Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

AI Firm Mercor Confirms Breach as Hackers Claim 4TB of Stolen Data

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Mercor, an AI firm, has confirmed a significant data breach linked to a supply chain attack involving LiteLLM. Hackers claim to have stolen 4TB of sensitive data, which may include internal systems and proprietary information. This breach raises serious concerns about the security of supply chain processes, as attackers often exploit vulnerabilities in third-party software to gain access to larger networks. Companies that rely on LiteLLM and similar technologies should be particularly vigilant and assess their security measures. The implications of such a large data theft could be severe, affecting not only Mercor but also its clients and partners who may be at risk of data exposure or further attacks.

Impact: LiteLLM supply chain, Mercor's internal systems, sensitive data
Remediation: Companies should review their supply chain security practices, implement stronger access controls, and monitor for unusual activity. Specific patches or updates were not mentioned.
Read Original

Researchers from watchTowr have discovered two significant vulnerabilities in Progress ShareFile, specifically within the Storage Zones Controller (SZC) component of versions 5.x. The first vulnerability, identified as CVE-2026-2699, is an authentication bypass that could allow unauthorized users to access files. The second flaw, CVE-2026-2701, is a remote code execution vulnerability that could enable attackers to run arbitrary code on affected systems. These vulnerabilities pose a serious risk to organizations using ShareFile, as they could lead to unauthorized data access and potential exploitation. It is crucial for users to take immediate action to secure their systems against these vulnerabilities.

Impact: Progress ShareFile versions 5.x, specifically the Storage Zones Controller (SZC) component.
Remediation: Users should update to the latest version of Progress ShareFile to patch these vulnerabilities. Additionally, organizations should review their access controls and ensure that only authorized personnel have access to sensitive files.
Read Original

The article discusses the rise of multi-extortion ransomware attacks, where attackers not only encrypt a victim's data but also threaten to leak sensitive information if their demands aren't met. This tactic adds pressure on victims, as the potential for public exposure can be damaging. Penta Security has developed a solution called the D.AMO platform, which aims to keep exfiltrated files encrypted, rendering them useless to attackers. This technology is crucial for organizations looking to protect their data from exploitation in such attacks. As ransomware tactics evolve, understanding and mitigating these risks is increasingly important for businesses of all sizes.

Impact: N/A
Remediation: Implement data encryption solutions like Penta Security's D.AMO platform to protect exfiltrated files.
Read Original

Drift, a company involved in cryptocurrency, has suffered a significant loss of $285 million due to a sophisticated hacking operation likely orchestrated by North Korean cybercriminals. The attackers employed advanced techniques, including the use of nonce-based tricks to pre-sign transactions and delay approvals, allowing them to bypass security measures. This incident raises alarms about the vulnerabilities in cryptocurrency platforms and the potential for state-sponsored actors to exploit these weaknesses for financial gain. The scale of the theft not only impacts Drift but also poses broader implications for the cryptocurrency market, as it highlights the ongoing risks of cyberattacks in this rapidly evolving sector. As companies like Drift face these threats, it becomes crucial for the industry to bolster security measures to protect against such sophisticated attacks.

Impact: Drift cryptocurrency platform
Remediation: Companies should enhance security protocols, including transaction verification and multisig approval processes.
Read Original

The article discusses recent incidents where source code leaks have exposed vulnerabilities in software supply chains. These leaks reveal a concerning lack of oversight in how software is developed and maintained, affecting various companies that rely on third-party code. Without proper security measures, these weaknesses can be exploited by cybercriminals, potentially leading to widespread attacks on critical infrastructure. The piece argues for stronger regulations and security practices to safeguard against these risks, emphasizing that software supply chains should be treated with the same importance as traditional infrastructure. As the reliance on software grows, the need for vigilance and oversight becomes increasingly urgent.

Impact: Software supply chains, third-party libraries, various affected companies not specified
Remediation: Implement strict security protocols, conduct regular audits of source code, and ensure third-party dependencies are up to date
Read Original

A new spear-phishing campaign has emerged, targeting senior executives and effectively bypassing multi-factor authentication (MFA) systems. This attack utilizes a recently identified phishing kit named VENOM, which allows attackers to craft convincing emails that trick recipients into providing sensitive information. The campaign poses a significant risk to businesses, as executives often have access to critical company data and systems. If successful, these attacks can lead to data breaches and financial losses. Companies must be vigilant and enhance their security measures to protect against such sophisticated phishing threats.

Impact: N/A
Remediation: Companies should implement additional security measures, such as employee training on recognizing phishing attempts and enhancing email filtering systems.
Read Original
Actively Exploited

WebinarTV has been found to be secretly joining public Zoom meetings, recording them, and then publishing the recordings online without the consent of the participants. This practice raises serious privacy concerns as it circumvents Zoom's built-in recording feature, making it difficult for the platform to take action against these recordings. Users who share sensitive information during these meetings could be at risk of having that information exposed to the public. The situation highlights the need for individuals and organizations to be more cautious about the privacy settings of their online meetings. Companies should consider implementing stricter access controls and educating their teams about the risks of public meeting invites to protect sensitive discussions.

Impact: Zoom meetings, WebinarTV
Remediation: Implement stricter access controls for online meetings, educate users on privacy settings and risks.
Read Original

The maintainer of the Axios npm package, Jason Saayman, revealed that a recent supply chain attack was linked to a targeted social engineering effort by North Korean hackers known as UNC1069. The attackers specifically tailored their approach to Saayman, initially posing as the founder of a prominent organization to gain his trust. This incident raises significant concerns about the security of open-source software, as it shows how easily even experienced developers can be manipulated. The compromise could potentially expose countless projects that rely on Axios, a popular library used in web development. Developers and organizations using Axios need to be vigilant and review their dependencies to prevent exploitation stemming from this attack.

Impact: Axios npm package
Remediation: Developers should audit their code dependencies and ensure they are using trusted sources. It's also recommended to implement security training for maintainers to recognize social engineering tactics.
Read Original

Hackers have exploited a vulnerability known as React2Shell in a large-scale campaign that has compromised over 750 systems. Using automated scanning tools and the Nexus Listener framework, these attackers targeted organizations to harvest credentials. This incident raises concerns for businesses and users alike, as stolen credentials can lead to unauthorized access and further security breaches. The scale of the attack highlights the need for heightened vigilance and improved security measures among affected organizations. Users and companies are urged to monitor their systems closely and implement stronger authentication protocols to mitigate risks.

Impact: Systems running React2Shell, possibly affecting various businesses and organizations.
Remediation: Organizations should implement stronger authentication measures and monitor systems for unusual activities. Regularly update security protocols to protect against automated scanning attacks.
Read Original

On April 2, 2023, the pro-Iranian hacker group Handala claimed to have breached PSK Wind Technologies, an Israeli defense contractor known for its work on command and control systems. This incident raises concerns about the security of critical infrastructure, as PSK Wind develops technology used in air defense and other sensitive applications. The breach highlights the ongoing cyber conflict between Iran and Israel, where state-sponsored hacking is increasingly used as a tactic. The extent of the breach and any potential data theft or disruptions it may cause remain unclear. However, this incident underscores the vulnerability of defense contractors to cyberattacks, which could have serious implications for national security.

Impact: PSK Wind Technologies, command and control systems, Israeli defense infrastructure
Remediation: N/A
Read Original

APERION has introduced the SmartFlow SDK, a new software development kit designed for secure, on-premises governance of artificial intelligence systems. This move comes as many companies look to distance themselves from potentially compromised cloud-based AI services, particularly following the LiteLLM supply chain attack. In that incident, attackers from the group TeamPCP breached a widely used open-source proxy in the Python ecosystem, impacting approximately 36% of cloud environments. The rise in web traffic to APERION's site, reported at 200% since the attack on March 24, suggests that organizations are seeking safer alternatives for their AI needs. This shift towards on-premises solutions reflects growing concerns about cloud security and the vulnerabilities associated with it.

Impact: LiteLLM, cloud-based AI services
Remediation: Transition to on-premises solutions like SmartFlow SDK
Read Original

The European Union's Cybersecurity Service (CERT-EU) has confirmed a significant data breach affecting the European Commission, linked to the TeamPCP hacking group. This breach has compromised the data of at least 29 other EU entities, raising concerns about the security of sensitive information within the Union's institutions. The attack underscores the ongoing risks to government networks from sophisticated cyber threats. The incident not only impacts the directly affected organizations but also raises alarms about the potential for further exploitation of the exposed data. As the investigation continues, EU officials are likely to review their cybersecurity protocols to prevent similar incidents in the future.

Impact: European Commission, 29 other EU entities
Remediation: N/A
Read Original

The article discusses the limitations of Endpoint Detection and Response (EDR) systems in cybersecurity. It points out that EDR relies heavily on logs and telemetry, which may not provide sufficient information to prevent real-time attacks. This gap in data can leave organizations vulnerable during an active threat. The piece suggests that autonomous IT management solutions could help bridge this gap by providing more comprehensive monitoring and response capabilities. This is particularly relevant for companies looking to enhance their security posture against evolving threats.

Impact: EDR systems
Remediation: Implement autonomous IT management solutions to enhance monitoring and response capabilities.
Read Original

Three Democratic lawmakers have criticized the Immigration and Customs Enforcement (ICE) agency for its confirmed use of Paragon spyware. The Democrats expressed concerns over the potential misuse of this technology and the implications it has for privacy and civil liberties. Their dissatisfaction stems from ICE's responses regarding how the spyware may be deployed in immigration enforcement operations. This issue raises significant questions about surveillance practices and the impact on communities, particularly immigrant populations. As the debate continues, it highlights the need for transparency and accountability in government surveillance activities.

Impact: Paragon spyware
Remediation: N/A
Read Original

Recent leaks of the Claude Code source code have been exploited by cybercriminals to distribute Vidar information-stealing malware through fraudulent GitHub repositories. Attackers are creating fake repositories that appear legitimate, luring unsuspecting users into downloading the malicious software. This situation puts many users at risk, especially those who might be searching for the leaked code or related tools on GitHub. The Vidar malware is known for stealing sensitive information such as login credentials and personal data. Users should be cautious when downloading software from unofficial sources and verify the legitimacy of repositories before proceeding.

Impact: Vidar information-stealing malware
Remediation: Users should avoid downloading software from unofficial GitHub repositories and verify the authenticity of any code they are interested in.
Read Original
PreviousPage 76 of 214Next