CISA Warns of Active Exploitation of Three Linux Kernel Flaws
CISA has issued an alert about active exploitation of three Linux kernel vulnerabilities, including one critical severity flaw affecting Linux systems.
Tag
80 results in the archive.
CISA has issued an alert about active exploitation of three Linux kernel vulnerabilities, including one critical severity flaw affecting Linux systems.
North Korean hackers behind the Contagious Interview campaign compromised over 30,000 devices worldwide, targeting crypto specialists and web designers to steal $10.7 million from more than 7,000 cryptocurrency wallets.
A critical unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor affecting versions prior to 3.30.2 is actively exploited and presents severe security risks.
The North Korean group WaterPlum compromised over 30,000 devices worldwide, stealing more than $10.7 million in cryptocurrency between December 2025 and July 2026.
Researchers identified RatHat, an Android malware using AI and abusing ADB to maintain shell access post-uninstallation, spreading via smishing and malvertising.
The Pakistan-aligned threat group Transparent Tribe (APT36) has launched cyber attacks using new Rust-based backdoors and private GitHub command and control, targeting government and defense sectors in India and Afghanistan.
RatHat is a newly discovered Android malware that incorporates an AI-powered subsystem enabling attackers to remotely control compromised devices, streamlining exploitation actions.
An attacker hijacked an AI coding assistant session to distribute the Shai-Hulud worm within approximately 100 internal code repositories at a SaaS provider, resulting in theft of repository secrets and source code.
A critical vulnerability in the Issabel Framework allows unauthenticated remote OS command execution, actively exploited and posing a severe security risk.
An attacker used a MeshCentral backdoor to gain root access to internal systems at 3BB, a major Thai broadband provider, exposing subscriber credentials and internal tools.
A mass-scanning campaign targets internet-exposed Vite development servers to steal cloud credentials linked to AWS and Azure environments.
The state-sponsored threat actor Red Heron exploited a remote code execution vulnerability in Gitea to compromise 13 organizations across six countries in a rapid, targeted campaign.
Microsoft disclosed campaigns where attackers exploited third-party email systems for large-scale financial scam phishing and used passkey-themed social engineering techniques to compromise cloud accounts.
The China-linked threat group UNC3569 exploited a vulnerability in Sogou Input Method on Windows to deploy the GRAYRABBIT backdoor, allowing attackers full control of the affected user's machine.
A Russian-speaking threat actor used hundreds of AI agents to exploit vulnerabilities in PaperCut NG/MF servers, compromising 395 organizations worldwide and highlighting the operational risks of AI-driven cyberattacks.
CISA has listed two critical actively exploited MikroTik RouterOS vulnerabilities in its Known Exploited Vulnerabilities Catalog, highlighting the need for prioritized remediation.
Two patched vulnerabilities in Cisco Secure Firewall Management Center are actively exploited by ransomware gangs and state-sponsored hackers, threatening critical network security infrastructure.
U.S. cybersecurity and intelligence agencies accuse China-based AI firms of industrial-scale distillation attacks on proprietary AI models including Claude, GPT, Gemini, and Grok, raising concerns over AI intellectual property security.
NSA, CISA, and FBI warn that China-based AI companies are systematically extracting proprietary functionalities from US AI models at scale using industrial distillation techniques.
A Linux rootkit targets F5 BIG-IP APM devices by injecting fileless web shells into memory through PHP file loading interception, complicating detection.
JSCeal malware is a sophisticated JavaScript-based threat that bypasses Google authentication by stealing session cookies and uses advanced obfuscation to evade detection.
Threat actors use invisible Unicode characters in phishing emails to evade detection by security filters, complicating phishing identification.
MikroTik released a patch for an SSH authentication bypass vulnerability currently exploited to create unauthorized accounts on devices.
Elastic Security Labs identified four REVSTEALER-associated programs that disable Windows Update and Defender to deploy a cryptocurrency miner, persisting even after the main stealer removes itself.
Over 5,400 small-business websites have been compromised to distribute ClickFix malware payloads stored in smart contracts on the BNB Smart Chain, using blockchain to evade detection.
Attackers are leveraging invisible Unicode characters originally used to evade AI detection as a new method to obfuscate phishing emails and bypass security filters.
Two zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances, including a critical pre-authentication SSRF flaw, are being exploited in the wild.
Attackers leveraged a BGP hijack to redirect Softaculous update traffic, delivering a malicious Virtualizor update that established persistent root access on five hypervisors.
The Iranian group Nimbus Manticore uses recruiter-themed coding tests to distribute Node.js and JavaScript remote access Trojans on Linux and macOS platforms, as reported by Kaspersky.
The China-linked Fire Ant group has compromised Cisco IOS XR routers, TACACS servers, and Linux hosts to steal credentials and disable security logs, targeting critical network infrastructure.
Attackers repurposed a public LLM inference honeypot to access sensitive coding-agent session information without executing tools, highlighting risks of using untrusted LLM endpoints.
Microsoft Threat Intelligence analyzes the TerminalFix campaign, which leverages fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel for multistage intrusion.
Researchers discovered 19 malicious Chrome and Edge browser extensions that steal cryptocurrency wallet secrets, indicating a coordinated campaign.
A critical ownCloud vulnerability tracked as CVE-2023-49105 has been added to CISA's KEV catalog following exploitation by a Chinese-speaking threat actor targeting a Philippine nuclear research organization.
Multiple critical vulnerabilities in Ebyte NE2-D11 devices allow unauthorized administrative access, data exposure, and operational disruption, affecting critical infrastructure controls.
Over 270 Zimbra Collaboration Suite servers have been breached through exploitation of a critical remote code execution vulnerability, exposing organizations to significant security risks.
Oasis Security disclosed a vulnerability in NVIDIA NemoClaw that allows attacker-controlled webpages to manipulate local Ollama AI agent models through injection of hidden commands, risking unauthorized AI model poisoning without authentication.
The Chinese-speaking cybercrime group UAT-10147 leverages AI to launch scaled attacks on Windows and Linux web servers worldwide and deploys advanced tools including the SPECTRE EDR bypass and Linux rootkit.
SynkLoader malware is delivered through a Microsoft Teams phishing campaign that uses a fake lock screen to steal enterprise user credentials, enabling unauthorized access.
A critical code injection vulnerability in GitLab, CVE-2026-19478, is actively exploited shortly after disclosure, enabling unauthenticated attackers to modify or delete certain publicly accessible projects.
Over 9,300 AWS access keys leaked between 2022 and 2026 remain active, exposing corporate accounts to unauthorized access risks.
CISA warns that threat actors are actively exploiting a critical vulnerability in the MLflow AI engineering platform, posing risks to federal agencies and beyond.
The StopAndProtect campaign uses nearly 2,000 compromised WordPress sites worldwide to distribute malware and collect stolen data, impacting web infrastructure security.
Researchers demonstrated that malicious payloads can spread between AI agents by exploiting editable persistent prompt files in autonomous AI systems.
CISA has added a critical Ray Framework vulnerability enabling browser remote code execution to its Known Exploited Vulnerabilities catalog, noting ongoing exploitation.
MacSync Stealer evades detection by rapidly rotating domains, but Microsoft identified over 30 related domains by analyzing consistent behavioral patterns to uncover its infrastructure.
A high-severity out-of-bounds read vulnerability in Siemens Parasolid parsing X_T files allows potential arbitrary code execution, affecting versions prior to V38.0.235 and V38.1.230.
The ShinyHunters group breached RingCentral in July, compromising personal data of 1.6 million user accounts.
The Jewelbug hacker group has breached government and military webmail accounts while simultaneously conducting cryptocurrency fraud, illustrating a dual-threat approach involving cyber espionage and financial crime.
The 'ShieldBreak' zero-day exploit targeting Microsoft Defender enables attackers to obtain SYSTEM-level privileges on affected systems following the August 2026 Patch Tuesday.
Healthcare software provider Unlimited Technology Systems disclosed an October 2025 breach impacting over 3.8 million individuals and sensitive healthcare data.
Meta confirmed that one of its AI models inadvertently hacked a company during a misconfigured cybersecurity test, revealing risks in AI security testing.
The Greatness phishing-as-a-service toolkit now uses device code phishing to exploit OAuth 2.0 Device Authorization Grant, bypassing MFA and hijacking accounts.
Talos analyzed prompt logs from various AI applications used by threat actors to understand their evolving tactics, revealing increased sophistication in leveraging cloud-based AI for malicious activities.
Adform's advertising scripts were compromised in a supply-chain attack that hijacks clipboard cryptocurrency addresses to redirect funds to attackers.
Cisco disclosed a high-severity zero-day vulnerability in its Secure Firewall Management Center involving static credentials, actively exploited to gain unauthorized access.
A coordinated cyberattack targeted operational technology at over 30 Minnesota community water systems in late July, causing outages and communication disruptions.
Iranian state-backed group Nimbus Manticore deploys NightLedger backdoor and custom WebSocket tunnelers in attacks across the Middle East, Africa, and South Asia, enhancing stealth and covert activity.
NVIDIA and 36 organizations have established the Open Secure AI Alliance to develop collaborative open technologies aimed at securing AI and software environments.
An open-source AI agent named Hermes was used to automate post-exploitation processes in an alleged breach of Thailand's Ministry of Finance, demonstrating AI's expanding role in cyberattacks.
A malvertising campaign named SourTrade targets retail traders by using browsers and a legitimate Bun runtime to assemble Windows malware executables, evading traditional detection methods.
The Certighost exploit enables low-privileged Active Directory users to obtain Domain Controller certificates and authenticate as domain controllers, risking critical Kerberos credential compromise.
A malvertising campaign on Bing promotes a fake Claude desktop app from a legitimate domain to deliver SectopRAT malware, posing a threat to affected systems.
The Anubis ransomware group has claimed responsibility for a cyberattack on Coca-Cola's Fairlife brand and threatened to leak stolen data if ransom demands are not met.
Russian intelligence services compromise internet-connected security cameras across Europe and Ukraine to gather military logistics intelligence, as reported by the Netherlands' AIVD and MIVD.
An advanced threat actor exploits the update mechanism of ViPNet private networking software to attack Russian government agencies, illustrating ongoing espionage.
Abbott Laboratories is investigating unauthorized access incidents affecting Exact Sciences legacy systems and its LabCentral portal, with allegations of stolen company data linked to extortion.
North Korean threat actors linked to the Contagious Interview campaign employ steganography within SVG flag images in fake coding challenges to deliver multi-stage OTTERCOOKIE-aligned malware.
ClickLock is a new macOS information-stealing malware that tricks users into revealing their system login password by terminating visible processes.
The OkoBot malware framework deploys more than 20 payloads aimed at stealing cryptocurrency wallet seed phrases, credentials, and sensitive data, posing a notable threat to individuals and enterprises.
CISA issued a warning about three actively exploited vulnerabilities in Internet-exposed on-premises SharePoint Server instances that allow remote compromise.
Zoom has disclosed a critical vulnerability in its Windows desktop client and SDK that enables unauthenticated attackers to hijack user accounts, posing a significant security risk.
Microsoft released its largest Patch Tuesday, addressing 622 security flaws including two actively exploited zero-day vulnerabilities, critical for millions of affected systems.
A threat actor created almost 300 counterfeit GitHub repositories impersonating legitimate software projects to deliver infostealer malware, posing a significant supply chain threat.
Spanish Police arrested four individuals and dismantled a cybercrime network responsible for €140 million in losses through investment fraud and business email compromise attacks.
CISA warns that remote code execution vulnerabilities are actively exploited in Joomla iCagenda and Balbooa Forms extensions through arbitrary file uploads, risking full compromise of affected sites.
Google and Microsoft removed the ModHeader browser extension from their stores due to a dormant hidden browsing-history collector found in the official version, with no evidence of active data transmission.
The MemGhost attack allows adversaries to implant persistent false information into AI assistants through a single email, altering AI behavior and posing a risk to AI response integrity.
The jscrambler npm package version 8.14.0 was compromised to install a Rust-based infostealer via a preinstall hook, impacting Windows, macOS, and Linux environments.
Researchers reveal cyber espionage targeting Pakistani law enforcement by suspected China- and India-aligned groups between 2024 and 2026, compromising police servers with critical data.