Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

The Dutch Ministry of Finance has taken its treasury banking portal offline following a cyberattack detected on March 19. While the treasury systems were impacted, the core tax systems remain unaffected. This decision was made as part of an ongoing investigation into the incident, which was first identified two weeks prior. The ministry has not provided detailed information about the nature of the attack or whether any data was compromised. This incident raises concerns about the security of government financial systems and the potential risks to sensitive taxpayer information.

Impact: Treasury banking portal
Remediation: N/A
Read Original

The article discusses the growing urgency for organizations to adopt unified exposure management in light of rapid advancements in cyber threats, particularly those driven by Artificial Intelligence. As attackers become faster and more sophisticated, traditional security measures may no longer suffice. This shift means that businesses must prioritize understanding their vulnerabilities and how they can be exploited in real-time. The emphasis on speed indicates a need for boards to reassess their cybersecurity strategies and invest in solutions that can keep pace with evolving threats. This is particularly important as the landscape of digital warfare becomes increasingly complex and dangerous.

Impact: N/A
Remediation: N/A
Read Original

A recently discovered vulnerability in StrongSwan, a popular open-source VPN solution, allows unauthorized attackers to crash VPN services remotely. This integer underflow flaw affects StrongSwan versions released over the past 15 years, putting a wide range of users at risk. The vulnerability can be exploited without authentication, meaning attackers can target systems without any prior access. Organizations using StrongSwan should take this seriously, as it could lead to significant downtime and disruption of services. Users are advised to update their StrongSwan installations as soon as possible to mitigate the risk of exploitation.

Impact: StrongSwan versions released over the past 15 years
Remediation: Users should update to the latest version of StrongSwan to address the vulnerability. Specific patch numbers are not mentioned.
Read Original

A recent software update from Lloyds Bank has accidentally exposed mobile banking users' transaction details to other users of the app. This incident has affected around 450,000 individuals who may have had their sensitive information accessible to others using the same application. The breach raises significant concerns about data privacy and the security of financial transactions. Users are now at risk of having their banking activities viewed by unintended parties, which could lead to identity theft or fraud. Lloyds has acknowledged the issue and is working to rectify the situation, but the incident serves as a reminder of the vulnerabilities that can arise from software updates.

Impact: Lloyds Bank mobile banking application
Remediation: Lloyds is working on resolving the issue with the faulty software update.
Read Original

According to a recent analysis by law firm Nockolds, employee data breaches have reached their highest level in seven years. The report attributes this surge primarily to non-cyber incidents, indicating that many breaches are due to human error or mishandling of sensitive information rather than external cyberattacks. This trend raises concerns for organizations as it suggests a need for improved training and awareness among employees regarding data privacy. With more personal information at risk, companies could face significant financial and reputational damage if these breaches continue. It's essential for businesses to address these vulnerabilities to protect both their employees and their overall data integrity.

Impact: Employee data, personal information
Remediation: Increase employee training on data handling and privacy practices
Read Original

A Maryland man has been charged with stealing over $53 million from the Uranium Finance cryptocurrency exchange through two separate hacking incidents. The suspect allegedly used a cryptocurrency mixer to launder the stolen funds, complicating the tracking of the illicit gains. This case raises concerns about the security of cryptocurrency exchanges and the effectiveness of measures in place to protect user assets. As the crypto market continues to grow, incidents like this highlight the vulnerabilities that can be exploited by attackers, putting both exchanges and their users at risk. Law enforcement's response may also impact the perceived safety of investing in cryptocurrencies.

Impact: Uranium Finance crypto exchange
Remediation: N/A
Read Original

The Dutch Ministry of Finance has temporarily taken several systems offline, including its treasury banking portal, following the detection of a cyberattack two weeks ago. The attack prompted officials to act swiftly to protect sensitive financial data and ensure the integrity of their systems. While the investigation is ongoing, there are concerns about the potential impact on government operations and public trust in digital services. This incident underscores the vulnerability of even government institutions to cyber threats, highlighting the need for robust security measures in public sector technology. Users of the treasury banking portal are advised to stay informed about any updates regarding the situation and potential impacts on their access to services.

Impact: Dutch Ministry of Finance treasury banking portal
Remediation: Systems taken offline for investigation and security assessment
Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies must patch their Citrix NetScaler appliances by Thursday to address a vulnerability that is currently being exploited by attackers. This flaw poses a significant risk as it allows unauthorized access and could lead to data breaches or further network compromises. Government agencies using Citrix NetScaler are particularly at risk, and timely action is essential to prevent potential exploitation. The urgency of this directive underscores the importance of maintaining up-to-date security measures in federal systems to protect sensitive information from malicious actors.

Impact: Citrix NetScaler appliances
Remediation: Agencies are required to apply the latest patches for Citrix NetScaler appliances as directed by CISA by the specified deadline. Specific patch numbers or versions were not mentioned in the article.
Read Original

Axios, a widely used HTTP client, has been compromised in a supply chain attack that affected two of its npm package versions: 1.14.1 and 0.30.4. These versions introduced a malicious dependency called 'plain-crypto-js' version 4.2.1, which was injected using the compromised credentials of the primary Axios maintainer. This incident was reported by StepSecurity, and it raises significant concerns about the security of open-source software, particularly how easily attackers can exploit trusted packages to distribute malicious code. Users and developers relying on these versions should take immediate action to mitigate potential risks. The attack serves as a reminder for the need for stringent security measures within the software supply chain.

Impact: Axios versions 1.14.1 and 0.30.4, npm package ecosystem
Remediation: Users should update to safe versions of Axios and review their dependency management practices to avoid malicious packages.
Read Original

A recently discovered vulnerability, identified as CVE-2026-20929, involves a Kerberos authentication relay attack that exploits CNAME records. This vulnerability can allow attackers to impersonate legitimate users and gain unauthorized access to sensitive systems. Organizations using Kerberos for authentication, particularly those with complex DNS configurations, are at risk. The implications are serious, as successful exploitation could lead to data breaches or unauthorized actions within an organization's network. Cybersecurity teams need to assess their systems for this vulnerability and take appropriate measures to secure their environments against potential attacks.

Impact: Kerberos authentication systems, organizations using DNS CNAME records
Remediation: Organizations should review their Kerberos configurations and DNS records, implement strict access controls, and monitor authentication logs for unusual activity. It is also recommended to apply any security patches related to Kerberos authentication as they become available.
Read Original

CareCloud, a healthcare IT firm, has reported a data breach that compromised sensitive patient information. The incident led to a network disruption lasting about eight hours, affecting the firm's ability to provide services. While the specifics of the stolen data have not been disclosed, the breach raises significant concerns over patient privacy and data security in the healthcare sector. This incident underscores the ongoing vulnerability of healthcare organizations to cyberattacks, which can jeopardize both patient trust and the integrity of healthcare systems. Stakeholders are urged to enhance their cybersecurity measures to prevent similar occurrences in the future.

Impact: Patient data, healthcare IT systems
Remediation: N/A
Read Original

A previously reported vulnerability in Fortinet's BIG-IP product, identified as CVE-2025-53521, has been reclassified from a denial-of-service (DoS) flaw to a remote code execution (RCE) vulnerability. This change indicates that the bug poses a much greater risk, allowing attackers to potentially execute arbitrary code on affected systems. Initially disclosed in October, this vulnerability is now known to be actively exploited, increasing the urgency for users to take action. Organizations using Fortinet BIG-IP devices should be especially vigilant, as this issue may compromise the security of their networks. Users are advised to implement necessary patches and monitor for unusual activity to safeguard their systems.

Impact: Fortinet BIG-IP products.
Remediation: Users should apply the latest security patches provided by Fortinet for their BIG-IP systems. Regular monitoring for unusual activity is also recommended to mitigate potential exploitation.
Read Original

A vulnerability in F5's BIG-IP software, initially categorized as a denial-of-service (DoS) issue, has been reclassified as a remote code execution (RCE) threat. This change comes after new findings revealed that attackers could exploit the flaw to execute arbitrary code on affected systems. Organizations using BIG-IP are at risk, as the vulnerability could allow unauthorized access and control over their systems. The reclassification raises concerns about the potential for severe exploitation, especially since the flaw is reportedly being actively targeted by attackers. Companies using F5 BIG-IP should take immediate action to protect their systems.

Impact: F5 BIG-IP software versions affected include various configurations that utilize the vulnerable components. Specific product versions were not detailed.
Remediation: F5 has recommended that users apply any available patches to their BIG-IP systems as soon as possible. Additionally, organizations should review their security configurations and consider implementing network segmentation to limit exposure.
Read Original
15-Year-Old strongSwan Flaw Lets Attackers Crash VPNs via Integer Underflow

Hackread – Cybersecurity News, Data Breaches, AI and More

A 15-year-old vulnerability in the strongSwan VPN software has been identified, allowing attackers to crash VPN connections through an integer underflow bug. This flaw specifically impacts the EAP-TTLS plugin and affects multiple versions of strongSwan used globally. The issue can lead to significant disruptions for users relying on these VPNs for secure communications. Organizations should be aware of this vulnerability as it poses a risk to their network stability and security. Immediate action is recommended to address this flaw and prevent potential exploitation.

Impact: strongSwan VPN software, EAP-TTLS plugin, multiple versions worldwide
Remediation: Organizations should apply relevant patches or updates to strongSwan as soon as they are available. Users are advised to review their configurations and consider alternative authentication methods if necessary.
Read Original

A serious vulnerability has been discovered in the Telegram messaging app, which can reportedly be triggered by a corrupted sticker. This flaw has been assigned a CVSS score of 9.8, indicating its severity. However, Telegram has denied the existence of this vulnerability, which raises questions about user safety. If this flaw is real, it poses a significant risk to Telegram users, as it could allow attackers to exploit the app without any user interaction, making it a no-click attack. The situation is concerning, especially for those who rely on Telegram for secure messaging.

Impact: Telegram messaging app
Remediation: N/A
Read Original
PreviousPage 82 of 215Next