Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Attackers have hacked Trivy, an open-source security tool, and released malicious versions of the software. This incident raises concerns as Mandiant warns that it could affect up to 10,000 downstream users who rely on Trivy for security assessments. The presence of compromised versions may lead to a significant rise in extortion attempts against these users. The situation emphasizes the risks associated with using open-source tools, particularly when they become targets for malicious actors. Organizations that use Trivy need to be vigilant and assess their security protocols to mitigate potential fallout.

Impact: Trivy security tool and its users
Remediation: Organizations should cease using the compromised versions of Trivy, conduct security assessments, and monitor for any unusual activity related to their systems.
Read Original

In December 2025, Poland experienced a significant cyberattack that targeted its energy system, leading to widespread disruptions. The attack is believed to have originated from Russia, raising concerns about geopolitical tensions and the security of critical infrastructure. This incident is part of a broader surge in cyberattacks affecting Poland, indicating a troubling trend in cybersecurity threats faced by the nation. As a result, the energy sector, crucial for both public services and economic stability, is now at heightened risk. The implications of these attacks extend beyond immediate operational disruptions, as they could impact national security and public confidence in essential services.

Impact: Poland's energy sector
Remediation: N/A
Read Original

A new hacking group known as Nasir Security, believed to be linked to Iran, has launched cyberattacks against various energy sector organizations in the Middle East. These attacks come amid rising geopolitical tensions, raising concerns about the security of critical energy infrastructure in the region. The targeted firms have not been specifically identified in the report, but the implications are significant, as energy companies are vital to national economies and security. Experts warn that such operations could disrupt energy supplies and have broader economic impacts, emphasizing the need for enhanced cybersecurity measures within this sector. Companies in the energy sector should be vigilant and bolster their defenses against potential threats from this group.

Impact: Energy sector organizations in the Middle East
Remediation: Companies should enhance their cybersecurity measures and remain vigilant against potential threats.
Read Original

A North Korean cyber operation known as WaterPlum has been using malicious Visual Studio Code (VS Code) projects to spread a new strain of malware called StoatWaffle since December. This operation is part of a broader campaign referred to as Contagious Interview. Researchers from The Hacker News reported that these infected projects are designed to trick users into downloading the malware, potentially compromising their systems. This tactic highlights the growing trend of using legitimate software tools to deliver malicious payloads, which can lead to significant security risks for developers and organizations relying on popular coding platforms. Users of VS Code should be cautious and ensure they are downloading extensions and projects from reputable sources to avoid falling victim to such attacks.

Impact: Visual Studio Code projects, StoatWaffle malware
Remediation: Users should only download extensions and projects from trusted sources and regularly update their software to mitigate risks.
Read Original

Mazda Motor Corporation has confirmed a data breach that involved the compromise of 692 records containing information about employees and business partners. This incident occurred in December and raises concerns about the security of sensitive data within the automotive industry. While Mazda has not disclosed specific details about how the breach happened, the exposure of such records can lead to identity theft or unauthorized access to company resources. Companies like Mazda must ensure they have strong security measures in place to protect personal information, as breaches can damage trust and reputation. Customers and partners may want to be vigilant about potential phishing attempts or other fraudulent activities that could arise from this incident.

Impact: Employee and business partner data
Remediation: N/A
Read Original
FBI Warns of Iran’s Handala Hack Group Using Fake Apps to Spy on Windows Users

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

The FBI has issued a warning about the Handala Hack Group, which has ties to Iran and is targeting Windows users by distributing fake versions of popular messaging apps, WhatsApp and Telegram. These counterfeit applications are designed to spy on users and potentially steal sensitive information. The attackers are using social engineering tactics to trick individuals into downloading the malicious software, which can lead to significant privacy breaches. This situation is particularly concerning as it underscores the risks associated with downloading apps from unofficial sources. Users are advised to only download applications from trusted sources and to remain vigilant about the permissions they grant to software.

Impact: Windows operating systems, WhatsApp, Telegram
Remediation: Users should only download applications from official sources and review app permissions carefully.
Read Original

The Silver Fox cyber campaigns have shifted tactics from using tax-related lures to employing WhatsApp-style stealers that combine espionage with phishing. This change indicates a broader strategy where attackers are not only targeting financial information but also attempting to extract sensitive data through social engineering techniques. The campaigns are designed to trick users into providing personal information, making them vulnerable to further exploitation. This shift in method could impact various sectors, particularly those relying on mobile communication platforms. Researchers are urging users to be cautious and verify the authenticity of messages, especially those asking for sensitive information.

Impact: WhatsApp, mobile communication platforms
Remediation: Users should verify the authenticity of messages before providing personal information and remain vigilant against phishing attempts.
Read Original

The U.S. Treasury Department is seeking public input on the potential expansion of cyber coverage within the Terrorism Risk Insurance Act (TRIA) established in 2002. This program currently provides financial assistance for insurance claims related to terrorist attacks, but the Treasury is considering whether it should also include cyber incidents. As cyber threats continue to increase and evolve, there is a growing concern about how these risks are insured. The public comment period allows stakeholders, including insurers, businesses, and cybersecurity experts, to voice their opinions on this critical issue. The outcome could significantly impact how cyber risks are managed and insured in the future, especially for organizations vulnerable to cyberattacks.

Impact: N/A
Remediation: N/A
Read Original

Citrix has issued an urgent warning regarding a critical vulnerability found in its NetScaler products. This flaw allows attackers without authentication to access sensitive data from the device's memory. Organizations using affected NetScaler appliances are at risk of data breaches that could expose confidential information. Citrix is urging all users to apply patches immediately to secure their systems. Addressing this vulnerability is crucial to prevent potential exploitation, which could lead to severe security incidents.

Impact: Citrix NetScaler products
Remediation: Users should apply the latest patches provided by Citrix as soon as possible.
Read Original

QualDerm Partners, a U.S.-based healthcare management firm, experienced a significant data breach in December 2025 that impacted over 3.1 million individuals. Hackers gained unauthorized access to the company's internal systems, compromising sensitive personal information, medical records, and health insurance details. This incident raises serious concerns about patient privacy and the security of healthcare data. Those affected may face risks such as identity theft or misuse of their medical information. The breach underscores the ongoing vulnerability of healthcare organizations to cyberattacks, emphasizing the need for stronger security measures to protect patient data.

Impact: Personal information, medical records, health insurance data of over 3.1 million individuals
Remediation: N/A
Read Original

The article discusses the challenges organizations face with fragmented identity systems that have become increasingly problematic due to the introduction of AI agents. Unlike human workers, AI agents operate continuously and unpredictably, which can lead to security gaps that are difficult to manage. CEO Ev Kontsevoy of Teleport emphasizes that traditional security measures may not be sufficient to handle these non-deterministic actors. This shift in how work is done raises concerns about the effectiveness of existing identity management systems in protecting against unauthorized access. As AI continues to evolve, organizations need to rethink their security strategies to address these new vulnerabilities and ensure that their systems can handle the complexities introduced by AI.

Impact: Identity management systems, AI agents, organizational security protocols
Remediation: Organizations should reassess and update their identity management systems to enhance security against AI-driven operations.
Read Original

The 'Ghost Campaign' is a new attack targeting users of the npm package manager. Attackers are creating fake install logs to disguise their malicious activity, which includes stealing sudo passwords and deploying Remote Access Trojans (RATs). These RATs are designed to loot cryptocurrency and sensitive data from affected systems. Developers and users of npm packages should be particularly vigilant, as the campaign exploits trust in the package manager system to facilitate these attacks. The potential fallout includes significant financial loss and compromised user data, making it crucial for users to be cautious when installing packages and to verify their sources.

Impact: npm packages, sudo passwords, cryptocurrency wallets
Remediation: Users should verify the sources of npm packages and ensure they are installing from trusted repositories. Regularly updating passwords and using two-factor authentication can help mitigate risks.
Read Original

The article discusses the limitations of multi-factor authentication (MFA) in securing user sessions against attacks. It explains that even if users pass MFA checks, attackers can still hijack authentication tokens and bypass identity verification. Specops Software advocates for a Zero Trust approach, which requires organizations to continuously verify both the identity of users and the health of their devices. This method is crucial because it helps prevent unauthorized access and ensures that not just any authenticated user can gain entry to sensitive systems. The piece emphasizes the need for companies to adopt these security measures to better protect themselves from potential breaches.

Impact: N/A
Remediation: Adopt a Zero Trust security model that verifies user identity and device health continuously.
Read Original
Actively Exploited

The Lapsus$ hacking group has reportedly breached AstraZeneca, gaining access to internal code repositories, employee credentials, and sensitive employee data. This incident raises significant concerns about the security of private information and proprietary code within the pharmaceutical industry, especially given AstraZeneca's role in vaccine development. If the claims are verified, it could lead to serious implications for the company's operations and trustworthiness in handling personal and sensitive data. Companies like AstraZeneca must enhance their cybersecurity measures to protect against such targeted attacks, which are becoming increasingly common in various sectors.

Impact: AstraZeneca internal code repositories, employee credentials, employee data
Remediation: Companies should review and strengthen their cybersecurity protocols, including employee training on phishing and credential management, and implement more stringent access controls.
Read Original

Infinite Campus, a popular student information system used by K-12 schools, has alerted its customers about a data breach after a group known as ShinyHunters claimed to have stolen sensitive information. The attackers reportedly attempted to extort Infinite Campus, raising concerns about the safety of student data and the potential for further exploitation. Schools relying on this system could be at risk of having personal information of students and staff compromised. As of now, it's unclear what specific data has been accessed and how many users are affected. This incident highlights the ongoing challenges educational institutions face in protecting their systems from cyber threats.

Impact: Infinite Campus K-12 student information system
Remediation: Customers are advised to monitor their accounts for suspicious activity and follow best practices for data protection.
Read Original
PreviousPage 91 of 215Next