Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A new Russian-speaking hacking group known as UAT-11795 is targeting organizations in the United States and Europe. This group is using innovative malware tools, specifically the Starland Remote Access Trojan (RAT) built with Python and the PowerShell-based WLDR agent, which operates solely in memory. These tools are designed to evade detection through encrypted communications and a unique execution environment. The emergence of UAT-11795 raises concerns for businesses and government entities, as their tactics could lead to significant data breaches or system compromises. As cyber threats continue to evolve, organizations need to be vigilant and enhance their security measures to defend against such sophisticated attacks.

Read Original

According to the 2026 Cybersecurity Hygiene Report, a significant concern for small and medium-sized businesses (SMBs) is the use of unauthorized AI tools by employees. The report reveals that 64% of employees engage with these tools, leading to an increase in what's called 'shadow AI.' This practice can create visibility gaps within organizations, making it harder for IT departments to monitor and secure sensitive data. As employees turn to unsanctioned applications, the risk of data breaches and compliance issues rises. Companies need to address these behavioral risks by implementing clear policies and training to ensure that employees understand the potential dangers of using unapproved technology.

Read Original

Ernst & Young (EY) has reported a data breach stemming from a compromised third-party IT support ticket system. This breach potentially exposed sensitive client documents and tax information, raising significant concerns about data security for affected clients. The attackers gained access to a platform used by EY's IT teams to manage support requests, indicating a serious vulnerability in the handling of third-party services. As a result, clients may need to monitor their accounts for suspicious activity and consider taking additional security measures. This incident serves as a reminder for companies to thoroughly vet third-party vendors and ensure robust security practices are in place.

Read Original

A serious vulnerability has been discovered in the WordPress core that allows unauthenticated attackers to execute code on affected sites. This flaw impacts any WordPress installation running versions 6.9 and 7.0, even those without any plugins installed. The issue was identified by Adam Kues from Assetnote, and WordPress has since addressed it with updates 6.9.5 and 7.0.2, which were released on Friday. These updates include a feature called forced updates to help secure sites against this vulnerability. It's crucial for WordPress users to ensure they are running the latest version to protect their sites from potential exploitation.

Read Original

The article discusses the inadequacy of measuring cybersecurity effectiveness solely by block rates of known-bad messages. It argues that just because a system can block certain threats does not mean it is fully prepared to detect and respond to all potential attacks. This is a significant point for organizations relying on these metrics, as it may give a false sense of security. The piece emphasizes the need for a deeper understanding of detection capabilities rather than just focusing on how many threats are blocked. By doing so, organizations can better assess their true security posture and improve their defenses against evolving threats.

Read Original

Abbott Laboratories is currently investigating two cybersecurity incidents that have raised concerns about the security of its internal systems. The first incident involves unauthorized access to legacy Exact Sciences systems within its Cancer Diagnostics division. The second incident pertains to claims that attackers breached its LabCentral portal and may have stolen sensitive company data. These incidents could potentially impact patient diagnostics and data integrity, making it crucial for Abbott to address these security breaches promptly. The company has not yet disclosed the extent of the breaches or the specific data that may have been compromised, which adds to the urgency of their investigation.

Read Original

A recently discovered vulnerability in OpenSSL, dubbed the HollowByte flaw, can cause unpatched servers to reserve up to 131 KB of memory for a tiny 11-byte TLS request that never arrives. This issue can lead to a denial-of-service condition, where the server's memory is tied up until the process is restarted. The problem was identified by Okta's Red Team, which reported it without a CVE or formal advisory. OpenSSL issued a fix for this vulnerability in June, but the lack of documentation means many users may remain unaware of the risk. As a result, organizations running affected OpenSSL versions should ensure they apply the update to avoid potential service disruptions.

Read Original
Actively Exploited

Recent reports indicate that the Inc ransomware has exploited two zero-day vulnerabilities found in SonicWall's mobile access appliances. When combined, these vulnerabilities grant attackers root-level access, potentially allowing them to take full control of affected systems. This situation is particularly concerning for organizations that rely on SonicWall for secure remote access, as it could lead to significant data breaches or system compromises. Users and companies using SonicWall's mobile access appliances need to be aware of this threat and take immediate action to protect their systems. The exploitation of these vulnerabilities underscores the necessity for timely software updates and security measures.

Read Original

Researchers have uncovered seven malicious npm packages that are part of an attack targeting the Vite frontend framework. This operation, named ViteVenom by Checkmarx, is associated with a broader campaign known as ChainVeil, which employs a complex blockchain-based command-and-control system. The packages are designed to deliver a Remote Access Trojan (RAT), posing significant risks to developers using Vite. This type of supply chain attack can lead to unauthorized access to systems and sensitive data. Developers and organizations relying on Vite need to be vigilant and remove any affected packages to protect their environments.

Read Original

A newly discovered vulnerability known as HollowByte poses a significant risk to OpenSSL servers by allowing unauthenticated attackers to create a denial-of-service (DoS) condition with a payload as small as 11 bytes. This flaw can lead to excessive memory consumption on affected servers, potentially causing them to crash or become unresponsive. The issue affects various OpenSSL implementations, which are widely used for secure communications on the internet. As the vulnerability is easy to exploit, it raises concerns for organizations relying on OpenSSL for their security infrastructure. Companies using OpenSSL should prioritize patching and implementing security measures to mitigate the risks associated with this vulnerability.

Read Original

Nichirei, one of Japan's largest food companies, has experienced a significant cyberattack that has disrupted its logistics and shipment operations. The company is working to gradually restore its services after the attack, which has raised concerns about the impact on food supply chains. Founded in 1942 and based in Tokyo, Nichirei is widely recognized for its frozen food products and operates globally through numerous subsidiaries. As the incident unfolds, it underscores the vulnerabilities that large organizations face in today’s digital landscape, particularly those in critical sectors like food supply. This incident serves as a reminder for companies to bolster their cybersecurity measures to protect against potential disruptions.

Read Original
Actively Exploited

The article discusses the rising concerns around AI fraud and deepfakes, which pose significant risks to businesses across various sectors. These attacks often involve manipulating audio or video to impersonate individuals, potentially leading to financial losses and reputational damage. To combat these threats, it's crucial for organizations to foster collaboration among different departments, including security, finance, HR, and legal. This approach ensures a well-rounded defense against the multifaceted nature of these cyber threats. As AI technology continues to evolve, companies must stay vigilant and proactive in their security measures to protect against these sophisticated scams.

Read Original

The article discusses the risks associated with AI models that are allowed to interpret and execute commands without adequate oversight. This blind trust in AI can lead to significant cybersecurity vulnerabilities, as there is a lack of human intervention to catch errors or malicious actions. The implications are serious, as organizations may unknowingly allow AI to make decisions that compromise their security. As AI systems become more integrated into business operations, the need for effective monitoring and control mechanisms becomes crucial to prevent potential exploitation. This situation raises concerns about how companies are managing AI technologies and ensuring they do not become a liability.

Read Original
Critical
The Good, the Bad and the Ugly in Cybersecurity – Week 29

Cybersecurity Blog | SentinelOne

Actively Exploited

This week, authorities have taken action against Russian-based cybercriminals, marking a significant step in international cybersecurity efforts. Meanwhile, attackers have been deploying a new malware known as Starland, which poses a serious risk to users by potentially compromising their systems. Additionally, researchers have discovered around 300 fake GitHub repositories that are designed to distribute BoryptGrab, an infostealer that can harvest sensitive information from infected devices. These incidents highlight the ongoing challenges in cybersecurity, as attackers continue to evolve their tactics and target unsuspecting users. It is crucial for individuals and organizations to stay vigilant and implement robust security practices to defend against these threats.

Read Original

In April 2026, cybersecurity researchers identified a breach involving DigiCert, a prominent certificate authority, linked to a threat group known as CylindricalCanine, which is a subgroup of the Chinese cybercrime organization GoldenEyeDog. This group is particularly notorious for attacking the gambling and gaming industries. The breach resulted in the theft of code-signing certificates, which can be used to sign malicious software, making it harder for users to detect the threats. The incident raises serious concerns for companies relying on DigiCert for security, as compromised certificates could lead to widespread malware distribution. Organizations need to assess their certificate management practices and ensure they have robust monitoring in place to detect any misuse of their digital signatures.

Read Original
PreviousPage 96 of 369Next