reports have surfaced regarding a cyberattack on PDVSA, Venezuela's state-owned oil and gas company, which allegedly led to major disruptions in its operations. While PDVSA has attempted to downplay the incident, the extent of the disruption suggests significant implications for the company and potentially for the wider oil market. This incident raises concerns about the security of critical infrastructure in the sector and the potential for similar attacks targeting other companies. As PDVSA navigates the aftermath, both the company and industry observers will be watching closely to assess the impact on production and supply chains.

Impact: PDVSA operations
Remediation: N/A
Read Original
PreviousPage 70 of 101Next