SonicWall has released urgent firmware updates to address three vulnerabilities found in its SonicOS software, which affects Gen 6, Gen 7, and Gen 8 firewalls. These flaws could potentially allow attackers to bypass security controls and gain unauthorized access to restricted services. Users of these firewall models are strongly advised to apply the patches immediately to protect their systems from possible exploitation. The vulnerabilities underscore the importance of keeping security software up to date, as failure to patch could leave networks open to attacks. Companies relying on these firewalls should prioritize this update to safeguard their network environments.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Two former employees from cybersecurity firms Sygnia and DigitalMint were sentenced to four years in prison for their involvement in BlackCat (ALPHV) ransomware attacks against U.S. companies. These individuals exploited their insider knowledge to facilitate cyberattacks that resulted in significant financial losses for the targeted organizations. The BlackCat ransomware group has gained notoriety for its sophisticated attacks and has been responsible for numerous breaches in recent years. This case underscores the risks posed by insider threats in the cybersecurity landscape, as even trusted employees can engage in malicious activities. The sentences aim to deter similar behavior and reinforce the importance of vigilance within the cybersecurity community.
Dataiku has introduced Kiji Privacy Proxy, an open-source tool designed to protect sensitive customer information when interacting with external AI services. Many organizations send prompts containing personally identifiable information (PII) to large language models without proper sanitization, risking data exposure. Kiji acts as a local gateway, filtering out customer emails, support transcripts, and other identifying data before requests reach APIs like OpenAI and Anthropic. This tool is particularly relevant for enterprise developers who need to ensure customer privacy while still utilizing advanced AI capabilities. By integrating this proxy, companies can better safeguard user data and comply with privacy regulations.
SCM feed for Latest
Ukrainian police have arrested three individuals, including a 19-year-old, for allegedly hijacking approximately 610,000 accounts on the popular gaming platform Roblox. The suspects reportedly exploited stolen session cookies, allowing them to bypass traditional password protections and gain unauthorized access to user accounts. This incident underscores the risks associated with session management and the potential for significant breaches in online gaming communities. The large number of affected accounts highlights the need for users to be vigilant about their account security and for platforms like Roblox to strengthen their defenses against such attacks. The situation serves as a reminder of the ongoing challenges in protecting digital identities in an increasingly interconnected world.
CyberScoop
Ryan Goldberg and Kevin Martin, both former incident responders, have been sentenced to four years in prison for their involvement in a series of ransomware attacks against five companies in 2023. The duo extorted nearly $1.3 million from one of their victims, showcasing a troubling trend where individuals with cybersecurity expertise turn to criminal activities. This case raises concerns about trust within the cybersecurity community and highlights the ongoing risks of ransomware, which continues to threaten businesses across various sectors. The sentencing serves as a reminder that those who exploit their knowledge for malicious purposes will face serious consequences.
SCM feed for Latest
Sri Lankan officials are investigating the disappearance of a $625,000 payment intended for the U.S. Postal Service. This payment went missing several weeks ago, raising concerns about potential hacking or cyber fraud. Authorities suspect that the incident might be linked to cybersecurity issues, although specific details about how the payment went missing remain unclear. This situation could signify vulnerabilities in the financial transaction processes between countries, potentially impacting international postal services and financial exchanges. The investigation aims to uncover the circumstances surrounding the missing funds and ensure that similar incidents do not occur in the future.
SCM feed for Latest
The European Commission has accused Meta of failing to properly manage the risks associated with children under 13 accessing its platforms, which is a serious concern for child safety online. The allegations suggest that Meta did not effectively identify or address potential dangers for younger users, raising questions about the company's compliance with the Digital Services Act (DSA). This scrutiny comes amid growing concerns about the protection of minors on social media and the responsibilities of tech companies to safeguard this vulnerable group. If found in violation, Meta could face significant penalties and be required to implement stricter safety measures. This situation emphasizes the ongoing debate about how to balance user engagement with the safety of young internet users.
SCM feed for Latest
Recent research by Cybernews has shown a notable increase in deepfake incidents aimed at U.S. officials, with 156 cases documented over the last two years. These incidents involve the use of manipulated videos or audio to create convincing impersonations of public figures, which can lead to misinformation and potentially harm public trust. The rise in deepfakes poses a significant challenge for cybersecurity and public safety, as they can be used to spread false information or manipulate political discourse. Officials and cybersecurity experts are urging increased awareness and preparedness to combat this growing threat, emphasizing the need for better detection tools and public education on recognizing deepfakes. As these incidents become more frequent, the implications for national security and the integrity of information could be profound.
The Federal Communications Commission (FCC) is tightening its Know Your Customer (KYC) regulations for telecom companies. This move aims to enhance the verification process for callers and curb the influx of illegal calls and scams targeting American consumers. By closing loopholes that previously allowed banned foreign services to operate, the FCC is taking a stronger stance against fraudulent activities in the telecommunications sector. This change affects telecom providers nationwide, requiring them to implement more rigorous identification measures to ensure that they are not facilitating scams. The new rules are part of a broader effort to protect consumers from unwanted and potentially harmful calls.
Hackread – Cybersecurity News, Data Breaches, AI and More
A database linked to suspected stalkerware has been left exposed, leaking private chats and photos of various celebrities and influencers. This incident raises serious privacy concerns, as sensitive information that was meant to be private is now accessible to anyone who finds the database. The exposed content could lead to harassment or other malicious actions against the affected individuals. The incident underscores the risks associated with stalkerware, which is often used to track and monitor people without their consent. It serves as a reminder for users to be cautious about the applications they install and the permissions they grant.
SCM feed for Latest
In 2022, U.S. states imposed a record $3.45 billion in privacy-related fines on companies, surpassing the total fines levied between 2020 and 2021. This sharp increase reflects growing scrutiny over how businesses handle personal data and comply with privacy regulations. The report by Gartner highlights the rising trend of regulatory actions as states strengthen their privacy laws. Companies across various sectors are feeling the pressure to improve their data protection practices to avoid hefty penalties. The surge in fines indicates a significant shift in enforcement, emphasizing the importance of compliance in today’s digital landscape.
SCM feed for Latest
A teenager known as 'Bouquet' has been charged in the U.S. for his alleged involvement with the Scattered Spider hacking group, which is linked to extensive extortion schemes that have targeted companies around the globe. The charges include several serious crimes connected to these large-scale cyberattacks. Authorities believe that this group has been responsible for significant financial losses to various businesses, raising concerns about the growing threat posed by young hackers. The case highlights the ongoing challenges in combating cybercrime, especially as younger individuals become more involved in sophisticated hacking operations. This incident serves as a reminder for organizations to strengthen their cybersecurity measures to protect against such attacks.
Hackread – Cybersecurity News, Data Breaches, AI and More
A misconfigured server associated with the carding marketplace known as Jerry’s Store has leaked around 345,000 stolen credit card details. This incident stemmed from an artificial intelligence coding error that created a significant security flaw. The exposed data poses a serious risk to individuals whose credit card information was compromised, potentially leading to unauthorized transactions and identity theft. This situation also raises concerns about the security practices of online marketplaces that deal with illicit activities. The incident emphasizes the need for robust security measures, especially in environments handling sensitive financial data.
A new phishing kit called Bluekit has emerged, featuring over 40 templates designed to target well-known online services. This kit stands out because it also includes basic AI capabilities that help users create phishing campaign drafts more efficiently. This means that even those with limited technical skills can launch sophisticated phishing attacks, increasing the risk for individuals and organizations. The availability of such tools makes it easier for cybercriminals to exploit unsuspecting users, potentially leading to data breaches and financial losses. As these tools become more accessible, companies and users need to be more vigilant about phishing attempts and enhance their security measures to protect sensitive information.
Security Affairs
A newly discovered vulnerability in Linux, tracked as CVE-2026-31431 and named 'Copy Fail', could allow local, unprivileged users to escalate their privileges to root. This flaw lets attackers write four controlled bytes into page cache files, which is a significant security risk for many major Linux distributions. Researchers from Xint Code assigned a CVSS score of 7.8 to this vulnerability, indicating its seriousness. The issue affects various Linux systems, potentially putting numerous users at risk if they do not take action. Companies and users are urged to monitor their systems and apply necessary patches to mitigate this risk.