Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

U.S. prosecutors have charged a New York couple with laundering $43 million gained from cyber investment fraud schemes. The duo is accused of being part of a larger crime ring that exploited unsuspecting investors through fake investment opportunities online. This case highlights the ongoing issues surrounding cyber fraud, where victims are often tricked into handing over their money under false pretenses. The charges serve as a reminder of the importance of vigilance when it comes to online investments and the need for law enforcement to pursue those who facilitate such crimes. With increasing sophistication in these scams, it is crucial for individuals to be aware of potential red flags when considering investment opportunities.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included new vulnerabilities in its Known Exploited Vulnerabilities catalog, specifically targeting the KNX Protocol Connection Authorization Option 1 from the KNX Association and various flaws related to Oracle products. This update is crucial as it indicates that these vulnerabilities could be actively exploited by attackers, posing risks to organizations using affected systems. The inclusion of these vulnerabilities serves as a warning to IT departments and security teams to prioritize patching and mitigation efforts. Notably, CISA also added vulnerabilities from SonicWall and Microsoft to the catalog, emphasizing the ongoing need for vigilance in cybersecurity practices. Companies should review their systems and apply necessary updates to safeguard against potential attacks.

Read Original

Coca-Cola's Fairlife brand has halted milk production in the U.S. due to a ransomware attack that was disclosed on July 16, 2026. The company confirmed that while product quality and safety remain intact, all production operations at Fairlife in the U.S. have been temporarily suspended. This incident raises concerns about the vulnerability of food production systems to cyberattacks, especially as ransomware increasingly targets critical infrastructure. Fairlife's operations in Canada appear to be unaffected for now, but the situation could have broader implications for supply chains and food availability if not resolved quickly. The attack is a reminder of the growing risks businesses face from cybercriminals seeking to disrupt operations and demand ransom payments.

Read Original

A newly discovered vulnerability in SharePoint has been exploited by attackers shortly after its disclosure. This critical flaw allows remote, authenticated attackers to execute arbitrary code on the server, posing a significant risk to organizations using the platform. The vulnerability could lead to unauthorized access and manipulation of sensitive data, making it crucial for affected users to take immediate action. Companies utilizing SharePoint need to prioritize security updates to protect their systems from potential breaches. The rapid exploitation of this vulnerability serves as a reminder of the importance of timely patch management in cybersecurity.

Read Original
Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft SharePoint Server to its list of Known Exploited Vulnerabilities. This flaw, identified as CVE-2026-58644, has a high severity score of 9.8, indicating that it poses a significant risk. Federal Civilian Executive Branch agencies are mandated to implement necessary patches by July 19, 2026. The vulnerability involves a deserialization issue that could allow attackers to execute remote code on affected systems, making it crucial for organizations using SharePoint to take immediate action. By addressing this vulnerability, agencies can help prevent potential exploitation by malicious actors.

Read Original

Coca-Cola has temporarily halted production of its Fairlife dairy brand in the U.S. following a ransomware attack. The company is still assessing the full extent and impact of the breach. While specific details about the attack have not been disclosed, this incident raises concerns about the vulnerability of food production systems to cyber threats. The disruption in production could affect supply chains and product availability for consumers. As the investigation continues, it serves as a reminder for companies to bolster their cybersecurity measures to protect against such attacks.

Read Original
Actively Exploited

The Sandworm group, which is associated with Russia's military intelligence agency, the GRU, is targeting Ukrainian organizations using a deceptive approach called ClickFix. This technique involves creating fake CAPTCHA challenges that trick users into downloading malware. By exploiting social engineering tactics, the attackers aim to gain access to sensitive information. This method poses a significant risk to Ukrainian entities, as it can lead to data breaches and further cyber operations. The use of such sophisticated tactics reflects the ongoing cybersecurity threats faced by Ukraine amid its geopolitical tensions with Russia.

Read Original

A recent investigation by Mozilla has found that the period tracking app Stardust is sharing sensitive user data with third-party service RudderStack. This data is linked to a unique identifier rather than personal names, which raises privacy concerns for users. The sharing of such information can potentially expose users to unwanted marketing and other privacy risks. Given the nature of period tracking apps, which often contain sensitive health data, this incident highlights the need for greater transparency and user control over personal information. Users of Stardust may want to reconsider their use of the app or review its privacy settings to protect their data.

Read Original

Researchers from Hunt.io uncovered a significant cyber intrusion campaign attributed to Chinese actors using AI tools to automate attacks on government and financial systems. This campaign was detected in June 2026 and involved 13 servers located in Hong Kong. The servers contained sensitive materials, including victim source code, exploit scripts, and logs from the operators. The use of AI in these attacks could allow for faster and more efficient exploitation of vulnerabilities, raising concerns about the potential scale and impact of such attacks on critical infrastructure. As these methods evolve, organizations must remain vigilant and enhance their security measures to protect against increasingly sophisticated threats.

Read Original

The Daxin malware, a kernel-mode rootkit first identified in March 2022, has resurfaced, with researchers discovering it operating on a compromised system belonging to a manufacturer in Taiwan in 2026. This malware is particularly concerning because it can provide attackers with deep access to targeted systems, potentially leading to data theft or further exploitation. The resurgence of Daxin suggests that attackers are still actively using and developing sophisticated tools to breach security measures, particularly in regions like Taiwan, which is significant for its role in global technology supply chains. Companies in the region should enhance their defenses and monitor for any signs of compromise to mitigate the risks associated with this malware. The ongoing evolution of threats like Daxin emphasizes the need for continuous vigilance in cybersecurity practices.

Read Original

23andMe has agreed to pay $18 million in a settlement following a data breach that affected approximately 6.9 million customers. This breach occurred between April and September 2023, and was caused by credential-stuffing attacks, where attackers used stolen usernames and passwords to access accounts. The compromised data included sensitive genetic ancestry information, raising significant privacy concerns for users. This incident underscores the risks associated with storing personal genetic data online, as it can be exploited for various malicious purposes. Customers affected by the breach may need to monitor their accounts closely and consider additional security measures to protect their personal information.

Read Original

Coca-Cola has reported a ransomware attack on its Fairlife dairy subsidiary, leading to a halt in production of Fairlife products across the United States. The attack has disrupted operations, affecting the availability of milk and dairy products under the Fairlife brand. This incident raises concerns about the vulnerability of food supply chains to cyber threats, as disruptions can have widespread implications for retailers and consumers alike. As the investigation unfolds, it remains unclear how long the production will be suspended and what measures will be taken to restore operations. The incident serves as a reminder of the growing risks that ransomware poses to various industries, including food and beverage.

Read Original

Organizations are increasingly concerned about the risks associated with agentic artificial intelligence, which refers to AI systems that can make decisions and take actions independently. This type of technology poses challenges, as it can lead to unpredictable behavior that might compromise security. Companies are now calling for a reevaluation of their security frameworks to better manage these risks. The implications of not addressing these issues could lead to significant vulnerabilities, affecting not only individual organizations but also broader systems that rely on AI. Stakeholders are urged to consider these developments seriously as they navigate the evolving landscape of AI security.

Read Original
Actively Exploited

Researchers have discovered that over one million phishing emails are using a technique called text salting to bypass AI security filters. This method involves hiding malicious text within seemingly harmless content, making it difficult for AI systems to detect the phishing attempts. As a result, many users may unknowingly receive these threats in their inboxes, putting their personal information at risk. This situation raises concerns about the effectiveness of current AI security measures and the need for improved detection strategies. Organizations and email service providers must address this vulnerability to better protect their users from sophisticated phishing attacks.

Read Original

The Government Accountability Office (GAO) reported that the Federal Rotational Cyber Workforce program, designed to rotate cybersecurity professionals among federal agencies, has seen minimal participation. Only a handful of personnel received approval to join the initiative, which aims to enhance collaboration and knowledge sharing across government entities. This low engagement raises concerns about the effectiveness of the program in addressing the growing cybersecurity challenges faced by federal agencies. Without a more robust participation rate, the program may struggle to achieve its intended goals of improving cyber defense capabilities and developing a skilled workforce. The findings suggest a need for better incentives or support to encourage agencies to utilize this resource effectively.

Read Original
PreviousPage 98 of 369Next