Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Researchers have identified a significant security breach involving WordPress sites, where attackers have implemented a backdoor known as SC. This malware is designed to maintain persistent access to infected sites by using various methods for recovery, even after attempts to remove it. The backdoor can reinfect the site through files, database entries, or shared memory, making it particularly challenging for site administrators to eliminate. This incident raises serious concerns for website owners who rely on WordPress, as the backdoor can compromise sensitive information and lead to further attacks. Users and companies need to be vigilant and take proactive measures to secure their sites against such persistent threats.

Read Original

Law enforcement agencies from multiple countries have successfully executed 'Operation KillSwitch', targeting the KillSec ransomware gang. During the operation, authorities seized the gang's data leak site and servers, leading to the arrest of three individuals, including a 16-year-old who is believed to be the group's main administrator. This operation is significant as it disrupts a notable ransomware group that has been involved in various cyberattacks, affecting numerous victims. The dismantling of this gang could help reduce the prevalence of ransomware attacks, which have been a growing concern for businesses and individuals alike. The involvement of a minor in this criminal activity raises questions about the recruitment and involvement of young individuals in cybercrime.

Read Original

Kiteworks, a company specializing in secure file-sharing software, has issued updates to fix 126 vulnerabilities in its products. Among these is a high-severity code injection flaw in their Email Protection Gateway (EPG) security solution, which could allow attackers to execute arbitrary code on affected systems. This vulnerability poses a significant risk as it could lead to unauthorized access and data breaches if exploited. Users of Kiteworks' EPG are particularly urged to apply these patches promptly to safeguard their systems. The rapid response to these vulnerabilities emphasizes the importance of regular software updates in maintaining cybersecurity.

Read Original

OpenAI recently revealed that it has disrupted a campaign aimed at extracting sensitive reasoning from its AI models. This operation, linked to a group connected with Moonshot AI, a Beijing-based company, has been ongoing since early July. The campaign involved coordinated efforts to illicitly access proprietary information from OpenAI's systems. This incident raises concerns about the security of AI technologies and the lengths to which some entities may go to exploit them. As AI becomes more integrated into various sectors, safeguarding these systems from unauthorized access is crucial for maintaining trust and innovation in the field.

Read Original

Cisco has released a patch for a serious zero-day vulnerability found in its Catalyst SD-WAN appliances. This flaw could allow remote attackers to gain administrative access to affected devices without needing any authentication. The vulnerability poses a significant risk, as it can be exploited to take control of network infrastructure. Users of Cisco's SD-WAN products should prioritize applying the patch to safeguard their systems. The disclosure of this vulnerability emphasizes the need for organizations to remain vigilant about software updates and security practices.

Read Original

MetaMask, a popular cryptocurrency wallet, has reported an ongoing security incident that affects parts of its infrastructure. While details are still emerging, the company has acknowledged that some users may be impacted by this incident. It's crucial for users to remain vigilant and monitor their accounts for any unusual activity. The exact nature of the security issue has not been fully disclosed, but MetaMask is actively working to address the situation. This incident serves as a reminder of the vulnerabilities that can exist in digital wallet services, highlighting the need for strong security practices among users.

Read Original

Security researchers have released a proof-of-concept for a newly identified vulnerability in Apple's CoreGraphics, tracked as CVE-2026-86950. This flaw can be triggered by a malicious PDF containing a specially crafted embedded font, which causes unpatched iPhones and Macs to crash. Apple has indicated that this vulnerability may have been exploited in targeted attacks against specific individuals. Users of iPhones and Macs need to be aware of this risk, especially if they frequently open PDF files from unknown sources. The situation underscores the importance of keeping devices updated to the latest software versions to mitigate such risks.

Read Original

Bitget, a cryptocurrency exchange, reported a significant theft of $387.5 million that occurred last week. Investigations by SlowMist revealed that the attackers exploited a zero-day vulnerability in third-party security products. This flaw allowed the hackers to carry out their malicious activities undetected. Bitget is currently working to recover the stolen funds and mitigate further risks. This incident raises concerns about the security of third-party tools used by cryptocurrency exchanges and highlights the need for enhanced security measures to protect user assets in the digital currency space.

Read Original

MetaMask has announced that it is dealing with an ongoing security incident affecting part of its infrastructure. The company is working with external partners and security advisors to address the issue. While they have not found any immediate threat to MetaMask wallets, the incident has led to the exit of some affected Ethereum validators. This situation raises concerns for users relying on MetaMask for cryptocurrency transactions, as any security flaws could potentially compromise their assets. The company is focused on remediation and ensuring the safety of its users during this incident.

Read Original

The Federal Trade Commission (FTC) is currently investigating OpenAI and Anthropic over potential risks to consumers related to their artificial intelligence products. While specific details about the nature of the risks haven't been disclosed, the investigation suggests that the FTC is taking a closer look at how these companies' technologies might affect users. This scrutiny reflects growing concerns about the safety and ethical implications of AI, especially as these technologies become more integrated into everyday life. The outcome of this investigation could lead to new regulations or guidelines for AI companies, impacting how they operate and develop their products in the future.

Read Original

The White House has introduced a new Accord aimed at enhancing safety measures for artificial intelligence, particularly focusing on what is termed 'Super Intelligence.' This initiative, backed by prominent tech companies, seeks to establish stricter controls and oversight over AI systems to mitigate potential risks. The agreement emphasizes the importance of responsible AI development, aiming to prevent misuse and ensure that these technologies are safe for public use. By encouraging companies to take proactive steps in AI governance, the Accord addresses growing concerns about the ethical implications and safety challenges posed by advanced AI systems. This move is significant as it reflects a collective recognition of the need for accountability in the rapidly evolving tech landscape.

Read Original

Russian state-sponsored hackers, known as Star Blizzard, have adopted a new technique called 'RedFlick' to install malware on targeted systems. This method is primarily used to deploy their notorious CosmicPulse backdoor, which allows them to gain unauthorized access and control over compromised networks. The implications of this tactic are significant, as it enhances the hackers' ability to infiltrate systems without detection. Organizations, especially those in sensitive sectors, need to be aware of this evolving threat and take steps to bolster their defenses. As these attacks become more sophisticated, it is crucial for companies to stay informed and prepared against such state-sponsored activities.

Read Original
Actively Exploited

The Dutch Institute for Vulnerability Disclosure (DIVD) reported that its network was breached due to the exploitation of two zero-day vulnerabilities in the Zammad ticketing system, which is open-source software used by various organizations. This breach raises concerns about the security of open-source applications, as attackers were able to leverage these vulnerabilities to gain unauthorized access. The incident emphasizes the need for users of Zammad and similar systems to ensure they are up to date with security patches and to monitor their networks for any suspicious activity. As the details of the breach unfold, it serves as a reminder for organizations to prioritize vulnerability management and implement robust security measures to protect their data and infrastructure.

Read Original

A recent analysis revealed that over 543,000 valid credentials were exposed in public GitHub repositories as of July 2023. Despite GitHub's ongoing efforts to enhance security and prevent such leaks, these sensitive credentials remained accessible, raising significant concerns for developers and organizations that utilize the platform. The exposed credentials could potentially allow unauthorized access to various systems and services, putting users and their data at risk. This incident underscores the need for developers to be vigilant about securing their credentials and for GitHub to continue improving its protective measures. The scale of this exposure serves as a reminder of the persistent challenges related to data security in collaborative coding environments.

Read Original

Recent findings from Microsoft's Security Research team reveal that attackers have exploited a serious vulnerability in the Zimbra Collaboration Suite (ZCS). The flaw, identified as CVE-2026-73570, allows for unauthenticated command injection, leading to remote code execution. This means that attackers can deploy web shells to access sensitive mailbox data. Organizations using ZCS should be particularly vigilant, as this vulnerability carries a high severity score of 8.9. The fact that attackers are taking advantage of this flaw emphasizes the importance of keeping software updated and applying patches promptly to safeguard against potential data breaches.

Read Original
Page 1 of 429Next