Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Anthropic has reported that Russian hackers are targeting AI companies to exploit their technology for malicious purposes. In a recent incident, these attackers used the Claude AI model to automate their malware evasion techniques, which helped them evade detection while carrying out their operations. This breach highlights a concerning trend where cybercriminals are not only stealing intellectual property, like a pre-release Claude model, but also misusing advanced AI tools to enhance their cyberattacks. The implications are significant, as it raises questions about the security of AI systems and the potential for their misuse in future attacks. Companies in the tech sector need to bolster their defenses against such tactics to protect their infrastructure and intellectual property.

Read Original
Actively Exploited

A Russian hacker group has harnessed artificial intelligence to exploit vulnerabilities in PaperCut software, impacting hundreds of organizations around the globe. These attacks involve creating and deploying sophisticated exploits that take advantage of specific flaws in the software. PaperCut is widely used for print management, making many businesses vulnerable to these AI-driven attacks. The implications are serious, as compromised systems can lead to unauthorized access to sensitive data and disruption of services. Companies using PaperCut should take immediate action to patch their systems and protect against these evolving threats.

Read Original

Attackers have exploited two vulnerabilities in JFrog Artifactory, a tool used to manage software packages for build pipelines, to gain admin access to self-hosted servers. This allowed them to install backdoors, enabling ongoing access and control. The attacks were observed between August 15 and September 8, but JFrog had already patched the vulnerabilities prior to the attacks. Therefore, only those servers that had not yet been updated were at risk. This incident underscores the importance of timely software updates, as failure to do so can leave systems vulnerable to exploitation by malicious actors. Organizations using JFrog Artifactory should ensure they are running the latest version to protect against these types of attacks.

Read Original

A Ukrainian man has been sentenced to four years in prison for his involvement with the Conti ransomware gang, which executed a series of attacks from 2021 to 2022. This gang was notorious for targeting businesses and organizations, demanding hefty ransoms in exchange for decrypting stolen data. The individual, whose exact role was not detailed, is part of a broader crackdown on cybercriminals involved in such ransomware schemes. The sentencing serves as a warning to others in the cybercrime community and aims to deter future ransomware activities. As ransomware attacks continue to plague organizations worldwide, this case highlights the ongoing efforts by law enforcement to hold perpetrators accountable.

Read Original

PaperCut has released a new security maintenance update to address two significant vulnerabilities in its software that were being actively exploited. The updates are available for users of PaperCut NG/MF versions 26.0.5, 25.0.13, and 24.1.10. This move replaces earlier emergency patches that were initially issued to tackle these issues. It's crucial for users running these versions to apply the updates promptly to protect their systems from potential attacks. The vulnerabilities pose risks to the security of printing services and could allow unauthorized access or manipulation of sensitive information.

Read Original
Actively Exploited

Indonesia is facing a cybersecurity threat from a group known as GoldFactory, which is using a technique involving the Android Work Profile feature to distribute the Gigabud Trojan. This malicious software targets Android banking apps, allowing attackers to steal sensitive financial information from users. Another group, Mantax Otax, is reportedly spreading malware independently. This situation raises concerns for Android users in Indonesia, particularly those who rely on banking apps for financial transactions. The ability of these groups to exploit legitimate features in Android underscores the need for heightened vigilance among users and better security measures from app developers.

Read Original

Oleksii Lytvynenko, a member of the infamous Conti ransomware group, has been sentenced to four years in prison for his role in cyberattacks targeting at least 12 companies. Lytvynenko joined the group in 2021, participating in schemes that extorted businesses by encrypting their data and demanding ransom payments. His sentencing serves as a reminder of the legal consequences facing cybercriminals. The Conti group has been linked to numerous high-profile attacks, making this ruling significant in the ongoing battle against ransomware. The case reflects the increasing focus on holding individuals accountable for their actions in the cyber realm.

Read Original

A recent cybersecurity incident has revealed that a group of likely Russian-speaking attackers exploited vulnerabilities in PaperCut NG/MF servers to compromise 395 organizations worldwide. Using a network of AI agents, they launched a sophisticated campaign that took advantage of unpatched flaws in these widely used print management solutions. The attackers targeted these servers, which are commonly found in businesses and educational institutions, making the breach particularly concerning for sensitive data exposure. Organizations using PaperCut products should urgently assess their systems for vulnerabilities and apply necessary security updates to protect against potential exploitation. This incident underscores the need for robust security practices, especially for software that handles critical operational functions.

Read Original

AI systems are advancing rapidly, but the safeguards meant to protect against their potential misuse are lagging behind. Jacob Coxon, a researcher who previously worked at OpenAI and Anthropic, recently left his position and issued a warning about the risks posed by increasingly capable AI agents. He emphasized the need for better permissions, isolation, and oversight to prevent harmful actions from these technologies. As AI continues to integrate into various sectors, the lack of adequate safety measures raises concerns about how these systems could be misused or cause unintended harm. This situation calls for urgent attention from AI developers and regulators to ensure that safety protocols keep pace with technological advancements.

Read Original

A researcher from Anthropic has resigned, citing serious concerns about the potential dangers associated with artificial intelligence development. This resignation follows a trend of similar departures from both Anthropic and OpenAI, where individuals have voiced worries about the safety protocols in AI research. The implications of these resignations raise questions about the ethical responsibilities of AI companies and the need for stricter safety measures. As AI technology continues to advance rapidly, the concerns highlighted by this researcher could impact the future direction of AI development and regulation. The discussion around AI safety is becoming increasingly urgent as more experts call for a reevaluation of current practices.

Read Original

In a recent investigation by Prophet Security, it was found that identity-related attacks accounted for about half of all confirmed malicious activities from May to July 2026. The analysis identified four main attack patterns that impacted various customer environments. The report also examined why some attacks were successful while others were thwarted. This information is crucial for organizations as it sheds light on the current tactics being used by cybercriminals, particularly focusing on identity theft and related fraud. Companies need to reassess their security measures to effectively protect against these prevalent threats, which could lead to significant data breaches and financial losses.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has revised its insider threat guide to address contemporary issues like remote work and the use of artificial intelligence. The updated guide provides organizations with new strategies for detecting and mitigating the risks posed by insider threats, especially as many employees continue to work from home. This is significant as insider threats can originate from both employees and contractors, making it essential for companies to adopt effective measures to safeguard sensitive information. The guidance aims to enhance awareness and preparedness against potential breaches from within, which can be particularly damaging. Organizations are encouraged to implement these new recommendations to improve their security posture against insider risks.

Read Original

Sean Cairncross, the U.S. National Cyber Director, commented on the ongoing struggle between technological innovation and cybersecurity. He emphasized that while artificial intelligence is often viewed as a new challenge, it actually exposes existing vulnerabilities in cyber systems. This statement reflects a broader concern among governments that they are merely 'buying time' to address these issues rather than effectively solving them. The implications are significant as they indicate that rapid advancements in technology may outpace the security measures currently in place, leaving systems vulnerable to attacks. This ongoing race between innovation and security could have serious ramifications for national security and the safety of digital infrastructure.

Read Original
Actively Exploited

A serious vulnerability, identified as CVE-2026-19490, has been found in NetScaler products that allows attackers to bypass authentication. This flaw has been actively exploited since at least September 3, raising concerns for organizations using affected systems. The vulnerability affects various versions of NetScaler and poses a significant risk as it could allow unauthorized access to sensitive information. Companies using NetScaler should prioritize patching their systems to mitigate potential breaches. The exploitation of this vulnerability highlights the ongoing risks associated with widely used network infrastructure.

Read Original

The FBI has released its first-ever cyber strategy, signaling a shift in how the U.S. government plans to tackle cyber threats. This strategy emphasizes proactive measures aimed at disrupting cybercriminals and other malicious actors before they can execute their plans. The approach reflects growing concerns over cyberattacks that can compromise national security and critical infrastructure. By focusing on disruption rather than just defense, the FBI aims to enhance its capabilities in combating increasingly sophisticated cyber threats. This move could lead to more aggressive tactics in cyber law enforcement, aiming to deter potential attackers.

Read Original
Page 1 of 395Next