Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Researchers have discovered a new software supply chain attack called SleeperGem, which targets the Ruby ecosystem. Three malicious RubyGems packages, specifically git_credential_manager (versions 2.8.0 to 2.8.3) and Dendreo (versions 1.1.3 and 1.1.4), were published on July 18, 2026. These rogue gems are designed to serve additional malicious payloads, putting developers who use these packages at risk. The attack could lead to unauthorized access and further exploitation of developer machines. It's crucial for developers to avoid these specific versions and to ensure their systems are secure from such threats.

Read Original

A recent analysis has raised concerns about the security of AI coding assistants, which are increasingly used by developers to generate code. Researchers found that these tools can be influenced by maliciously altered training data, leading them to produce insecure code when prompted in specific ways. This risk is particularly alarming as developers may unknowingly introduce vulnerabilities into their projects by relying on compromised suggestions. The potential for backdoored code completions can have serious implications for software security, affecting both the developers who use these tools and the end users of their applications. As AI integration in coding becomes more common, addressing these vulnerabilities is crucial for maintaining software integrity and security.

Read Original

According to Mozilla's report, 'The State of Open Source AI 2026', almost half of open-source AI projects fail to make it to production. As organizations increasingly adopt open models, challenges related to deployment, governance, and operational tools are becoming more pronounced. The report emphasizes that without adequate investment in the necessary infrastructure and tools, the AI landscape risks becoming dominated by restrictive, closed models. This situation is concerning because it may limit innovation and accessibility in AI technologies, which are critical for various sectors. The findings suggest that stakeholders need to prioritize these areas to ensure open-source AI can thrive and be effectively utilized.

Read Original

F5 has released important updates to address a critical vulnerability in NGINX, identified as CVE-2026-42533. This flaw allows attackers to send specially crafted HTTP requests that can cause a heap buffer overflow in the NGINX worker process. As a result, this vulnerability could lead to the crashing or restarting of the worker, effectively denying service to legitimate users. The issue affects versions of NGINX prior to 1.30.4 and 1.31.3, as well as NGINX Plus versions before 37.0.3.1. Users running these versions should upgrade immediately to protect their systems from potential exploitation.

Read Original
Actively Exploited

The latest Malware Newsletter from Security Affairs includes several notable malware threats. One of these is CrashStealer, a C++ infostealer for macOS that masquerades as a crash reporter, targeting users to extract sensitive information. Another threat, Lucide Proxy, is exploiting student web proxies to create DDoS bots, potentially impacting educational institutions. Additionally, the AsyncAPI npm organization has been compromised, affecting about 2 million weekly downloads, which raises concerns for developers relying on these packages. Lastly, OkoBot is a sophisticated malware framework specifically designed to target cryptocurrency users, highlighting the ongoing risks in the digital currency space. These developments illustrate the evolving tactics of cybercriminals and the need for users and organizations to stay vigilant.

Read Original

The latest Security Affairs newsletter reports on two significant cybersecurity issues. First, OpenSSL has addressed a vulnerability known as the HollowByte memory exhaustion bug, which could lead to service disruptions. Users of OpenSSL, particularly those running servers or applications that rely on this library, should ensure they update to the latest version to avoid potential downtime or denial-of-service attacks. Additionally, researchers have discovered Daxin, a malware that has been linked to China, still active on a manufacturer's network despite being over a decade old. This finding raises concerns about the long-term persistence of such malware and its ability to evade detection. Companies must remain vigilant and conduct thorough network security assessments to identify and eliminate such threats.

Read Original
Actively Exploited

Hackers are exploiting the update mechanism of the ViPNet software, a private networking solution, to target Russian government agencies and other organizations. This sophisticated attack has raised concerns about the security of critical infrastructure in Russia, as ViPNet is widely used by various state entities. Researchers have identified the malicious activity, which indicates a significant threat to the integrity of communications within these agencies. The ability to manipulate software updates poses serious risks, as it could allow attackers to gain unauthorized access or disrupt operations. This incident underscores the need for heightened security measures and vigilance among users of ViPNet and similar products.

Read Original

A new threat actor, identified as UTA0533, has been exploiting zero-day vulnerabilities in SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances before these issues were publicly disclosed. This activity has been tracked since June 22, 2026, and was uncovered during an incident response investigation by cybersecurity firm Volexity. The attackers gained root access to systems, raising serious concerns about the security of organizations using these VPN appliances. This incident is particularly alarming as it highlights the potential risks associated with undisclosed vulnerabilities, which can be exploited by malicious actors before users have a chance to protect themselves. Organizations using SonicWall SMA appliances should be vigilant and prepare for potential impacts from these vulnerabilities.

Read Original

Last week, two high severity vulnerabilities were discovered in WordPress that require immediate attention from users and site administrators. The 7.0.2 security release addresses one critical issue along with a high severity problem, both of which could potentially expose websites to serious risks. WordPress users are urged to update their installations promptly to protect against possible exploitation. Additionally, there was a mention of an open-source research agent that poses risks when it interacts with live cloud accounts, emphasizing the importance of securing credentials. These vulnerabilities serve as a reminder of the ongoing need for vigilance in website security.

Read Original

Recent discoveries have revealed serious vulnerabilities in WordPress, specifically two flaws tracked as CVE-2026-63030 and CVE-2026-60137. These vulnerabilities, known as wp2shell, can be exploited by attackers to execute code remotely without needing authentication. This means that anyone with these vulnerabilities can potentially take control of a WordPress site, particularly those running default configurations. The availability of public proof-of-concept exploits raises the urgency for website owners to address these flaws promptly, as they are now at greater risk of being targeted by malicious actors. It’s critical for users to be aware of these vulnerabilities and take immediate action to secure their sites.

Read Original

7-Zip has released version 26.02 to address a serious remote code execution (RCE) vulnerability. This flaw allows attackers to execute malicious code on users' systems if they open specially crafted compressed files. Users of 7-Zip should update to the latest version to protect themselves from potential exploitation. The vulnerability is particularly concerning as it could be exploited easily by tricking users into opening harmful files. Keeping software up to date is crucial in maintaining security and preventing such attacks.

Read Original

Okta has reported a new vulnerability in OpenSSL, dubbed HollowByte, which allows remote attackers to exploit a flaw that can lead to memory exhaustion on servers. This specific vulnerability is only 11 bytes long, and when exploited, it can cause a server to allocate up to 131 KB of memory. As a result, this could trigger denial-of-service attacks, rendering the affected servers unable to respond to legitimate requests. Organizations using affected versions of OpenSSL should prioritize patching this vulnerability to protect their systems from potential exploitation. The risk is significant, as attackers can exploit this flaw without needing authentication, making it easier for malicious actors to disrupt services.

Read Original

Recent vulnerabilities known as 'wp2shell' have been discovered in WordPress Core, allowing remote code execution. These flaws are particularly concerning because public exploits have now been released, meaning attackers can actively take advantage of them. Administrators of WordPress sites need to act quickly to patch their systems to protect against potential breaches. The urgent nature of this situation is underscored by the fact that these vulnerabilities can compromise the security of websites, putting sensitive data at risk. Users of WordPress should ensure they are running the latest version to mitigate these risks.

Read Original

WordPress has released a security update, version 7.0.2, to address two significant vulnerabilities that pose risks to users. The first vulnerability, identified as CVE-2026-60137, is a SQL injection issue that could allow attackers to manipulate databases. The second, also CVE-2026-60137, relates to a REST API batch-route confusion that could lead to remote code execution, potentially giving attackers full control over affected systems. The vulnerabilities affect WordPress version 6.9 and earlier. Users are strongly advised to update their installations immediately to mitigate the risks associated with these security flaws.

Read Original

Zhuoying Chen, 27, and Haojie Zhang, 38, have been charged in New York for allegedly laundering $43 million that was obtained through various investment scams. The two men are accused of operating a network that funneled this significant sum of money to China, raising concerns about the scale and sophistication of financial fraud schemes. The case illustrates how cybercriminals are increasingly using complex methods to hide illicit funds, which can undermine legitimate financial systems. Authorities are focusing on these activities to combat financial crimes and protect potential victims from similar scams. The investigation underscores the ongoing challenges law enforcement faces in tracking and prosecuting financial fraud linked to cyber activities.

Read Original
PreviousPage 95 of 369Next