Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Dolphin X is a new type of infostealer that utilizes artificial intelligence to evaluate and rank potential victims, making it easier for cybercriminals to target those most likely to yield valuable data. This AI profiling allows attackers to efficiently sift through large amounts of data to identify lucrative targets, which could include individuals or organizations with sensitive information. The implications of this development are significant, as it enhances the capabilities of cybercriminals and increases the risk for those who may be targeted. Companies and individuals should be aware of this evolving threat and take steps to protect their sensitive information from being exploited. The rise of such advanced tools underscores the need for improved cybersecurity measures across the board.

Read Original

Google has introduced a new feature for account recovery that allows users to upload a video selfie as a way to verify their identity. This option aims to enhance security by providing a more personal method of account recovery, especially for those who may not have access to traditional recovery methods like email or SMS. However, the move raises concerns about privacy and the potential risks of storing biometric data. Users need to be cautious about sharing personal information and consider the implications of having their facial data stored by a tech giant. Overall, while the feature could help some recover their accounts more easily, it also brings up important questions about data security and user privacy.

Read Original

The Python Package Index (PyPI) has implemented new security measures to protect users from potential attacks. Starting now, any new files uploaded to releases that are older than 14 days will be rejected. This change aims to prevent attackers from poisoning established releases if they gain access to a project's publishing tokens or release workflows. By enforcing this restriction, PyPI hopes to minimize the cleanup efforts required when projects are compromised. It also helps avoid confusion regarding the status of compromised releases, ensuring users can trust the integrity of the packages they are using.

Read Original

Swiss rail manufacturer Stadler is facing a significant cyber threat after the hacker group Everest demanded a ransom of 10 million Swiss francs (approximately $12.3 million). The breach occurred through compromised credentials on a data exchange platform shared with one of Stadler's suppliers. With operations spanning 16 production plants and a global workforce of over 17,100, the impact of this attack is considerable. Although Stadler confirmed receipt of the ransom demand, the company has publicly stated it will not pay the ransom. This incident raises concerns about the security of supply chain connections and the potential for sensitive data exposure in the rail manufacturing sector.

Read Original

Check Point has issued urgent security updates to address a serious authentication bypass vulnerability in SmartConsole, identified as CVE-2026-16232, which has a CVSS score of 9.3. This flaw affects both Security Management and Multi-Domain Security Management (MDSM) systems and is currently being exploited in the wild. The vulnerability allows attackers to bypass authentication, potentially granting them unauthorized access to critical management functions. Given the severity of this flaw, it's crucial for organizations using these systems to apply the updates as soon as possible to mitigate the risk of exploitation. Users should ensure they are running the latest versions to maintain the security of their environments.

Read Original
Actively Exploited

Check Point Software, an Israeli cybersecurity firm, has reported a zero-day vulnerability in its SmartConsole admin panel that is currently being exploited by attackers. This flaw allows unauthorized access to the graphical user interface, potentially leading to significant security breaches. Organizations using SmartConsole are at risk, as the vulnerability could enable attackers to manipulate settings or extract sensitive information. The firm has urged users to take immediate action to protect their systems, highlighting the urgency of the situation. It's crucial for affected users to stay informed and implement any necessary security measures to mitigate potential risks.

Read Original

A newly disclosed vulnerability in the Linux kernel, known as RefluXFS and tracked as CVE-2026-64600, allows unprivileged local users to overwrite files owned by the root user on systems using the XFS filesystem. This flaw, which has been around for nine years, can grant persistent root access to attackers on default installations of Red Hat Enterprise Linux (RHEL), Fedora Server, and Amazon Linux. Researchers from Qualys demonstrated how this vulnerability can be exploited, raising significant concerns for system administrators and users of these platforms. Given the potential for local users to gain elevated privileges, it is crucial for affected organizations to assess their systems and apply necessary mitigations to prevent unauthorized access.

Read Original

A recent study has found that two-thirds of organizations affected by ransomware attacks believe that the use of artificial intelligence tools by hackers has significantly improved the effectiveness of these attacks. This trend is concerning for cybersecurity professionals who are already struggling to defend against increasingly sophisticated threats. The study suggests that AI can help attackers automate tasks and analyze vulnerabilities more efficiently, making it harder for companies to protect their systems. As ransomware continues to evolve, organizations must adapt their defenses and strategies to counter these AI-enhanced methods. This shift highlights the ongoing arms race between cybercriminals and defenders, emphasizing the need for improved security measures.

Read Original
Actively Exploited

A Brazilian banking Trojan is currently spreading in Portugal, targeting Portuguese businesses that share the same language as the attackers. This malware is particularly dangerous as it can compromise sensitive financial information, leading to significant financial losses for companies. With the seamless communication between Brazilian hackers and their Portuguese victims, the threat level has increased. Businesses need to be vigilant about their cybersecurity practices to protect themselves from this growing menace. The situation underscores the need for enhanced security measures, particularly for financial transactions and sensitive data handling.

Read Original

Check Point has issued security updates to fix several vulnerabilities affecting its Security Management and Multi-Domain Management (MDSM) products. Among these is a serious flaw, identified as CVE-2026-16232, which has a CVSS score of 9.3 and allows attackers to bypass authentication in the SmartConsole login process. This vulnerability is particularly concerning as it is currently being exploited in the wild, meaning malicious actors can gain full administrative access to affected systems. Companies using Check Point's management products need to apply these updates promptly to protect their environments from unauthorized access. The timely response to this patch is crucial for maintaining security integrity.

Read Original

As artificial intelligence becomes more integrated into daily business operations, companies are facing challenges in managing its use, particularly with what is known as 'Shadow AI.' This refers to the AI tools and applications that employees adopt without formal approval or oversight from their organizations. The rapid adoption of these tools, often outpacing the company’s governance capabilities, raises significant security concerns. Employees are using AI for various tasks—from drafting emails to analyzing data—which can expose sensitive information or lead to compliance issues. Companies need to establish clear policies and oversight mechanisms to mitigate the risks associated with unregulated AI usage, ensuring that security and data protection measures keep up with this technological shift.

Read Original

The U.S. government has issued a warning about Iranian hackers targeting industrial control systems from companies like Siemens, Schneider, and Rockwell. The advisory highlights specific techniques used to compromise programmable logic controllers (PLCs), which are crucial for managing industrial operations. This threat is significant because it could disrupt critical infrastructure, potentially affecting manufacturing and utility services. Organizations using these ICS devices are urged to enhance their security measures to protect against these targeted attacks. The warning reflects ongoing concerns about state-sponsored cyber activities that can have real-world consequences for national security and economic stability.

Read Original

Researchers at the University of Texas at Dallas analyzed 1,646 open source Common Vulnerabilities and Exposures (CVEs) that had multiple patches. They found that in many cases, the first patch in a series did not fully address the vulnerability, leaving systems exposed until subsequent patches were applied. This issue can lead to confusion for developers and security teams, as a CVE may be marked as resolved even though the flaw remains unpatched. The study raises concerns about the effectiveness of vulnerability management in open source software and the potential risks it poses for users relying on these patches to secure their systems. It's crucial for organizations using open source components to closely monitor patch sequences and ensure all related updates are applied to avoid leaving vulnerabilities unaddressed.

Read Original

Theori tested 28 applications developed using AI coding agents from Anthropic and OpenAI to identify vulnerabilities. Surprisingly, the common security issues like SQL injection and cross-site scripting, which are often expected, were not prevalent. Instead, the AI models utilized prepared statements and Object-Relational Mappers (ORMs) effectively, reducing the risk of these traditional vulnerabilities. This research indicates that while AI can still produce vulnerabilities, the nature of these vulnerabilities may differ from conventional coding errors. As AI tools become more widespread in software development, understanding their security implications is crucial for developers and organizations to safeguard their applications.

Read Original

In a recent video, Venkata Pavan Kumar Gummadi, a Professional Software Engineer at Broadridge, discusses the importance of a defense in depth strategy for safeguarding sensitive data. He emphasizes that relying on a single security measure, such as disk encryption or data loss prevention (DLP) tools, can leave vulnerabilities that attackers may exploit. Gummadi outlines four key layers of protection that should work in tandem throughout the data lifecycle to enhance security. By classifying sensitive information like Social Security numbers, organizations can better manage and protect their data against potential breaches. This approach is crucial as cyber threats continue to evolve, making comprehensive protection essential for businesses handling sensitive information.

Read Original
PreviousPage 84 of 369Next