Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

OpenAI's ChatGPT has made its debut in the list of the top 10 most impersonated brands in phishing attacks, according to research from Check Point. This marks a significant shift as attackers are increasingly using the chatbot's name to deceive users into revealing personal information. Phishing scams typically involve creating fake websites or emails that look like legitimate services, and in this case, scammers are leveraging the popularity of ChatGPT. This is concerning for both users and organizations, as it indicates that bad actors are targeting well-known brands to exploit their trustworthiness. Users need to be vigilant and verify the authenticity of any communication claiming to be from ChatGPT or related services to avoid falling victim to these scams.

Read Original
Critical
Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

A group of Russian hackers known as TA488 has exploited a zero-day vulnerability in the Zimbra webmail platform. This flaw allows attackers to steal user credentials and access up to 90 days of email messages simply by opening or previewing emails, without the need for users to click any links. This incident affects organizations using Zimbra for their email services, potentially compromising sensitive information. The ability to extract such a large amount of data from victims' accounts raises significant concerns about data security and privacy. Companies using Zimbra should take immediate action to protect against this exploit and review their email security practices.

Read Original

A hacker has taken control of an AI assistant and used it to infiltrate Thailand's Ministry of Finance, which oversees the country's treasury and tax collection. The attacker rented a server, disabled security settings, and directed the AI to autonomously explore the ministry's network. The AI agent searched for ways to gain root access and rummaged through file systems without supervision. This incident raises significant concerns about cybersecurity practices within government agencies, especially regarding the use of AI tools that can be easily manipulated. The breach not only compromises sensitive financial data but also poses risks to national security by potentially allowing unauthorized access to critical systems.

Read Original

The Golden Chickens malware-as-a-service group has returned with four new malware families: TinyEgg, ChonkyChicken, a modular version of ChonkyChicken, and a modified credential-stealing browser variant. This resurgence comes despite previous efforts to expose their operations. The new malware poses risks primarily to organizations and individuals who might fall victim to these threats, as they are designed to facilitate a variety of cybercriminal activities. The continuous development of these malware families indicates that the operators are adapting and evolving their tactics, which could make combating these threats more challenging for security professionals. It's critical for users to remain vigilant and update their defenses against these emerging threats.

Read Original
Actively Exploited

A recent analysis by Comparitech reveals a significant spike in ransomware attacks targeting universities, largely attributed to the emergence of The Gentlemen ransomware. In the first half of 2026, higher education institutions reported a marked increase in incidents where attackers encrypt critical data and demand ransom payments for its release. This trend is particularly alarming as universities often handle sensitive personal information, making them attractive targets for cybercriminals. The rise of such attacks poses serious risks not only to educational operations but also to the privacy and security of students and faculty. Institutions need to bolster their cybersecurity measures to protect against these evolving threats.

Read Original

U.S. agencies, including CISA, NSA, and FBI, have issued a warning about the Russian group Laundry Bear exploiting a known vulnerability in Zimbra servers. This flaw allows attackers to access and steal email accounts from organizations that have not applied the necessary patches. The advisory stresses that any organizations running unpatched versions of Zimbra could be at risk, as the attackers are actively targeting these systems. It is crucial for affected organizations to update their servers promptly to protect sensitive information and prevent unauthorized access. This incident emphasizes the ongoing threat posed by advanced persistent threat groups and the importance of maintaining up-to-date software.

Read Original

NodeBB, a popular forum software, has publicly disclosed eight serious security flaws that could allow unauthorized access to admin accounts and private chats. These vulnerabilities were identified by Aikido Security's AI-powered pentesting tools during a six-hour review of the software's source code. All versions prior to 4.14.0 are affected, and NodeBB has released a patch to address these issues. Administrators are advised to upgrade to version 4.14.2 to protect their forums. One of the vulnerabilities can be fixed with a simple settings adjustment, underscoring the importance of timely updates for maintaining security.

Read Original

The Clop ransomware group is currently targeting PTC's Windchill and FlexPLM products, specifically those that are accessible over the internet. This new campaign focuses on stealing sensitive data from these systems and then extorting the affected organizations for money. Companies using these platforms should be particularly vigilant as the attackers exploit vulnerabilities to gain access. The implications of such attacks are significant, as they not only threaten the confidentiality of proprietary data but also risk operational disruptions and reputational damage. Organizations are urged to strengthen their security measures to protect against these types of ransomware incidents.

Read Original

A recent analysis reveals that AI products across Europe are vulnerable due to inconsistent security measures in multilingual contexts. Researchers found that the AI security frameworks currently in place do not provide uniform protection against jailbreaking and other unsafe actions when interacting in different languages. This uneven coverage poses a risk not just to developers but also to users who rely on these technologies in their daily lives. As AI continues to integrate into various sectors, the need for improved security protocols that account for linguistic diversity becomes increasingly urgent. If left unaddressed, these gaps could lead to significant misuse of AI applications, potentially compromising user data and safety.

Read Original

Researchers have discovered multiple remote code execution (RCE) vulnerabilities in several versions of Redis, a widely used in-memory data structure store. The vulnerabilities affect Redis versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0, with specific exploitation chains requiring commands like RESTORE, EVAL, and XGROUP. Redis confirmed that these memory flaws could allow attackers to execute arbitrary code remotely. In response, Redis released seven security updates on July 23 to address these issues, including versions 6.2.23, 7.2.15, and 7.4.10. Users of these affected versions need to update their systems promptly to protect against potential exploitation.

Read Original

Origin Energy, one of Australia’s major energy providers, has confirmed a data breach affecting approximately 2 million customers. A hacker claims to have stolen sensitive customer information and is threatening to leak it unless certain demands are met. This breach raises significant concerns about the security of personal data in the energy sector, highlighting the vulnerability of large corporations to cyberattacks. Customers of Origin Energy should be aware of the potential risks, including identity theft and fraud, as their information may be exposed. The company has not yet detailed the specific types of data compromised but is likely facing scrutiny from both customers and regulators regarding its data protection practices.

Read Original

A recent study has revealed that employees at well-funded companies are more likely to open phishing emails and attachments. In a simulation involving 13.9 million phishing messages, only 10% of recipients reported suspicious emails to their security teams. This leaves the other 90% potentially vulnerable, as attackers only need one unsuspecting employee to compromise a system. The research emphasizes the importance of employee training and awareness in cybersecurity, particularly in high-stakes environments where sensitive information is at risk. Organizations must prioritize educating their staff to recognize and report phishing attempts to reduce the chances of successful attacks.

Read Original

The 2026 Ransomware Report from Black Kite reveals a significant increase in ransomware activity, with 61 new groups emerging between April 2025 and March 2026, averaging over one new group each week. This marks a shift from the previous years, where ransomware incidents were often tied to a single dominant actor or a major supply chain breach. Instead, the market has become more fragmented, with multiple ransomware playbooks operating simultaneously. As a result, the number of victims continues to rise, which poses serious risks for organizations across various sectors. This growing trend underscores the need for enhanced security measures and vigilance among companies to protect against these evolving threats.

Read Original
Actively Exploited

Ukrainian cybersecurity officials have uncovered a new cyber campaign that exploits the popular Notepad++ text editor to spread malware. This attack allows malicious actors to gain persistent access to affected systems, posing a significant risk to users in Ukraine. The use of a legitimate application like Notepad++ makes the malware distribution less detectable, increasing the chances of successful infiltration. As this campaign targets Ukraine, it raises concerns about the security of critical infrastructure and personal data in the region. Users and organizations should be vigilant about software installations and monitor for any unusual activity on their systems.

Read Original

The Lampion banking malware, which is believed to have originated in Brazil, is still making waves as it targets organizations in Portugal. This banking Trojan is designed to steal sensitive financial information, posing a significant risk to businesses and individuals alike. Recent reports indicate that Lampion is actively involved in ongoing attacks, raising alarms about the safety of financial transactions within the affected organizations. As cyber threats continue to evolve, it’s crucial for companies to remain vigilant and implement strong security measures to protect against such malware. The implications are serious, as breaches can lead to financial losses and damage to reputation.

Read Original
PreviousPage 80 of 369Next