Tag: emerging threats
5091 articles

Apple Bolsters iOS Security to Counter DarkSword Web Exploit Kit
Apple just took a major step to safeguard its users by expanding its iOS security update to include older devices, shielding them from the DarkSword web exploit kit. This move ensures that users with older devices, as well as enterprises relying on long-lived hardware, receive crucial protection against potential threats.

Stryker Recovers from Data-Wiping Cyberattack Claimed by Handala Hackers
In a remarkable comeback, Stryker Corporation has bounced back to full operation just three weeks after a devastating data-wiping cyberattack erased many of its systems, claimed by the Iranian-linked Handala hacktivist group. The global medical-technology giant has successfully restored its operations, showcasing resilience in the face of cyber threats.

Progress ShareFile Flaws Enable Pre-Auth RCE Attacks
When the tool designed to safeguard confidential documents becomes a vulnerability, data theft can occur without a single login credential. Progress ShareFile's two chained flaws allow for pre-authentication remote code execution attacks, putting sensitive files at risk of unauthorized exfiltration.

Fake ISO Installers Spread RATs, Crypto Miners in Global Campaign
Beware of fake ISO installers that masquerade as legitimate software, but secretly unleash a malicious payload of RATs, crypto miners, and CPA fraud on unsuspecting victims. For over two years, a financially motivated operation, codenamed REF1695, has been quietly spreading malware through these Trojan horses.

Google Exposes Sophisticated iPhone Hacking Tool Likely Tied to US Government
Imagine a single website visit being all it takes to secretly install malware on your iPhone, bypassing every defense along the way - that's the alarming reality uncovered by Google's security researchers. They've discovered a sophisticated hacking tool, dubbed Coruna, that exploits 23 iOS vulnerabilities to silently compromise devices.

Cisco Patches Authentication Bypass in Integrated Management Controller
Cisco just patched a critical vulnerability in its Integrated Management Controller that lets attackers bypass authentication and gain Admin access - essentially, walk right past the lock on the network's control panel. This fix is a must-have for any Cisco IMC users looking to keep their network secure.

WhatsApp Exposes Italian Users to Spyware via Fake iOS App
WhatsApp has alerted around 200 users, mostly in Italy, about a sneaky spyware attack that hit them after they downloaded a fake version of the app for iOS. This alarming incident raises a crucial question: how can you trust that the app on your phone is genuine?

Microsoft Probes Outlook Disruption Tied to Email Delivery Issues
Microsoft is investigating a frustrating issue affecting Classic Outlook users, preventing them from sending emails via Outlook.com due to a bug linked to broader email delivery problems. The disruption is causing inconvenience for users relying on seamless communication.

F5 BIG-IP Instances Vulnerable to Ongoing RCE Attacks
With over 14,000 F5 BIG-IP Access Policy Manager instances exposed online, a critical vulnerability is putting countless systems at risk of remote code execution attacks. Attackers are actively exploiting this flaw, making it crucial for organizations to take immediate action to protect themselves.

OT Attacks Threaten £5m Downtime Hit on CNI Firms
A single cyberattack on operational technology systems could cripple critical infrastructure providers, causing up to £5m in downtime losses and days of operational paralysis. For organisations that underpin essential services, the stakes have never been higher.

Coffee Machines Expose Corporate Networks to Hacking Risks
Your daily cup of coffee might be putting your company's network at risk of a massive breach, thanks to the humble coffee machine's connection to the internet. Connected devices like these can unwittingly create a backdoor for hackers into an otherwise secure environment.

Google Tightens Android App Verification for Sideloaded Software
Google is shaking things up in the mobile world by introducing a new requirement for Android apps installed outside its official store: developers must now verify their identity to ensure user safety. This move aims to strike a balance between platform openness and protection from potential harm.

Mercor Hit in Widespread LiteLLM Supply-Chain Attack
Thousands of companies, including AI hiring startup Mercor, have been hit by a widespread LiteLLM supply-chain attack, marking the first publicly disclosed downstream casualty of a software supply-chain intrusion. This incident raises a critical question: how can organizations trust their tech toolchains when the chain itself can be compromised?

CrystalRAT Malware Emerges with Advanced RAT and Data Theft Capabilities
Meet CrystalRAT, a powerful malware-as-a-service that's being sold on Telegram, capable of giving outsiders remote control of your computer, stealing sensitive files, recording every keystroke, and even hijacking your clipboard. This malicious tool is a nightmare come true, and its emergence poses a serious threat to online security.

Hackers Exploit TrueConf Flaw to Deploy Malicious Updates
Imagine the video conferencing platform you rely on to connect with your team being turned against you, allowing hackers to spread malicious software to everyone in the room. A recently discovered zero-day flaw in TrueConf's update mechanism has been exploited by threat actors to deliver and execute malicious files on connected devices.

Apple Bolsters iOS 18 Defenses Against DarkSword Exploit Kit
Apple is stepping up its game to protect iPhone users with a new security update for iOS 18, shielding against the sneaky DarkSword exploit kit that's been compromising devices. This proactive move is a crucial defense in the ever-evolving world of cybersecurity threats.

Unified Platforms Fortify Recovery Against Ransomware, AI Threats
As ransomware attacks intensify and AI-powered threats accelerate, consolidating infrastructure and automating recovery can be a game-changer for organizations, enhancing safety while slashing costs. By fortifying defenses with unified platforms, IT leaders and senior managers can meaningfully reduce risk and stay ahead of evolving cyber threats.

US Cyber Strategy May Embolden Private Sector Hackback
The Biden administration's 2026 Cyber Strategy for America is making waves with a bold call to action: unleashing the private sector to disrupt adversary networks and scale national cyber capabilities. This single move has sparked debate and concern, effectively greenlighting private companies to conduct hackback operations - a concept that's simple in theory but fraught with danger in practice.

HHS Realigns Cyber, AI Oversight Under CIO Office
The US Department of Health and Human Services has realigned its cyber and AI oversight under the Chief Information Officer's office, a move that aims to bolster protection of the nation's sensitive health data. This change reverses previous structural adjustments, refocusing the Office of the National Coordinator for Health IT on external policy and standards.

Qodo Raises $70M to Mitigate AI Code Risks with Governance Platform
As businesses increasingly turn to AI to generate production code, a pressing question emerges: who will be accountable when machines write the software that runs our critical systems? With AI-generated code comes a new set of risks - bugs, security threats, and noncompliance - that governance gaps must address to ensure speed and scale don't compromise safety and reliability.

Anthropic Leak Exposes AI Security Fault Lines
A recent leak of source code linked to Anthropic's Claude model has exposed a gaping hole in AI security, revealing a fissure between AI developers and cybersecurity firms that's putting national security, consumer trust, and responsible AI development at risk. This incident highlights the urgent need for stronger safeguards to prevent digital harms as AI capabilities continue to advance at breakneck speed.

AI Boosts Pentesting Efficiency by 40% at Amazon
Amazon's security team has achieved a game-changing 40% boost in pentesting efficiency by harnessing the power of artificial intelligence, significantly speeding up the process of identifying vulnerabilities and keeping the internet more secure. This innovative approach is a major win for productivity and a strong indicator of AI's growing role in cybersecurity.

EvilTokens Fuels Sophisticated Microsoft Phishing Attacks
This month, a commercially available toolkit called EvilTokens made it alarmingly easy for fraudsters to launch sophisticated Microsoft phishing attacks, putting corporate email systems and Microsoft accounts directly in their crosshairs. By exploiting device code authentication, a feature designed to simplify login, EvilTokens has turned a convenient tool into a potent weapon for organized cybercrime.

CERT-UA Warns of AGEWHEEZE Malware Spread via Impersonation Campaign
Beware of scammers impersonating Ukraine's cyber emergency team, CERT-UA, in a massive phishing campaign that sent nearly one million emails with a malicious payload. The attackers used a clever tactic, disguising their malware, known as AGEWHEEZE, as a legitimate warning from a trusted source.