A recent study has revealed that employees at well-funded companies are more likely to open phishing emails and attachments. In a simulation involving 13.9 million phishing messages, only 10% of recipients reported suspicious emails to their security teams. This leaves the other 90% potentially vulnerable, as attackers only need one unsuspecting employee to compromise a system. The research emphasizes the importance of employee training and awareness in cybersecurity, particularly in high-stakes environments where sensitive information is at risk. Organizations must prioritize educating their staff to recognize and report phishing attempts to reduce the chances of successful attacks.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Help Net Security
The 2026 Ransomware Report from Black Kite reveals a significant increase in ransomware activity, with 61 new groups emerging between April 2025 and March 2026, averaging over one new group each week. This marks a shift from the previous years, where ransomware incidents were often tied to a single dominant actor or a major supply chain breach. Instead, the market has become more fragmented, with multiple ransomware playbooks operating simultaneously. As a result, the number of victims continues to rise, which poses serious risks for organizations across various sectors. This growing trend underscores the need for enhanced security measures and vigilance among companies to protect against these evolving threats.
Ukrainian cybersecurity officials have uncovered a new cyber campaign that exploits the popular Notepad++ text editor to spread malware. This attack allows malicious actors to gain persistent access to affected systems, posing a significant risk to users in Ukraine. The use of a legitimate application like Notepad++ makes the malware distribution less detectable, increasing the chances of successful infiltration. As this campaign targets Ukraine, it raises concerns about the security of critical infrastructure and personal data in the region. Users and organizations should be vigilant about software installations and monitor for any unusual activity on their systems.
The Lampion banking malware, which is believed to have originated in Brazil, is still making waves as it targets organizations in Portugal. This banking Trojan is designed to steal sensitive financial information, posing a significant risk to businesses and individuals alike. Recent reports indicate that Lampion is actively involved in ongoing attacks, raising alarms about the safety of financial transactions within the affected organizations. As cyber threats continue to evolve, it’s crucial for companies to remain vigilant and implement strong security measures to protect against such malware. The implications are serious, as breaches can lead to financial losses and damage to reputation.
Pete Waterman, who leads the Federal Risk and Authorization Management Program (FedRAMP), has issued a strong warning to technology companies about the importance of addressing security vulnerabilities swiftly. He stated that companies unable to promptly fix dangerous flaws should reconsider selling their products to federal agencies. This statement comes amid growing concerns over cybersecurity risks in government procurement. By enforcing stricter standards, Waterman aims to ensure that federal agencies are protected from potential security breaches that could arise from unpatched vulnerabilities. This approach emphasizes the need for tech vendors to prioritize security in their development processes, which is crucial for maintaining the integrity of government systems.
SCM feed for Latest
A recent security assessment has revealed serious vulnerabilities in the healthcare sector, particularly related to social engineering tactics and poor network security practices. Attackers are exploiting weaknesses in gatekeeper roles, which are supposed to protect sensitive data. These lapses not only jeopardize patient information but also disrupt critical healthcare services. The findings raise urgent concerns about the need for improved cybersecurity measures within hospitals and healthcare organizations. Without addressing these vulnerabilities, patients and staff remain at risk of data breaches and other cyber threats, which can have severe implications for patient care and trust in healthcare systems.
SCM feed for Latest
A recent report by The Hacker News has brought attention to the growing issue of fabricated machine identities, which pose a serious security risk similar to synthetic identity fraud in humans. This type of fraud involves the creation of fake identities for machines, which can lead to unauthorized access to sensitive systems and data. Organizations that rely heavily on machine-to-machine communication, such as those in the IoT and cloud computing sectors, are particularly vulnerable. Without proper safeguards, these fabricated identities can bypass traditional security measures, making it essential for companies to enhance their identity verification processes. This situation underscores the need for improved security protocols to protect against this often-overlooked threat.
SCM feed for Latest
This article discusses the characteristics of nation-state threat actors and how they differ from other types of cyber attackers. It emphasizes the importance for cybersecurity professionals to accurately identify these actors in order to assess threat intelligence effectively. Nation-state actors are typically backed by governments and have access to significant resources, making their tactics more sophisticated than those of independent hackers or criminal groups. Understanding these distinctions can help organizations prioritize their defenses and respond appropriately to potential threats. The article serves as a guide for security teams to enhance their threat assessments and better prepare for attacks that may originate from state-sponsored entities.
A new malware called Dolphin X has emerged, functioning as a remote access trojan (RAT) that utilizes artificial intelligence to assess and rank the value of its victims. By scoring infected users, cybercriminals can prioritize their targets based on the potential payoff. This AI-driven profiling allows attackers to focus their efforts on high-value individuals or organizations, making the threat particularly concerning for anyone at risk of being compromised. The introduction of such technology could lead to more targeted and effective cyberattacks, raising alarms for security professionals and users alike. As the malware spreads, it highlights the evolving tactics of cybercriminals and the need for enhanced security measures.
Senator Marco Rubio has announced new visa restrictions targeting individuals involved in sextortion and cyber scams. This decision follows an executive order from the Trump administration aimed at combating cyber-enabled fraud. The restrictions are designed to prevent those engaged in these criminal activities from entering the United States, reflecting a growing concern over the impact of online scams on victims. Sextortion, a form of blackmail that exploits personal images or information, has been on the rise, affecting many individuals, particularly young people. By tightening visa regulations, lawmakers hope to deter these criminals and protect potential victims from their schemes.
A recent malvertising campaign on Bing is promoting a fake desktop application that masquerades as the Claude AI tool. This fake installer is hosted on a legitimate domain for Claude.ai and is designed to deliver a malware known as SectopRAT. Users searching for Claude on Bing may unknowingly download this malicious software, which can compromise their systems. The presence of such malware poses risks not only to individual users but can also affect organizations if their employees inadvertently install it on work devices. Cybersecurity experts are urging users to be cautious when downloading software from search engine ads, as this incident illustrates the potential dangers of malvertising.
The Hacker News
A Russian state-sponsored espionage group has exploited a previously unknown vulnerability in Zimbra's webmail client to gain unauthorized access to Western email accounts. This attack allowed the hackers to read the last 90 days of emails, access the entire email directory, and retrieve saved passwords and two-factor authentication recovery codes. The exploitation was triggered simply by opening a malicious email. The U.S. National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA), along with their partners, have alerted organizations to this ongoing threat. This incident raises significant concerns about the security of email communications, especially for organizations using Zimbra, as it underscores the need for vigilance against such sophisticated attacks.
CyberScoop
A Russian espionage group known as Laundry Bear has been exploiting a zero-day vulnerability in Zimbra for five months before it was patched in July 2025. Despite the patch, the group continues to target vulnerable systems to steal sensitive data from Western countries. This ongoing activity raises concerns about the security of email platforms and the potential for data breaches that could affect numerous organizations. As companies rely on these systems for communication, the implications of such attacks could be significant, leading to unauthorized access to confidential information. Organizations using Zimbra should prioritize updating their systems to protect against this threat.
On July 22, 2026, the FBI, CISA, and NSA issued a joint alert regarding a rise in cyberattacks linked to Iranian actors. These attacks are primarily targeting critical infrastructure, raising concerns about potential disruptions to essential services. The agencies highlighted that these cyber threats could affect various sectors, including energy, water, and transportation systems. As tensions continue to escalate, organizations in these areas are urged to bolster their cybersecurity measures to prevent potential breaches. This alert serves as a timely reminder for companies and governmental bodies to remain vigilant against sophisticated cyber threats that could have serious implications for public safety and national security.
Ukraine's CERT has reported that attackers are using a combination of the legitimate Notepad++ application and a malicious utility named LunchPoke, which is disguised as a plugin. This malicious tool is designed to install malware on victims' systems and maintain a presence even after initial infection. Users who download the compromised software may unknowingly introduce this malware into their systems, putting their data and security at risk. This incident serves as a reminder for users to be cautious about the sources from which they download software, as even trusted applications can be manipulated to deliver harmful payloads. The situation emphasizes the need for vigilance in software installation practices.