Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

In February 2026, the Uffizi Galleries, a renowned art museum in Florence, Italy, fell victim to a cyberattack that resulted in the theft of its complete photographic archive. The attack raised significant concerns about the security of cultural institutions, which often hold invaluable collections. The museum has since managed to restore its archive using backups, but the incident raises questions about the adequacy of cybersecurity measures in place to protect sensitive data. Such breaches not only threaten the integrity of cultural heritage but also expose institutions to potential reputational damage and financial losses. This incident serves as a stark reminder for museums and similar organizations to bolster their cybersecurity defenses.

Impact: Uffizi Galleries' photographic archive
Remediation: Restored using backups
Read Original

Charming Kitten, a group linked to Iran's security forces, has been ramping up its use of social engineering tactics to carry out cyber espionage. This group is known for targeting officials, researchers, and employees at various companies by pretending to be trusted contacts. By impersonating familiar figures, they manipulate individuals into sharing sensitive information or clicking on malicious links. This method of attack is concerning because it exploits human psychology rather than technical vulnerabilities, making it harder for victims to recognize the threat. As these tactics become more sophisticated, it raises alarm bells for organizations that must bolster their defenses against such deceptive practices.

Impact: N/A
Remediation: Organizations should implement training programs to educate employees about recognizing social engineering attacks and ensure robust verification processes for sensitive communications.
Read Original

A new exploit known as GrafanaGhost has been discovered that can bypass AI guardrails, allowing attackers to exfiltrate sensitive data from Grafana instances. This vulnerability combines AI prompt injection techniques with URL flaws to access information that should be protected. Grafana, a widely used open-source platform for data visualization, is particularly vulnerable, and this breach could expose critical insights stored by companies using the software. The implications are serious, as organizations could face data leaks that might compromise their operations and customer trust. Users of Grafana are urged to review their security settings and monitor for any unusual access patterns to safeguard their data.

Impact: Grafana instances
Remediation: Users should review security configurations and monitor access logs for unusual activity.
Read Original

Recent findings reveal that attackers can exploit Grafana's AI components to leak sensitive enterprise data. By directing Grafana to external resources and using indirect prompts, they can bypass existing security measures. This vulnerability poses a significant risk to organizations that rely on Grafana for data visualization and monitoring, as it may expose confidential information. Companies using Grafana should take immediate action to assess their configurations and consider implementing additional safeguards to protect against such exploitation. The implications of this issue are serious, as it could lead to unauthorized access to critical business data.

Impact: Grafana AI components
Remediation: Companies should review their Grafana configurations and implement additional security measures to prevent exploitation.
Read Original

Noma Security researchers have discovered a method called 'GrafanaGhost' that exploits Grafana's AI capabilities to extract sensitive corporate data without detection. By using indirect prompt injection, attackers can manipulate the AI to inadvertently share confidential information. This incident raises significant concerns for organizations relying on Grafana for data visualization, as it reveals vulnerabilities in how AI handles user inputs. The implications are serious, as this could lead to unauthorized data exposure for companies that use Grafana's services. Organizations need to be aware of these risks and consider reviewing their AI configurations and security protocols.

Impact: Grafana's AI systems
Remediation: Organizations should review and update their AI configurations and implement stricter input validation measures to prevent indirect prompt injections.
Read Original

Storm-1175, a China-based cybercriminal group, is executing rapid ransomware attacks using newly discovered vulnerabilities to infiltrate networks. The group focuses on exploiting flaws before organizations have a chance to patch them, allowing for swift movement from gaining access to stealing data and deploying Medusa ransomware. This tactic not only threatens the immediate security of affected networks but also poses a significant risk to sensitive data and financial resources. Companies need to be vigilant about their security measures, especially around exposed systems, to defend against these fast-moving attacks. The urgency of this situation is underscored by the group's ability to execute attacks shortly after vulnerabilities are made public.

Impact: N/A
Remediation: Organizations should prioritize patching newly disclosed vulnerabilities and reinforce security measures on exposed systems.
Read Original
AI Agents and Non-Human Identities Creating Critical Security Gaps, Report

Hackread – Cybersecurity News, Data Breaches, AI and More

A new report from Keeper Security indicates that non-human identities, such as AI agents and automated systems, pose a significant security risk for businesses by 2026. Researchers found that as companies increasingly rely on these automated interactions, vulnerabilities are emerging that could be exploited by attackers. This shift raises concerns about how well current security measures can protect against these non-human threats. Organizations need to reassess their cybersecurity strategies to address the unique challenges presented by automated systems and ensure they are not leaving critical gaps in their defenses. As businesses become more digital, understanding and mitigating these risks will be vital for maintaining security and trust.

Impact: N/A
Remediation: Companies should reassess their cybersecurity strategies to address risks from non-human identities.
Read Original

The FBI has reported that cyber fraud cost victims over $17 billion in the past year, with cryptocurrency scams accounting for more than $7 billion of that total. The rise of AI-enabled fraud is a growing concern, as attackers are increasingly using advanced technology to deceive individuals and organizations. This surge in cyber crime affects a broad range of victims, from everyday users to businesses. The FBI's findings emphasize the urgent need for increased awareness and protective measures against these evolving scams. As cyber criminals become more sophisticated, both individuals and companies must stay informed about the risks and adopt better security practices to safeguard their assets.

Impact: Cryptocurrency, personal finances, online platforms
Remediation: Users should employ strong security measures, such as two-factor authentication and regular monitoring of financial accounts. Companies should provide training on recognizing scams and implement advanced security protocols.
Read Original

Researchers have shown that GPU Rowhammer attacks can lead to privilege escalation, allowing attackers to gain root shell access on affected systems. This technique exploits vulnerabilities in the way graphics processing units (GPUs) manage memory, enabling unauthorized users to manipulate data and execute commands with higher privileges than intended. The implications of this discovery are significant, as it raises concerns about the security of systems that rely on GPUs for processing. Companies and users who utilize GPUs in their infrastructure may need to reassess their security measures to protect against this type of attack. As the research develops, it’s crucial for affected parties to stay informed and take necessary precautions to secure their systems.

Impact: GPUs from various vendors susceptible to Rowhammer attacks
Remediation: Users should monitor for updates from GPU vendors and apply any security patches as they become available; implementing memory isolation techniques may also help mitigate risk.
Read Original

Researchers have identified a new attack method called GPUBreach that exploits vulnerabilities in GPU memory, specifically through a technique known as RowHammer. This attack can lead to privilege escalation and even give attackers full control over affected systems. The method takes advantage of bit-flips in GDDR6 memory, which can go beyond just corrupting data. This poses a significant risk to users and organizations relying on these graphics processors, as it could compromise sensitive information and system integrity. As technology increasingly relies on GPUs for various applications, understanding and addressing this vulnerability is crucial for maintaining security.

Impact: GDDR6 memory used in various GPUs from multiple manufacturers.
Remediation: Users and organizations should monitor for updates from GPU manufacturers regarding patches or mitigations related to memory vulnerabilities. Implementing hardware-level protections against RowHammer attacks may also be necessary.
Read Original

Recent reports indicate that North Korean operatives are actively recruiting Iranian workers for fraudulent IT jobs. Internal records show how these facilitators scout for potential candidates and provide them with training to carry out various online scams. This operation raises concerns about the collaboration between North Korea and Iran in cybercrime, as it allows North Korea to generate revenue through illicit means while exploiting the skills of Iranian workers. The implications are significant, as this partnership could enhance the capabilities of both nations in executing cyberattacks and scams, potentially affecting businesses and individuals globally. Cybersecurity experts warn that such alliances may lead to more sophisticated cyber threats in the future.

Impact: N/A
Remediation: N/A
Read Original

The Medusa ransomware group has been swift in exploiting vulnerabilities, utilizing zero-day exploits to gain access to systems. Once inside, they quickly exfiltrate and encrypt data, often within days of their initial breach. This rapid response poses a significant threat to organizations, as it reduces the time available for victims to respond and mitigate the damage. Companies across various sectors need to be vigilant and ensure their systems are updated to prevent falling victim to these attacks. The effectiveness of Medusa's tactics highlights the importance of maintaining robust cybersecurity defenses and monitoring for unusual activity.

Impact: N/A
Remediation: Organizations should ensure their systems are up to date with the latest security patches and conduct regular vulnerability assessments to identify and address potential weaknesses.
Read Original

The Hong Kong police can now compel individuals to disclose encryption keys for their personal devices, including phones and laptops. This change stems from a revision to the enforcement of the National Security Law, announced on March 23, 2026. The U.S. Consulate General issued a security alert regarding this development on March 26, warning that travelers could be affected even while passing through the airport. This legal shift raises significant privacy concerns, as individuals may be forced to provide access to sensitive personal information without any legal protections. It is essential for travelers and residents to be aware of this new requirement and consider the implications for their personal data security.

Impact: Personal electronic devices including computers, phones, and hard drives.
Remediation: N/A
Read Original

Recent reports have surfaced about a significant code leak from Claude, an AI chatbot developed by Anthropic. The exposed code could potentially allow malicious actors to replicate or manipulate the chatbot's functions, raising concerns over misuse and security vulnerabilities. Additionally, there has been a compromise involving the Axios NPM package, which affected developers using this popular JavaScript library. The incident emphasizes the risks associated with third-party libraries in software development, particularly in open-source environments. As these security issues come to light, developers and organizations must take extra precautions to safeguard their applications and data from potential exploitation.

Impact: Claude AI chatbot, Axios NPM package
Remediation: Developers should review and update their dependencies, implement security best practices for open-source components, and monitor for unusual activity in their applications.
Read Original

A Chinese hacker group known as Storm-1175 is exploiting a mix of zero-day and N-day vulnerabilities to launch rapid attacks, specifically using Medusa ransomware. These attacks target internet-facing systems that are vulnerable, allowing the group to infiltrate networks quickly. Their ability to identify exposed assets has led to successful breaches, raising concerns for organizations that may not have adequate defenses in place. As these vulnerabilities are actively exploited, it becomes crucial for companies to strengthen their cybersecurity measures. The situation underscores the need for vigilance and timely patching of known vulnerabilities to prevent ransomware infections.

Impact: Internet-facing systems, particularly those with unpatched vulnerabilities
Remediation: Organizations should prioritize patching exposed systems, regularly update software, and employ security measures to detect and respond to ransomware threats.
Read Original
PreviousPage 72 of 214Next