Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

As tax season approaches, cybercriminals are ramping up their phishing attacks, targeting individuals and businesses with a variety of scams. These attacks are designed to deliver remote monitoring and management (RMM) malware, steal credentials, and perpetrate business email compromise (BEC) schemes. Additionally, hackers are using tax-form scams to trick users into providing sensitive information. This surge in phishing attempts poses significant risks, especially for those who may be more vulnerable during the busy tax season. Users and organizations need to be vigilant and implement security measures to protect against these evolving tactics, which can lead to financial loss and identity theft.

Impact: Individuals and businesses filing taxes
Remediation: Users should verify the sender's email address, avoid clicking on suspicious links, and use multi-factor authentication for accounts. Regular software updates and security training can also help mitigate risks.
Read Original

Recent discussions have emerged around how large language models (LLMs) can inadvertently compromise access control within organizations. These models are capable of generating complex code for access control policies, such as Rego and Cedar, in just a few seconds. However, a minor oversight—like a missing condition or a fabricated attribute—can undermine the security model designed to enforce least-privilege access. This is particularly concerning for businesses that rely on strict access controls to protect sensitive data. The implications are significant, as organizations may unknowingly expose themselves to greater risks due to these automated code generation errors. As LLMs become more integrated into security processes, understanding their limitations is crucial for maintaining robust access control.

Impact: Rego, Cedar, organizational access control systems
Remediation: Organizations should review and validate any code generated by LLMs for access control policies, ensuring all conditions and attributes are accurate and align with security requirements.
Read Original

CareCloud, a healthcare IT company, is investigating a cybersecurity incident that may involve a data breach within one of its electronic health record systems. While the specifics of the breach have not been fully disclosed, the company is assessing the situation to determine the scope and impact. This incident raises concerns about the security of sensitive patient information, as breaches in healthcare can lead to significant risks for individuals, including identity theft and compromised medical records. The investigation is ongoing, and CareCloud is likely to update its clients and stakeholders as more information becomes available.

Impact: Electronic health record systems
Remediation: N/A
Read Original

A newly disclosed vulnerability in Telegram could allow attackers to execute code on users' devices without any interaction, making it a significant security risk. This flaw, identified by researcher Michael DePlante and tracked as ZDI-CAN-30207, has a CVSS score of 9.8, indicating its severity. Telegram has denied the existence of this issue, which raises concerns about user safety and device security. If confirmed, this vulnerability could affect millions of users who rely on Telegram for messaging. Users should remain vigilant and follow updates from Telegram regarding this potential threat.

Impact: Telegram messaging app
Remediation: N/A
Read Original

A recent glitch in Lloyds Banking Group's app has exposed sensitive data of nearly 448,000 customers. During a routine update, the flaw allowed unauthorized access to transaction details and personal information, raising significant concerns about data privacy. The bank has acknowledged the issue and is investigating the extent of the exposure. Customers affected by this incident may need to monitor their accounts closely for any suspicious activity. This incident underscores the risks associated with software updates and the importance of robust security measures in protecting customer data.

Impact: Lloyds Banking Group app, customer personal and transaction data
Remediation: The bank is currently investigating the issue and has not specified particular remediation steps yet.
Read Original
Dark Web Market Lists Alleged 375TB Lockheed Martin Data for $600M

Hackread – Cybersecurity News, Data Breaches, AI and More

A dark web marketplace called Threat Market is advertising a massive haul of Lockheed Martin data, claiming to have 375 terabytes of sensitive information. The alleged source of this leak is a group identifying itself as 'APT Iran.' If true, this could pose serious risks not only to Lockheed Martin but also to national security, given the company's role in defense contracts. The asking price for this data is a staggering $600 million, raising concerns about the potential for misuse. This incident underscores the ongoing threat posed by malicious actors targeting major corporations and government contractors, highlighting the need for enhanced cybersecurity measures across the industry.

Impact: Lockheed Martin data
Remediation: N/A
Read Original

A serious SQL injection vulnerability, tracked as CVE-2026-21643, has been discovered in Fortinet's FortiClient Endpoint Management Server (EMS), which manages FortiClient endpoint agents across multiple platforms. This vulnerability is currently being actively exploited, as reported by Defused Cyber, a firm that specializes in threat intelligence. Although it has not yet been listed on CISA’s Known Exploited Vulnerabilities (KEV) list, the ongoing attacks pose significant risks to organizations using FortiClient EMS. Companies should take immediate action to assess their systems and implement necessary security measures to safeguard against potential breaches. The situation emphasizes the need for vigilance in monitoring and securing endpoint management solutions.

Impact: Fortinet FortiClient Endpoint Management Server (EMS)
Remediation: Organizations should promptly review their FortiClient EMS configurations and apply any available patches or updates from Fortinet. It is also advisable to implement web application firewalls (WAFs) or other intrusion prevention systems (IPS) to help mitigate SQL injection attacks. Regular vulnerability assessments and security monitoring should be conducted to identify and remediate any potential exploitation vectors.
Read Original

The UK's National Cyber Security Centre (NCSC) has alerted organizations about a serious vulnerability in the F5 BIG-IP Access Policy Manager (APM). This flaw allows attackers to execute remote code without authentication, posing a significant risk to affected systems. Companies using F5 BIG-IP APM could be compromised if they do not take immediate action. The NCSC is urging organizations to implement mitigation measures to protect their networks. This vulnerability underscores the necessity for timely updates and vigilance in cybersecurity practices.

Impact: F5 BIG-IP Access Policy Manager (APM)
Remediation: Organizations are encouraged to apply available patches and implement mitigation strategies as outlined by F5.
Read Original

According to GitGuardian's latest report, secrets sprawl is worsening at an alarming rate. In 2025, researchers found 29 million new hardcoded secrets in public GitHub repositories, marking a 34% increase from the previous year. This surge represents the largest single-year jump ever recorded in the analysis of billions of code commits. The report indicates that security teams are struggling to keep pace with this trend, which poses significant risks for organizations as sensitive information becomes more exposed. The findings suggest that companies need to prioritize safeguarding their codebases against this growing issue to prevent potential data breaches.

Impact: Public GitHub repositories
Remediation: Organizations should implement better secret management practices and review their code for hardcoded secrets.
Read Original

The European Commission has confirmed that its cloud infrastructure supporting the Europa.eu platform was targeted in a cyberattack, which was detected on March 24. Initial investigations indicate that data was extracted from the affected websites, although there is no evidence that the Commission's internal systems were breached. This incident marks the second data breach the Commission has experienced this year, raising concerns about its cybersecurity resilience. The Commission acted quickly to contain the situation and implemented measures to protect its services and data. However, the repeated breaches prompt questions about the effectiveness of its security protocols and the potential risks to sensitive information.

Impact: Europa.eu platform, cloud infrastructure
Remediation: Risk mitigation measures were implemented to protect services and data.
Read Original

Iranian hacking groups are increasingly using high-volume cyberattacks that have a low impact but can disrupt systems and services. These attacks have been enhanced by artificial intelligence, making them more effective. Affected entities include hospitals and other critical infrastructure, which are particularly vulnerable to these tactics. This trend reflects a growing integration of digital warfare in geopolitical conflicts, posing risks not only to the targeted organizations but also to public safety and national security. As these cyber threats evolve, it becomes crucial for organizations to bolster their cybersecurity measures and stay vigilant against potential attacks.

Impact: Hospitals, critical infrastructure systems
Remediation: Organizations should enhance their cybersecurity defenses, conduct regular security assessments, and train staff on recognizing potential cyber threats.
Read Original

Apple has implemented a camera indicator light system designed to alert users when their device's camera is active. This feature is crucial as it protects against potential malware that could secretly access the camera to record without user consent. The article emphasizes that a dedicated hardware indicator light is more secure than a software-rendered display indicator, as it is physically connected to the camera and cannot be manipulated by malicious software. This distinction is important for users who rely on their devices for privacy and security. Overall, the design aims to enhance user awareness and control over their device's camera usage.

Impact: Apple devices with camera functionality
Remediation: N/A
Read Original

F5 Networks has escalated the severity of a vulnerability in its BIG-IP Application Policy Manager (APM) from a denial-of-service issue to a critical remote code execution flaw. This vulnerability allows attackers to exploit unpatched devices and deploy webshells, which can give them unauthorized access to systems. Organizations using affected versions of BIG-IP are urged to apply the necessary patches immediately to prevent potential breaches. The exploitation of this flaw poses a significant risk, especially for businesses relying on BIG-IP for application delivery and security. With reports of active attacks already in progress, it is crucial for users to take swift action to secure their environments.

Impact: F5 BIG-IP APM
Remediation: Users should patch their systems to the latest version as specified by F5 to mitigate this vulnerability.
Read Original

Google has rolled out new location privacy features in the Android 17 Beta 3, allowing users better control over their precise location data. A key addition is the location button, which enables one-time access to location information for tasks like finding nearby places or tagging content, without the need for continuous tracking. This update aims to minimize data collection practices and enhance user privacy while providing developers with the tools necessary to design safer applications. This change is particularly relevant as location data can often be sensitive, and users are increasingly concerned about how their information is used. By implementing these features, Google is responding to user demands for greater transparency and control over personal data.

Impact: Android 17 Beta 3
Remediation: N/A
Read Original

Researchers from watchTowr and Defused have discovered that attackers are exploiting CVE-2026-3055, a serious vulnerability affecting Citrix NetScaler. This flaw allows unauthorized access to systems that utilize the NetScaler product, which is commonly used for application delivery and load balancing. Organizations using NetScaler are at risk, as the vulnerability is currently being actively targeted in the wild. Companies should be aware of this threat and take immediate action to protect their systems, as the consequences of exploitation could lead to significant data breaches and operational disruptions. It's crucial for affected users to stay informed and apply any available patches as soon as possible.

Impact: Citrix NetScaler products, specifically versions affected by CVE-2026-3055.
Remediation: Organizations should apply the latest security patches provided by Citrix for NetScaler. Regularly check for updates and ensure that all systems are up to date. Additionally, consider implementing network segmentation to limit exposure.
Read Original
PreviousPage 83 of 215Next