Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

California's Attorney General Rob Bonta has filed a lawsuit against 23andMe, the genetic testing company, alleging that it failed to adequately protect user data following a breach earlier this year. The lawsuit comes after the company, now operating under the name Chrome Holding Co. due to bankruptcy proceedings, reportedly exposed sensitive information of its users. This breach raises significant concerns about data privacy and the responsibilities of companies handling personal information. If the allegations are proven, it could lead to stricter regulations and greater scrutiny of how personal data is managed in the biotech industry. Users who trusted 23andMe with their genetic information are particularly affected, as their sensitive data may have been compromised.

Impact: 23andMe user data, genetic information
Remediation: N/A
Read Original

A man from North Carolina has been sentenced to over 10 years in prison for selling the personal data of more than 7 million elderly Americans to scammers based in Jamaica. The man, whose actions have raised concerns about privacy and security, provided sensitive information like names, addresses, and Social Security numbers. This breach not only puts the affected individuals at risk of identity theft but also highlights the ongoing issue of data exploitation in the digital age. Law enforcement officials emphasize the need for stronger protections for vulnerable populations, particularly the elderly, who are often prime targets for scams. The case serves as a reminder of the importance of safeguarding personal information and the severe consequences for those who exploit it.

Impact: Personal information of elderly Americans, including names, addresses, and Social Security numbers.
Remediation: N/A
Read Original

Researchers have discovered a new technique called FROST, which allows websites to track user activity by analyzing the behavior of a user's Solid-State Drive (SSD). This method can infer information about the files and applications stored on the SSD, which is unexpected for most users. The implications of this technique raise significant privacy concerns, as it adds another layer to the existing methods websites use to monitor user behavior, like browser fingerprinting and tracking scripts. Users may not be aware that their storage devices can be exploited in this way, highlighting the need for more robust privacy protections. As this method gains attention, it emphasizes the ongoing challenges of online privacy and security.

Impact: Websites utilizing tracking techniques, users with SSDs, browsers supporting OPFS.
Remediation: Users should consider using privacy-focused browsers and tools that limit tracking, as well as regularly clearing browser data.
Read Original

According to ESET's 2026 APT Activity Report, Chinese-backed advanced persistent threats (APTs) are capitalizing on the instability caused by ongoing conflicts in Iran to target maritime and energy companies. This surge in cyber-attacks indicates that attackers are exploiting geopolitical tensions to carry out their operations. The report highlights that these APTs are not only focusing on regional targets but are also continuing their activities against organizations globally. This situation raises concerns for companies in the maritime and energy sectors, as they may face increased risks of data breaches and operational disruptions due to these cyber threats. Understanding these tactics is crucial for organizations to bolster their cybersecurity defenses and protect sensitive information.

Impact: Maritime and energy companies
Remediation: Companies should enhance their cybersecurity measures, including implementing stronger access controls and monitoring systems for unusual activity.
Read Original
Actively Exploited

A recent incident involving an AI-generated npm infostealer has drawn attention after it accidentally exposed its own GitHub token, revealing the identity of its operator. This infostealer, designed to collect sensitive information, had a flaw that led to the leak of the token on a public platform. As a result, researchers were able to trace back to the developer behind the malware, raising concerns about the capabilities of AI tools in creating malicious software. This incident highlights the potential risks associated with the misuse of AI in software development, particularly in the realm of cybersecurity. Developers and users of npm packages should be vigilant about the security of their applications and the code they incorporate from third parties.

Impact: npm packages, GitHub
Remediation: Developers should review their npm packages for security vulnerabilities and ensure that sensitive tokens are not hard-coded or exposed in public repositories.
Read Original

Humanix has introduced a new capability aimed at detecting real-time violations of security procedures in IT support workflows. This is particularly important as help desk and service desk agents often face pressure from attackers to bypass identity verification steps, which can lead to unauthorized access and data breaches. By identifying these violations as they occur, Humanix aims to enhance the security of sensitive requests, such as credential resets. This development is crucial for organizations that rely on help desk support to protect sensitive information and maintain secure operations. The new feature could help prevent incidents where attackers exploit human vulnerabilities in security protocols.

Impact: IT support workflows, help desk systems, service desk procedures
Remediation: Implement Humanix’s detection capabilities to monitor compliance with security procedures.
Read Original

GreyVibe, a suspected Russian hacking group, has been targeting Ukrainian organizations using advanced techniques involving AI-generated messages. They create enticing lures to trick victims into downloading malware, which is custom-built for their operations. This approach allows them to bypass traditional security measures and effectively compromise systems. The use of AI tools like ChatGPT and Gemini in these cyberattacks raises concerns about the evolving nature of threats, particularly in geopolitical contexts. Organizations in Ukraine need to bolster their security protocols to defend against these sophisticated tactics.

Impact: Ukrainian entities, custom malware tools
Remediation: Organizations should enhance security measures, conduct employee training on recognizing phishing attempts, and implement advanced threat detection systems.
Read Original

The House Homeland Security Committee is planning to hold a public hearing focused on the impact of artificial intelligence on cybersecurity. This event is part of a series of discussions aimed at understanding how AI can both enhance and complicate security measures. Lawmakers are looking to explore the potential risks and benefits associated with the integration of AI technologies in cybersecurity practices. The hearing will likely address concerns over AI's role in facilitating cyberattacks, as well as its potential for improving defensive strategies. This initiative reflects growing recognition of the need to adapt to rapidly changing technology in the field of cybersecurity.

Impact: N/A
Remediation: N/A
Read Original

Researchers have identified a group known as GreyVibe, linked to Russia, that is using artificial intelligence tools like ChatGPT and Gemini to enhance their cyberattacks. This development raises concerns about how cybercriminals and state-sponsored groups may evolve their tactics in the future. The use of AI allows these attackers to automate and optimize their strategies, potentially making their operations more effective and harder to detect. Companies and organizations need to be vigilant and adapt their cybersecurity measures in light of these advancements. This trend signifies a worrying shift in the capabilities of cyber adversaries, emphasizing the need for improved defenses against sophisticated AI-driven attacks.

Impact: N/A
Remediation: Organizations should enhance their cybersecurity protocols and training to counter AI-driven attacks.
Read Original

Hackers are exploiting a vulnerability in FortiClient Enterprise Management Server (EMS), identified as CVE-2026-35616, which allows them to bypass authentication. This flaw is being used to deliver a credential-stealing malware known as EKZ. Organizations using FortiClient EMS are at risk, as attackers can gain unauthorized access to sensitive information through this exploit. The situation is concerning since the malware targets credentials, potentially leading to further data breaches. Companies should prioritize patching this vulnerability to protect their systems and data from compromise.

Impact: FortiClient Enterprise Management Server (EMS)
Remediation: Organizations should apply the latest security patches for FortiClient EMS to address CVE-2026-35616. Regularly updating software and monitoring systems for unusual activity are also recommended to mitigate risks.
Read Original

A serious vulnerability has been found in Gogs, a widely used open-source Git service that allows users to host their own repositories. This flaw, which has a CVSS score of 9.4, enables any authenticated user to execute arbitrary code, potentially giving them full control over the server. This means that individuals with valid access can exploit this weakness to run malicious commands, posing a significant risk to the integrity and security of the affected systems. Currently, there is no CVE identifier linked to this vulnerability, which may complicate tracking and response efforts. Users of Gogs should be particularly vigilant and consider implementing immediate security measures to mitigate potential exploitation.

Impact: Gogs self-hosted Git service
Remediation: Users should apply security patches as they become available and review access controls to limit authenticated user privileges.
Read Original

A recently identified vulnerability in FortiClient Endpoint Management Server (EMS), tracked as CVE-2026-35616, is being actively exploited to deploy information-stealing malware, according to a report from Arctic Wolf. This flaw has a high severity rating of 9.1 and allows attackers to execute remote code without needing authentication, making it particularly dangerous. Organizations using FortiClient EMS should be on high alert as the vulnerability can be exploited through specially crafted requests. The vulnerability was patched in April, but the ongoing exploitation highlights the importance of timely updates and monitoring for suspicious activity. Companies must ensure they have applied the latest patches to protect their systems from these attacks.

Impact: FortiClient Endpoint Management Server (EMS)
Remediation: Organizations should apply the patch released in April to FortiClient EMS to mitigate the vulnerability. Regularly monitor systems for any unauthorized access or unusual activity.
Read Original

Recent research has uncovered vulnerabilities in AI data centers that can be exploited through wireless attacks. These attacks can allow cybercriminals to access sensitive data and disrupt operations, raising concerns for organizations that rely heavily on AI technologies. The findings indicate that many existing security measures are inadequate to protect against these types of threats. As AI continues to integrate into various sectors, the implications of these vulnerabilities could lead to significant data breaches and operational disruptions. Companies operating AI data centers need to reassess their security protocols to mitigate these risks.

Impact: AI data centers, wireless communication systems
Remediation: Implement stronger encryption for wireless communications, conduct regular security audits, and update security protocols to address identified vulnerabilities.
Read Original

Recent research shows that cybercriminals have shifted tactics from typosquatting—where they create malicious packages with misspelled names—to developing more sophisticated open source packages that closely mimic legitimate code. This new approach allows attackers to trick users into downloading and installing harmful software without them realizing it. The implications are significant, as developers and organizations relying on open source software may inadvertently use these compromised packages, leading to potential data breaches or system vulnerabilities. Users must remain vigilant and verify the authenticity of packages before installation to prevent falling victim to these impersonation tactics.

Impact: Open source software packages, particularly those in popular repositories like npm or PyPI
Remediation: Users should verify the authenticity of software packages before installation and consider using tools that can scan for known malicious packages.
Read Original

A man was arrested in Buren, Netherlands, for allegedly hacking into the computer systems of Ajax, a prominent football club. The suspect is accused of unauthorized access to Ajax's systems multiple times earlier this year. This incident raises concerns about the security of sports organizations, which can be vulnerable to cyberattacks that may compromise sensitive data or disrupt operations. The arrest reflects ongoing efforts by law enforcement to tackle cybercrime and protect digital assets in the sports industry. As cyber threats grow, it is crucial for organizations to bolster their cybersecurity measures to prevent similar incidents in the future.

Impact: Ajax football club's computer systems
Remediation: N/A
Read Original
Page 1 of 218Next