Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Three Democratic lawmakers have criticized the Immigration and Customs Enforcement (ICE) agency for its confirmed use of Paragon spyware. The Democrats expressed concerns over the potential misuse of this technology and the implications it has for privacy and civil liberties. Their dissatisfaction stems from ICE's responses regarding how the spyware may be deployed in immigration enforcement operations. This issue raises significant questions about surveillance practices and the impact on communities, particularly immigrant populations. As the debate continues, it highlights the need for transparency and accountability in government surveillance activities.

Impact: Paragon spyware
Remediation: N/A
Read Original

Recent leaks of the Claude Code source code have been exploited by cybercriminals to distribute Vidar information-stealing malware through fraudulent GitHub repositories. Attackers are creating fake repositories that appear legitimate, luring unsuspecting users into downloading the malicious software. This situation puts many users at risk, especially those who might be searching for the leaked code or related tools on GitHub. The Vidar malware is known for stealing sensitive information such as login credentials and personal data. Users should be cautious when downloading software from unofficial sources and verify the legitimacy of repositories before proceeding.

Impact: Vidar information-stealing malware
Remediation: Users should avoid downloading software from unofficial GitHub repositories and verify the authenticity of any code they are interested in.
Read Original

Hasbro has reported unauthorized access to its systems, leading the company to activate its business continuity plans and take some systems offline. The incident was disclosed in an 8-K filing, indicating that the attack has had a significant impact on the company's operations. While specific details about the nature of the attack or the data involved have not been released, the company expects that remediation could take weeks. This incident raises concerns about the security of sensitive information within major corporations and highlights the ongoing risks businesses face from cyber threats. Stakeholders are advised to stay informed as the situation develops.

Impact: Hasbro systems and potentially customer data, though specifics are not provided.
Remediation: Activated business continuity plans and took some systems offline.
Read Original

As tensions rise due to ongoing conflicts, cybersecurity experts warn about the increased risk of Iranian cyberattacks targeting critical infrastructure. Many organizations have not yet assessed their operational technology (OT) networks for potential vulnerabilities linked to Iranian cyber activities. To mitigate these risks, teams are advised to take proactive steps, including conducting thorough security assessments, implementing robust monitoring systems, and ensuring that incident response plans are up to date. These measures are vital to safeguard essential services and prevent potential disruptions that could have significant repercussions on public safety and national security. Organizations must remain vigilant and prepared as the geopolitical landscape evolves.

Impact: Critical infrastructure systems, operational technology networks
Remediation: Conduct security assessments, implement monitoring systems, update incident response plans
Read Original

A significant credential harvesting campaign has been detected, utilizing the React2Shell vulnerability (CVE-2025-55182) to gain access to sensitive data from 766 Next.js hosts. Attackers are stealing various credentials, including database logins, SSH private keys, AWS secrets, Stripe API keys, and GitHub tokens. This operation has been linked to a threat group that Cisco Talos is monitoring. The widespread nature of this breach is concerning, as it affects a range of developers and companies using Next.js, potentially compromising their applications and user data. Companies need to be vigilant and take immediate steps to secure their systems against this threat.

Impact: Next.js hosts, database credentials, SSH private keys, Amazon Web Services (AWS) secrets, Stripe API keys, GitHub tokens.
Remediation: Organizations should patch their systems to address the React2Shell vulnerability (CVE-2025-55182) and implement security best practices such as limiting access to sensitive credentials, regularly rotating keys and secrets, and monitoring for unauthorized access attempts.
Read Original
Actively Exploited

A recent study conducted by researchers from Stanford University, the University of California, Davis, and TU Delft revealed that thousands of API credentials have been exposed on public websites. Using a tool called TruffleHog, the researchers scanned various sites and discovered sensitive information that could be exploited by malicious actors. This exposure poses significant risks as attackers could gain unauthorized access to systems and data. The findings underscore the need for companies to implement better security practices, such as using environment variables and secure storage solutions for API keys. The research serves as a warning for developers and organizations to regularly audit their code and remove any sensitive information from public repositories.

Impact: API credentials from various companies and services
Remediation: Implement secure storage solutions for API keys, conduct regular audits of code repositories to remove sensitive information
Read Original

CrystalRAT is a new type of malware that has emerged in 2023, functioning as a malware-as-a-service platform. It operates on a subscription model, allowing users to access its capabilities, which include remote access to infected systems and features designed for pranks. Researchers from Kaspersky have noted that CrystalRAT bears a strong resemblance to an earlier malware called WebRAT. This is concerning as it lowers the barrier for entry for cybercriminals, enabling even those with limited technical skills to launch attacks. The rise of such services poses a growing threat to individuals and organizations, as they can be exploited for a variety of malicious purposes including data theft and system manipulation.

Impact: CrystalRAT malware, potentially affecting any system it infects.
Remediation: Users should ensure their systems are protected with updated antivirus software and be cautious of suspicious downloads and links.
Read Original

Hasbro, the well-known toy manufacturer, reported a cyberattack on Wednesday that has disrupted some of its operations. The company is currently investigating the incident to determine the extent of the attack and whether any sensitive data has been compromised. This situation raises concerns not only for Hasbro and its employees but also for customers who may be affected if personal information is involved. The investigation is ongoing, and Hasbro is working to restore its normal operations as quickly as possible. This incident serves as a reminder of the vulnerabilities that organizations face in the digital landscape.

Impact: Hasbro operations and potentially customer data
Remediation: N/A
Read Original

A Brazilian cybercrime group known as Augmented Marauder and Water Saci has launched a phishing campaign that spreads two banking trojans: Casbaneiro and Horabot. The attackers use a mix of WhatsApp, ClickFix techniques, and email phishing to deliver these malicious programs. The campaign primarily targets individuals and organizations, aiming to steal sensitive banking information. This is particularly concerning as it showcases the evolving tactics employed by cybercriminals to exploit users through familiar communication channels. Users should be cautious about unsolicited messages and verify the authenticity of links before clicking.

Impact: Casbaneiro and Horabot banking trojans
Remediation: Users should be wary of phishing attempts, avoid clicking on suspicious links, and ensure their security software is up to date.
Read Original

Recent reports indicate that ransomware attackers are increasingly using legitimate IT tools, such as Process Hacker and IOBit Unlocker, to bypass traditional antivirus software. These tools have deep access to operating system functions, allowing attackers to execute malicious activities without raising alarms. This trend poses significant risks to organizations, as it makes it harder for security systems to detect and prevent these kinds of attacks. Companies must reassess their security measures to account for the misuse of legitimate software, which could compromise sensitive data and disrupt operations. As attackers continue to evolve their tactics, it’s crucial for users and companies to stay vigilant and update their defenses accordingly.

Impact: Process Hacker, IOBit Unlocker
Remediation: Companies should enhance monitoring of system processes, implement stricter access controls, and regularly update their security software to recognize and mitigate the risks posed by legitimate tools being misused.
Read Original
Actively Exploited

WhatsApp has raised concerns about a fake iPhone app developed by the Italian spyware company SIO. This app is designed to impersonate the legitimate WhatsApp service, potentially tricking users into downloading malicious software. If users unknowingly install this app, their personal information and communications could be at risk. This situation highlights the ongoing threat of spyware and the importance of downloading applications only from trusted sources. Users are encouraged to verify app authenticity before installation to protect their data from potential exploitation.

Impact: iPhone users, WhatsApp application
Remediation: Users should only download apps from official app stores and verify the app's publisher before installation.
Read Original

Cisco has addressed several critical and high-severity vulnerabilities that could potentially allow attackers to bypass authentication, execute malicious code, escalate privileges, and access sensitive data. The company released patches for two critical vulnerabilities and six high-severity issues, including CVE-2026-20093, which has a significant CVSS score indicating its severity. These vulnerabilities affect various Cisco products, making it crucial for users and organizations to apply the patches promptly. Failure to address these flaws could lead to unauthorized access and significant security breaches. It's important for companies to stay updated with security patches to mitigate these risks effectively.

Impact: Cisco products affected include unspecified software versions that utilize the vulnerable components.
Remediation: Cisco has released patches for the identified vulnerabilities. Users are advised to apply these patches as soon as they are available to prevent potential exploitation.
Read Original

The Akira ransomware group has been reported to gain access to systems and encrypt data in under an hour, according to research from Halcyon. This quick turnaround is alarming for organizations, as it emphasizes the speed at which attackers can operate. The group is also noted for their focus on creating effective decryptors, possibly to encourage victims to pay ransoms. This tactic highlights a concerning trend in ransomware operations, where attackers not only seek to breach systems but also aim to facilitate recovery, making it more likely that companies will comply with their demands. Businesses need to be aware of these evolving methods and strengthen their security measures to mitigate the risk of such attacks.

Impact: N/A
Remediation: Companies should enhance their security protocols, conduct regular backups, and train employees on recognizing phishing attempts.
Read Original

Windows 11 users who attempted to install a problematic preview update released in March are encouraged to download a new out-of-band update that fixes installation errors. This recent update addresses issues that may have prevented users from successfully applying the earlier version. Affected users should check for the latest updates in their system settings to ensure they have the fix installed. This situation is important because installation errors can disrupt users' workflows and impact system stability. Keeping software up to date is crucial for security and performance.

Impact: Windows 11
Remediation: Users should download the new out-of-band update to fix installation errors from the March preview update.
Read Original

Stryker, a major player in the medical technology sector, recently recovered from a cyberattack attributed to the Iranian hacking group Handala. This attack involved a wiper malware that compromised the company's systems, disrupting operations and potentially affecting patient care and medical device functionality. Although Stryker has announced that its systems are back online, the implications of such an attack raise concerns about the security of healthcare infrastructure. Cyberattacks on medical technology firms can have serious consequences, not only for the companies involved but also for healthcare providers and patients relying on their products. The incident serves as a reminder of the ongoing risks facing the medtech industry and the need for enhanced cybersecurity measures.

Impact: Stryker's medical devices and operational systems
Remediation: N/A
Read Original
PreviousPage 77 of 215Next