Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Actively Exploited

A new phishing campaign, dubbed 'The TFF Trap', employs sophisticated evasion tactics to execute business email compromise (BEC) attacks. This method utilizes fileless techniques and low-detection loaders to deploy various remote access trojans (RATs) and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger. The attackers aim to infiltrate corporate networks and steal sensitive information. Organizations should be on high alert, as these tactics make it challenging for traditional security measures to detect the malicious activities. Companies must bolster their email security practices and educate employees on recognizing phishing attempts to mitigate the risks associated with this evolving threat.

Read Original

The Director of the newly formed Center for AI Standards and Innovation, part of the Department of Commerce, has left the position after just three months. This center was established to evaluate the risks and challenges associated with artificial intelligence technologies. The sudden departure raises questions about leadership stability and the future direction of the center, which plays a pivotal role in shaping federal AI policy. With AI systems increasingly integrated into various sectors, effective oversight is crucial to mitigate potential harms. The vacancy may hinder efforts to develop comprehensive standards that ensure AI technologies are safe and beneficial for society.

Read Original

Researchers have identified a new crypter known as Cruciferra that employs advanced techniques to evade detection by security software. This crypter utilizes a method called process ghosting, along with 90 custom ciphers, to obscure malicious payloads for various cyber actors. The ability to hide effectively means that malware can be deployed without triggering alarms, making it a significant concern for cybersecurity professionals. The techniques used by Cruciferra can complicate the detection and analysis of threats, potentially allowing attackers to compromise systems more easily. As this method becomes more widespread, organizations need to enhance their defenses and monitoring to counteract these stealthy tactics.

Read Original

A critical vulnerability in the ServiceNow AI Platform, identified as CVE-2026-6875, is being actively exploited by attackers. This pre-authentication code injection flaw allows unauthenticated users to escape the platform's script sandbox and execute arbitrary code on targeted instances. Researchers from Searchlight Cyber discovered this vulnerability and reported it to ServiceNow in early April 2026. The exploitation of this vulnerability poses significant risks to organizations using the ServiceNow AI Platform, as it could lead to unauthorized access and control over sensitive workflows and data. Companies are urged to take immediate action to safeguard their systems against potential attacks.

Read Original

The article discusses the limitations of simply blocking AI models to combat cyber threats. While AI companies can identify vulnerabilities and create patches, the author argues that a more comprehensive, long-term defense strategy is necessary, and this responsibility falls to the government. The piece emphasizes that merely restricting AI tools won't resolve the underlying security issues they may create. It calls for a collaborative effort between the private sector and government to develop effective strategies to protect against the evolving landscape of cyber threats. This conversation is particularly relevant as AI technology becomes increasingly integrated into various systems and applications, raising new security concerns.

Read Original

SonicWall discovered that two zero-day vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, were exploited by a threat actor known as UTA0533. These vulnerabilities were actively used to deliver custom malware over several weeks before a patch was released. Organizations using affected SonicWall products need to be particularly vigilant, as the malware has already been deployed in the wild. This situation emphasizes the importance of timely patch management and monitoring for unusual activity, given that attackers can exploit such vulnerabilities to gain unauthorized access to systems. Companies should prioritize updating their security infrastructure to mitigate the risk posed by these exploits.

Read Original
Actively Exploited

The JadePuffer group has launched a new campaign using a ransomware variant called ENCFORGE. This ransomware is specifically designed to target and wipe AI model artifacts, which are crucial for machine learning applications. Researchers have found that this attack poses a significant risk to organizations that rely on AI technologies, as it can lead to the loss of valuable intellectual property and disrupt business operations. The campaign raises concerns about the emerging threats to AI systems and the potential for attackers to exploit vulnerabilities in this rapidly evolving field. Companies that develop or use AI models should be particularly vigilant and take steps to secure their data against this new threat.

Read Original

A researcher has utilized OpenAI's latest model to create an exploit chain for a serious vulnerability found in WordPress. This development raises concerns for millions of users and organizations that rely on WordPress for their websites. If exploited, this vulnerability could allow attackers to compromise sites, leading to unauthorized access or data breaches. The incident emphasizes the need for website administrators to stay informed about potential vulnerabilities and to apply security updates promptly. As the situation evolves, users should be vigilant about their site security and consider implementing additional protective measures.

Read Original

This week saw multiple security incidents that exploited vulnerabilities in various systems. Notably, a remote code execution vulnerability in WordPress was identified, allowing attackers to run malicious code on affected sites. Additionally, SonicWall reported zero-day vulnerabilities that could lead to unauthorized access. AI services are also being targeted, with attackers using fake prompts to trick users. These incidents highlight the need for organizations to patch outdated systems and be vigilant against social engineering tactics. The situation is concerning as some of these vulnerabilities were already being exploited before they were disclosed, leaving many systems at risk.

Read Original

Dutch intelligence agencies AIVD and MIVD have issued a warning that Russian operatives are hacking internet-connected IP cameras in the Netherlands and other EU countries to monitor NATO military logistics and weapons shipments to Ukraine. This systematic compromise of IP cameras poses a significant risk, as it allows adversaries to gather sensitive information about military movements and operations. The intelligence services did not disclose the exact number of cameras affected, but they emphasized the need for heightened security measures. The situation raises concerns about the security of civilian technology and its potential use in military espionage, highlighting the ongoing cybersecurity challenges faced by NATO allies amidst the conflict in Ukraine.

Read Original

OpenSSL has addressed a vulnerability known as 'HollowByte' that could allow attackers to launch denial-of-service (DoS) attacks. By sending specially crafted payloads, attackers could exploit the way memory is allocated by the software, potentially leading to server memory exhaustion. This issue affects any systems that utilize OpenSSL for secure communications, which includes a wide range of web servers and applications. The risk is significant because it could lead to service outages for affected systems. Users and administrators are advised to update their OpenSSL versions to mitigate this vulnerability and ensure continued security.

Read Original

Russian intelligence services are reportedly hijacking internet-connected security cameras across Europe and Ukraine to monitor military activities. This operation includes spying on military transport routes and weapons shipments destined for Ukraine, as well as tracking the locations of Ukrainian troops. The findings, published by the Dutch intelligence agencies AIVD and MIVD, reveal a concerning method of surveillance that poses significant risks to military operations. The use of easily accessible surveillance technology for espionage highlights vulnerabilities in security systems and raises alarms about the potential for increased military tensions in the region. This incident underscores the need for stronger security measures in internet-connected devices used in sensitive areas.

Read Original
Critical
The Hidden Risk in Enterprise AI Agents: Ungoverned Context

Hackread – Cybersecurity News, Data Breaches, AI and More

Enterprises are increasingly integrating AI agents into their systems, which grant these agents access to sensitive customer data, financial records, and internal documents. This practice raises significant security concerns, as these AI systems may operate without adequate oversight, potentially leading to unauthorized access or data leaks. With the growing reliance on AI in business processes, organizations must ensure that these agents are governed properly to prevent misuse. The lack of regulation around AI's interaction with critical systems could expose companies to serious risks, including data breaches and compliance violations. It's essential for businesses to implement strict protocols and monitoring for AI access to safeguard sensitive information.

Read Original

Richard Bird, a seasoned cybersecurity executive, has created a new index aimed at tracking significant data breaches. This resource is designed for a wide audience, including security professionals, journalists, policymakers, and everyday users, providing a clearer picture of material breaches without quantifying the financial losses involved. The index serves as a tool for understanding the frequency and nature of these incidents, which can help inform responses to cybersecurity threats. By focusing on the incidents themselves rather than the monetary impact, Bird hopes to raise awareness about the risks associated with data breaches and encourage better security practices across various sectors. This initiative comes at a time when data security is a growing concern for individuals and organizations alike.

Read Original

Ernst & Young has reported a significant data breach involving the theft of sensitive personal and financial information from a third-party management platform. Hackers accessed a range of data, including names, addresses, Social Security numbers, and credit and debit card numbers. This incident raises serious concerns as it affects individuals whose information was compromised, potentially leading to identity theft and financial fraud. The breach emphasizes the risks associated with third-party services and the importance of robust security measures to protect sensitive data. Users and organizations alike are urged to monitor their accounts and consider additional security measures following this incident.

Read Original
Page 1 of 277Next