Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Cognyte, an Israeli surveillance firm, has developed a mobile cell surveillance van equipped with technology that mimics a mobile phone tower. This system, known as FalcoNet, can intercept signals from nearby phones, allowing law enforcement to track devices in the area regardless of ownership. The van can hide the technology within its structure or deploy it in a backpack or even from a helicopter. This technology is similar to the Stingray system, which has been controversial due to privacy concerns. The implications of this type of surveillance raise significant questions about civil liberties and the extent of police monitoring capabilities.

Read Original

Lookout has launched the Mobile Security Exposure Center (MSEC), which aims to enhance the security of enterprise mobile applications. This initiative focuses on creating Software Bill of Materials (SBOMs) that help organizations identify vulnerable components and dependencies within their mobile apps. By uncovering hidden risks, MSEC enables companies to better protect their sensitive data and maintain the integrity of their applications. This is particularly important as mobile apps increasingly become targets for cybercriminals. With the rise of sophisticated attacks, understanding the security posture of mobile applications is crucial for businesses that rely on them.

Read Original

A cybercrime group linked to China has been using a sophisticated crypter service named Cruciferra to hide malware in attacks targeting Indian taxpayers, tax professionals, and corporate finance teams. Recent analysis from Proofpoint reveals that this service allows various cybercriminals to deliver different forms of remote access malware while evading detection. Cruciferra employs techniques such as Bring Your Own Vulnerable Driver (BYOVD) and process ghosting, which help the malware operate stealthily on victim systems. The implications of these tactics are significant, as they enable attackers to compromise sensitive financial data and potentially cause substantial financial harm to individuals and organizations. This development is a reminder for users and companies to remain vigilant against evolving cyber threats and to implement strong security measures.

Read Original

Anthropic's latest AI model, Opus 5, has shown improvements in identifying software bugs, coming close to the performance of its predecessor, Mythos 5. However, it falls short in generating exploits, as it has blocked the ability to conduct binary-based vulnerability scanning and penetration testing. This limitation means that while it can find vulnerabilities, it cannot demonstrate how those vulnerabilities could be exploited. This is significant for developers and security teams who rely on such tools for comprehensive security assessments. Without the ability to generate exploits, users may not fully understand the implications of the bugs found, which could leave systems at risk if not properly addressed.

Read Original
Actively Exploited

A recent report from Halcyon reveals that while the overall number of ransomware attacks is decreasing, attackers are becoming more sophisticated with their techniques. Specifically, they are increasingly using methods to disable Endpoint Detection and Response (EDR) systems, which are crucial for detecting and mitigating these threats. This trend poses a significant challenge for organizations trying to defend themselves, as traditional security measures may not be effective against these new tactics. As cybercriminals evolve their strategies, it becomes essential for companies to update their defenses and stay informed about the latest ransomware developments. The report suggests that organizations need to prioritize bolstering their security protocols to counteract these advanced obfuscation techniques.

Read Original

In May 2026, hackers breached DentaQuest's computer network, compromising the personal and dental health information of over 23 million individuals. This incident raises serious concerns about data security in the healthcare sector, as the stolen information could be used for identity theft or insurance fraud. Those affected may face risks related to their sensitive health data being exposed. DentaQuest, a major provider of dental benefits, is now under scrutiny for its cybersecurity measures and how it protects patient information. This breach serves as a reminder for healthcare organizations to strengthen their defenses against cyberattacks and ensure the confidentiality of patient data.

Read Original

Cybersecurity researchers have identified a series of cyberattacks targeting government agencies in the Middle East, linked to a threat group from East Asia. The attackers are using Telegram for command and control (C2) operations and have deployed new malware families named TELESHIM, MIXEDKEY, and BINDCLOAK. Zscaler ThreatLabz reported that these activities were detected earlier this month. The implications of these attacks are significant, as they exploit communication platforms for malicious purposes, potentially compromising sensitive government data and operations. Understanding these tactics is crucial for enhancing security measures in affected regions.

Read Original

A recent report has identified 148 ransomware attacks against Italian organizations during the first half of 2026, with the manufacturing sector being the primary target. The analysis, conducted by ransomNews under its RedACT project, indicates a significant rise in ransomware incidents, which raises concerns about the security posture of Italian businesses. LockBit5 and Qilin are the two ransomware groups implicated in these attacks, suggesting a coordinated effort to exploit vulnerabilities within these organizations. This surge in ransomware activity not only threatens the operational integrity of affected companies but also highlights the need for enhanced cybersecurity measures. The manufacturing sector, already facing challenges from supply chain disruptions, may find itself further strained if these attacks continue to escalate.

Read Original

A new open-source AI sandbox called Nono has raised concerns about security vulnerabilities. When an AI coding agent operates within this environment, it can access sensitive information such as cloud keys stored in plaintext. This means that if the agent is improperly prompted or given incorrect commands, it may inadvertently access and misuse the company's credentials or files that the user has permission to read. This situation poses a significant risk, as any misstep could lead to unauthorized access to critical company data. Organizations using this sandbox need to be aware of these potential pitfalls to protect their sensitive information.

Read Original
Actively Exploited

The PEAR ransomware group has claimed responsibility for a significant data breach at MCBS, a company specializing in medical business management. They reportedly stole 3 terabytes of sensitive information, which affects approximately 1.2 million individuals. The stolen data could include personal health information and financial details, raising concerns about identity theft and privacy violations. This incident not only impacts those directly affected but also highlights vulnerabilities within healthcare data management systems. Companies in the healthcare sector need to reassess their security measures to prevent similar attacks in the future.

Read Original
Actively Exploited

In September 2025, attackers compromised the credentials of an npm maintainer, allowing them to release malicious versions of popular packages including chalk and debug. These packages are widely used, collectively racking up over 2 billion downloads weekly. In response, GitHub announced that it would delay automatic version updates to allow time for malware detection before users receive updates. This incident underscores the risks associated with open-source package management, where speed can sometimes lead to vulnerabilities. Developers and teams relying on these packages need to be vigilant and ensure they review updates carefully to avoid introducing malicious code into their projects.

Read Original

GitHub and the Python Package Index (PyPI) have rolled out a new time-based defense within their Dependabot tool to combat supply chain attacks. This mechanism aims to reduce the potential damage from such attacks by limiting the timeframe in which dependency updates can be exploited. Supply chain attacks have been a growing concern, as they can affect countless projects by targeting the libraries and packages they rely on. By implementing this time-based approach, GitHub and PyPI are enhancing security for developers and users who depend on their platforms. This change is particularly important as the software ecosystem continues to grow, making it a key area for ongoing security improvements.

Read Original
Actively Exploited

The Security Affairs Malware Newsletter discusses recent malware threats, including a backdoor introduced through compromised RubyGems like SleeperGem, Dendreo, and fastlane. These malicious packages can allow attackers to maintain persistent access to affected systems. Additionally, the report highlights the chaos caused by over 800 fake AI skills and MCP servers that delivered malware to unsuspecting users. The newsletter also mentions a ransomware variant called msaRAT that poses further risks. These developments are significant as they illustrate the evolving tactics used by cybercriminals, affecting developers and users who rely on these tools. Companies and users should remain vigilant and ensure their software sources are secure to prevent such incidents.

Read Original
Actively Exploited

Hackers have taken advantage of compromised hotel Wi-Fi gateways to trick users into entering their Microsoft 365 credentials on fake login pages. According to research from ReliaQuest's threat team, attackers have targeted hotels and conference centers, redirecting guests without their knowledge. This method avoids traditional phishing tactics like emails or attachments, making it particularly sneaky. Anyone using hotel Wi-Fi could be at risk, especially business travelers who often access sensitive accounts. This incident serves as a reminder for users to be cautious when logging into accounts over public networks and to verify the authenticity of login pages.

Read Original

Iran-linked actors have been identified as targeting critical infrastructure in the United States, specifically focusing on water and energy control systems. This escalation raises alarms about the security of essential services that millions rely on. The attacks pose significant risks, as breaches in these systems could lead to disruptions in water supply and energy distribution, impacting daily life and public safety. The involvement of state-sponsored groups highlights the ongoing geopolitical tensions and the potential for cyber warfare to affect civilian infrastructure. Organizations managing these essential services need to enhance their security measures to defend against such sophisticated threats.

Read Original
PreviousPage 76 of 369Next