Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

The article discusses the challenges of securing artificial intelligence (AI) systems, emphasizing that the real issue lies in how we approach AI security rather than the technology itself. It argues that many of the problems arise from human factors, such as misuse or misunderstanding of AI capabilities. The piece suggests that a shift in perspective is needed to effectively manage the risks associated with AI applications. By focusing on how we use AI, rather than solely on the technology, organizations can better protect themselves against potential vulnerabilities. This is crucial as AI continues to play a larger role in various industries, impacting everything from data privacy to operational security.

Read Original

IEH Corporation, a U.S. defense and aerospace manufacturer based in Brooklyn, New York, recently suffered a phishing attack that compromised its Microsoft 365 inbox. This breach potentially exposed sensitive emails and export-controlled military data. IEH specializes in high-reliability electrical connectors, which are critical in military and aerospace applications. The incident raises concerns about the security of sensitive information in the defense sector, as attackers could exploit such data for malicious purposes. Companies in similar fields need to be vigilant and enhance their email security measures to prevent similar attacks in the future.

Read Original
Actively Exploited

The latest Malware Newsletter from Security Affairs covers a variety of recent malware incidents. One notable threat involves fake Roblox cheats that are being distributed through Discord and online forums, which are actually Java stealers designed to harvest sensitive information from users. Another focus is on a complex operation involving a cluster of malicious npm packages that deliver a remote access Trojan (RAT) targeting Alibaba. This highlights the ongoing risks associated with third-party software and the importance of scrutinizing downloads from less reputable sources. As these attacks evolve, users and companies need to stay vigilant and prioritize security measures to protect their data.

Read Original

Recent research by PortSwigger's Gareth Heyes has revealed a significant vulnerability in major webmail services, where attackers can exploit CSS (Cascading Style Sheets) to conduct various malicious activities. This method can allow attackers to steal user credentials, hijack email sessions, and manipulate AI tools linked to users' inboxes. The use of CSS, typically intended for styling web pages, raises alarms because it shows how seemingly harmless web technologies can be weaponized. This issue affects all users of webmail services that utilize AI features, making it crucial for companies to assess their security measures. The implications are serious, as compromised accounts could lead to unauthorized access to sensitive information and further exploitation.

Read Original

Last week, Cisco addressed a vulnerability in its Integrated Management Controller (IMC) that could allow unauthorized access to sensitive system functions. This bug potentially affects users of Cisco's servers and data center management solutions, which are critical for IT infrastructure. The flaw could lead to serious security implications if exploited, making it essential for affected users to apply patches promptly. Additionally, the article discusses an upcoming Patch Tuesday, which is expected to bring further updates and fixes, and mentions plans for Black Hat USA 2026, a major cybersecurity conference. Keeping systems updated is vital in the ongoing fight against cyber threats.

Read Original

The Head Mare hacktivist group has been targeting unpatched TrueConf video conferencing servers, exploiting vulnerabilities to swap out legitimate client installers with malicious versions that contain backdoors. This means that unsuspecting users who download these compromised installers may unknowingly install malware that could allow attackers unauthorized access to their systems. TrueConf, which is used for video conferencing, is now facing scrutiny as users may be at risk of data breaches and privacy violations. Organizations using TrueConf need to ensure their servers are updated and secure to prevent these kinds of attacks, which are becoming increasingly common as hackers look for easy targets. It's crucial for users to be aware of the risks and to regularly update their software to protect against such vulnerabilities.

Read Original

Brand impersonation is a rising concern for organizations as attackers create fake websites that mimic legitimate brands to deceive customers and steal sensitive information. The Federal Trade Commission (FTC) reported receiving 3 million fraud complaints, many stemming from these scams. To combat this issue, the article outlines four essential steps for companies to ensure their takedown requests for impersonating domains are not rejected. This is crucial because effective takedown requests can help protect brand reputation and customer trust, preventing further exploitation by malicious actors. Organizations need to be proactive in addressing these threats to safeguard their assets and their clients' data.

Read Original

A serious security vulnerability has been discovered in Metabase Cloud, a popular analytics platform, allowing attackers to exploit a zero-day flaw rated at CVSS 10. This high-severity vulnerability has enabled unauthorized access to administrative features and the potential theft of sensitive data from affected users. Framework, a known user of Metabase, confirmed it was one of the victims of this breach. The flaw was unpatched and unknown to security teams at the time of exploitation, raising concerns about the effectiveness of current security measures in place. Companies using Metabase should take immediate action to assess their exposure and implement protective measures to safeguard their data.

Read Original

Researchers from Varonis have discovered a serious vulnerability in Atlassian’s Rovo AI that allows attackers to exploit a one-click method known as the RovoBlast attack. This vulnerability could potentially enable unauthorized access to sensitive enterprise data stored in applications like Confluence, Jira, and SharePoint. Organizations using these tools should be particularly concerned, as the exposure of this data could lead to significant breaches and loss of confidential information. The discovery emphasizes the need for companies to regularly update their security protocols and patch vulnerabilities promptly to safeguard their data. As of now, the specific details about whether this vulnerability is being actively exploited are not confirmed.

Read Original

Atlassian's Rovo assistant has a vulnerability that allows attackers to trick it into gathering sensitive data from Jira and Confluence, which it can then send to external servers. This issue was identified by two separate security firms, although only one method of exploitation has been confirmed as blocked. PromptArmor was able to embed malicious instructions in content that Rovo processes, leading to unauthorized data access. This incident poses a significant risk to organizations using these Atlassian products, as it could lead to the exposure of confidential project information and internal communications. Users of Jira and Confluence should be aware of this vulnerability and take steps to secure their data against potential exploitation.

Read Original

Recent research has revealed new attack techniques that can exploit webmail services by allowing malicious content in emails to escape their intended boundaries. This vulnerability affects major platforms like Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. Attackers can use these methods to capture user passwords, take control of third-party accounts, leak sensitive tokens, and manipulate user interface actions. This is particularly concerning as it could allow for unauthorized access to personal information and interactions with AI tools that read emails. The implications for user privacy and security are significant, as these attacks can bypass traditional defenses that many users rely on.

Read Original

Unlimited Technology Systems, a U.S.-based healthcare technology company, has reported a data breach affecting approximately 3.8 million individuals. The breach occurred after hackers gained access to one of its commercial data centers between October 5 and 10, 2025. Stolen data includes personal, medical, and insurance information of patients, raising significant concerns about privacy and identity theft. This incident emphasizes the vulnerabilities within healthcare technology systems, which are critical for patient care and data security. Individuals affected should be vigilant about potential phishing attempts and monitor their accounts for suspicious activity.

Read Original

Metabase has issued a warning about a serious security vulnerability in its data visualization software, which is currently being exploited by attackers. This zero-day flaw, rated with a CVSS score of 10.0, allows unauthorized individuals to execute arbitrary SQL commands in the Metabase application database without needing to log in. As a result, attackers can gain administrative access to sensitive data. Since this vulnerability does not have a CVE identifier, it adds another layer of urgency for users to secure their systems. Organizations using Metabase should take immediate action to protect their data, as the exploit is actively being used in the wild.

Read Original

N-able has issued a hotfix for its N-central Remote Monitoring and Management (RMM) software amid ongoing attacks exploiting a recently identified security flaw. The company is enhancing its protective measures as it observes evolving tactics from threat actors targeting managed systems. This update is part of their commitment to maintaining system integrity and safeguarding user data. Users of N-central should apply the latest hotfix to mitigate the risks associated with these active exploitation attempts. The situation underscores the importance of timely updates in the face of persistent cyber threats.

Read Original
Actively Exploited

A serious SQL injection vulnerability in Metabase has been exploited in zero-day attacks, resulting in unauthorized access to customer data. This flaw has specifically affected companies like Framework and Tally, raising concerns about the security of user information stored in Metabase instances. Attackers have taken advantage of this weakness to steal sensitive data, which highlights the urgent need for affected organizations to address the vulnerability promptly. Users and companies relying on Metabase should be vigilant and ensure their systems are secure against potential breaches. The situation emphasizes the importance of maintaining robust security measures, especially when using widely-used data analysis tools.

Read Original
Page 1 of 326Next