Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A serious vulnerability in Fortinet's FortiClient EMS platform, identified as CVE-2026-21643, is currently being exploited by attackers. This flaw, which has a CVSS score of 9.1, allows for remote code execution through SQL injection. Researchers from Defused have reported active exploitation of this vulnerability, posing significant risks to organizations using FortiClient EMS. Companies are urged to take immediate action to protect their systems, as the potential for unauthorized access and control could lead to severe consequences. It is essential for affected users to stay informed and apply any available patches promptly to mitigate the risks associated with this flaw.

Impact: Fortinet FortiClient EMS platform
Remediation: Organizations should apply patches provided by Fortinet for the CVE-2026-21643 vulnerability as soon as they are available. Additionally, users should review their SQL database configurations and implement input validation to protect against SQL injection attacks.
Read Original

Microsoft has withdrawn the KB5079391 update for Windows 11 after users reported installation issues resulting in error code 0x80073712. This non-security preview update was intended to enhance the operating system but instead caused problems for those attempting to install it. The company is now investigating the source of the error, which is affecting users who downloaded this particular update. For many, this means they may have to wait longer for fixes or improvements that were supposed to come with the update. It's a reminder of the potential complications that can arise from software updates and the importance of monitoring system changes closely.

Impact: Windows 11, KB5079391 update
Remediation: Microsoft has pulled the KB5079391 update and is investigating the issue.
Read Original

The UK Information Commissioner’s Office (ICO) has fined Birmingham-based company TMAC £100,000 for making nuisance calls. This fine was imposed after the ICO found that TMAC was responsible for making a significant number of unsolicited calls, which harassed individuals and violated privacy regulations. The ICO's action highlights the ongoing battle against spam calls that often target vulnerable populations. Such fines are part of a broader effort to hold companies accountable for their practices and protect consumers from unwanted communications. This incident serves as a reminder for businesses to comply with regulations regarding direct marketing and for consumers to stay vigilant against potential scams.

Impact: Nuisance calls, consumer privacy
Remediation: Companies should ensure compliance with privacy regulations regarding unsolicited calls.
Read Original

The European Commission has confirmed a data breach affecting its AWS infrastructure, compromising sensitive information. While specific details regarding the extent of the breach remain limited, the incident raises concerns about the security of cloud services used by governmental bodies. The breach could potentially expose personal data and operational information, impacting trust in the Commission's digital systems. This incident highlights the ongoing risks associated with cloud computing, especially for entities dealing with sensitive or confidential data. Users and stakeholders are advised to remain vigilant and review their cybersecurity protocols in light of this breach.

Impact: AWS infrastructure used by the European Commission
Remediation: N/A
Read Original

The FBI has confirmed that Iranian hackers successfully targeted the personal email account of Kash Patel, the former Director of the U.S. National Counterterrorism Center. While the agency noted that the information accessed in the hack is old, the incident raises concerns about the security of personal communications for high-profile government officials. In response to this breach, the U.S. government has announced a reward of up to $10 million for information leading to the identification and capture of those responsible for the attack. This move underscores the ongoing risks posed by state-sponsored hacking and the importance of safeguarding sensitive information, particularly for individuals in prominent positions. The incident serves as a reminder for both officials and the public to remain vigilant about cybersecurity practices.

Impact: Kash Patel's personal email account, possibly related government communications
Remediation: N/A
Read Original

A serious vulnerability in Fortinet's FortiClient EMS platform is currently being exploited by attackers, according to the threat intelligence firm Defused. This flaw poses significant risks to organizations using the affected software, as it allows unauthorized access and potential control over their systems. Companies that rely on FortiClient EMS for endpoint management and security should urgently assess their systems to mitigate the risk. The ongoing exploitation of this vulnerability underscores the need for timely updates and security patches to protect sensitive data and maintain system integrity. Users are advised to follow best practices for cybersecurity and monitor for any unusual activities.

Impact: Fortinet FortiClient EMS platform
Remediation: Organizations should apply the latest security patches from Fortinet and ensure their systems are updated to the most recent versions to mitigate this vulnerability.
Read Original

A Russian-linked hacking group known as TA446 is actively targeting iPhone users through a new phishing campaign that employs the DarkSword iOS exploit kit. These attacks involve sending malicious emails designed to compromise iOS devices, putting users' personal information at risk. The group, also referred to as SEABORGIUM and ColdRiver, has been noted for its sophisticated tactics in the past. This wave of phishing emphasizes the increasing dangers that smartphone users face, especially as attackers refine their methods to bypass security measures. As these campaigns evolve, it’s crucial for iPhone users to remain vigilant about suspicious emails and links.

Impact: iPhone users, iOS devices
Remediation: Users should avoid clicking on links or downloading attachments from unknown or suspicious emails. Keeping iOS devices updated to the latest version may help mitigate vulnerabilities.
Read Original

The European Commission has confirmed that its Europa.eu web platform experienced a data breach following a cyberattack attributed to the ShinyHunters extortion gang. This group is known for targeting various organizations and leaking sensitive information online. The breach raises concerns about the security of personal data held by the European Commission, which could potentially affect thousands of users who interact with the platform. The incident highlights ongoing cybersecurity challenges faced by governmental institutions in safeguarding sensitive information. As investigations continue, it remains crucial for affected individuals to stay informed about potential fallout and take necessary precautions to protect their data.

Impact: Europa.eu web platform
Remediation: N/A
Read Original

Researchers from the University of Oxford and the AI Security Institute have created a benchmark called SandboxEscapeBench. This tool tests whether AI agents can break free from their container sandboxes, which are used to safely run code and access system resources without risking the host system. The benchmark specifically evaluates scenarios where an AI agent has shell access, aiming to determine if it can escape the confines of its sandbox. This research is significant because if AI agents can escape, they might pose risks to the systems they were intended to protect. Understanding these vulnerabilities is crucial for developers and organizations that rely on AI technologies.

Impact: AI agents operating within container sandboxes
Remediation: Implement stricter access controls and monitoring for AI agents within sandboxes
Read Original
Actively Exploited

The latest Malware newsletter from Security Affairs reports on several significant cybersecurity threats. One notable incident involves new malware specifically targeting users of Cobra DocGuard software, potentially compromising sensitive data. Additionally, Iranian cyber actors have been using Telegram as a command and control channel to distribute malware to predetermined targets, raising concerns about state-sponsored cyber activities. The newsletter also discusses the Trivy supply chain attack, which has now expanded to include compromised Docker images, putting many containerized applications at risk. Lastly, a new malware called VoidStealer has been identified, which manipulates Chrome debugging tools to extract user information. These developments highlight ongoing vulnerabilities in software and the tactics employed by cybercriminals and state actors alike.

Impact: Cobra DocGuard software, Docker images, Google Chrome
Remediation: Users of affected software should update to the latest versions and apply security patches as they become available. It's also recommended to monitor network traffic for unusual activity and to use security tools that can detect and block malware.
Read Original

In a recent cybersecurity incident, the hacking group ShinyHunters has claimed responsibility for breaching a European Commission group linked to Iran, known as Handala. This attack has raised concerns about the security of sensitive information and the potential implications for international relations. Additionally, the group reportedly hacked FBI Director Kash Patel’s personal data, which could expose vulnerabilities in U.S. federal cybersecurity measures. The incidents underline the ongoing risks associated with state-sponsored hacking and the need for improved defenses against such threats. As these attacks come to light, organizations and governments may need to reassess their cybersecurity protocols to protect against similar intrusions in the future.

Impact: European Commission, Handala group, FBI Director Kash Patel
Remediation: Organizations should review and strengthen their cybersecurity measures, including implementing advanced threat detection and response strategies.
Read Original

At the BSides SF 2026 hacker conference, a researcher warned that Software as a Service (SaaS) and cloud assets are increasingly vulnerable to identity-based ransomware attacks. This type of attack exploits weaknesses in identity management systems, allowing attackers to gain unauthorized access and encrypt critical data. Organizations that rely on cloud services for their operations, especially those with inadequate security measures in place, are at significant risk. The researcher emphasized that as more businesses transition to these platforms, the need for robust identity protection becomes essential. Companies should prioritize enhancing their identity security protocols to mitigate these risks and protect sensitive customer information.

Impact: SaaS platforms, cloud services
Remediation: Enhance identity security protocols, implement two-factor authentication, conduct regular security assessments
Read Original

At the RSAC 2026 conference, researchers discussed the emergence of Shai-Hulud worms, which have taken advantage of automatic updates in open-source software repositories. They warned that these types of supply-chain attacks may become more common, posing significant risks to software integrity and security. This could affect a wide range of organizations that rely on open-source software for their operations. The implications are serious, as attackers could potentially infiltrate systems through seemingly legitimate software updates, compromising sensitive data and systems. Companies using open-source solutions need to be vigilant and implement stricter security measures to protect against these evolving threats.

Impact: Open-source software repositories, automatic update systems
Remediation: Implement stricter security measures for software updates, conduct regular audits of dependencies
Read Original
ShinyHunters Claims 350GB Data Breach at European Commission

Hackread – Cybersecurity News, Data Breaches, AI and More

ShinyHunters, a notorious hacking group, claims to have breached the European Commission's systems, resulting in the leak of 350GB of sensitive data. This incident raises significant concerns about the security of governmental data and the potential implications for privacy and national security. The European Commission is currently investigating the breach, but as of now, there has been no independent verification of ShinyHunters' claims. Such a large data leak could expose confidential communications and personal information, which might lead to further cyber threats or exploitation. The situation underscores the need for robust cybersecurity measures within governmental organizations to protect against such attacks.

Impact: European Commission systems, potentially including confidential communications and personal data
Remediation: N/A
Read Original

Iranian hackers known as the Handala Hack Team have breached the personal email account of Kash Patel, the director of the FBI. They leaked various sensitive photos and documents online, claiming that Patel is now among their list of successful targets. This incident raises concerns about the security of personal email accounts for high-ranking officials and the potential for sensitive information to be misused. The breach not only affects Patel personally but also poses broader implications for national security, as it demonstrates the vulnerability of even top-tier officials to cyberattacks. Such incidents can undermine public trust in the security measures protecting important government figures and their communications.

Impact: Kash Patel's personal email account
Remediation: N/A
Read Original
PreviousPage 84 of 215Next