#1 Trusted Source for Cybersecurity News

cybersecurity updates

The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra . “The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened,” ZeroBEC said in a report published last week. Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs “secure document” lures to deliver legitimate remote monitoring and management ( RMM ) tools.

  • Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.
  • They use fake profiles and social engineering tactics to distribute malware and steal cryptocurrency.
  • Mindgard researcher Aaron Portnoy disclosed a code execution flaw in Cursor AI editor that silently runs trojanized git.exe files when developers clone malicious repos.
  • Zero Trust in 2026 means verifying every single access request as if it came from an open web.

Group-IB documented ClickLock, a macOS stealer using a 210ms app-kill loop to coerce macOS passwords, hitting more than 100 victims across 33 countries. A single resource that provides you with access to information on services across CISA’s mission areas. The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

A new phishing operation, tracked as Operation BlueDash, is tricking https://innovatenexes.com/securing-business-networks.html users into installing a fake Microsoft Teams update that silently hands attackers not one… Our reviews provide clear, research-backed insights for confident choices. “The portal combined build generation, finance, victim chat, support, victim records, teams, and payout functions,” the company said in an extensive report shared with The Hacker News. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis . As phishing campaigns become more sophisticated, simply identifying malicious websites and impersonation domains is no longer enough.

Fake SBI Reward App Delivers Android Malware

cybersecurity updates

Oracle patched 318 vulnerabilities across its product suite, including critical flaws in Fusion Middleware, MySQL, and Database Server with CVSS scores up to 9.9. Over 50,000 Fortinet firewalls remain vulnerable to an authentication bypass flaw enabling super-admin access via crafted WebSocket requests. Canonical has patched 126 vulnerabilities affecting Linux kernel subsystems, including networking, file systems, and drivers, for Ubuntu 22.04 LTS users.

“We have no evidence of impact to customer information stored outside of GitHub’s internal repositories, such as our customer’s own enterprises, organizations, and repositories,” Alexis Wales, Chief Information Security Officer of GitHub, said in a statement. The security flaw, per Rapid7, is rated 9.4 on the CVSS scoring system. The victim calls itself a small county with limited resources.

cybersecurity updates

This case highlights the deceptive nature of such schemes, illustrating how easily individuals can fall victim to these ruses. He emphasized evaluating human awareness within organizations as the crucial link in cybersecurity, identifying potential threats, and rectifying vulnerabilities. This workshop not only solidified Anxinsec’s role as a contributor to the cybersecurity community but also provided a platform for industry professionals to advance cybersecurity practices and insights collectively. Experts caution that such social engineering tactics, including email, phone, text, and social media channels, serve as gateways for hackers aiming to extract sensitive information from corporations and individuals. An NWS spokesperson emphasized their multi-layered security that successfully detected and https://www.faststartfinance.org/kv-berlin-muster-datenschutz/ rebuffed these LinkedIn-based intrusion attempts, aligning with the larger trend of hackers using social media platforms to breach security. Despite these attempts, Parr affirmed that no cyber incidents significantly impacted RWM’s operations last year.

Embracing these advanced defensive approaches is key to combating the relentless evolution of automated cyber threats. A single compromised device can grant attackers system-wide control, leading to blackouts or disrupted utilities. Defensive measures that can dramatically lower risk meanwhile include zero trust frameworks, AI-based anomaly detection, and continuous patching. If your organization’s goal is to protect data, maintain trust, and avoid costly downtime, it’s essential to stay on top of the mentioned cyber security trends that will shape 2026. Below, we explore six ways these trends are manifested in real-world settings, including DevSecOps pipelines and continuous vulnerability scans. It’s one thing to understand the latest cyber security trends, but it’s another to implement them https://bussinessfair.info/revolutionizing-strategies-exploring-the-role-of-ai-in-modern-strategic-management.html effectively, bridging knowledge gaps and adapting internal processes.

  • Hackers accessed insurance, treatment, and personal data months before victims were finally notified.
  • An NWS spokesperson emphasized their multi-layered security that successfully detected and rebuffed these LinkedIn-based intrusion attempts, aligning with the larger trend of hackers using social media platforms to breach security.
  • If you’re serious about building these skills, a Cyber security and ethical hacking course in India will provide real-world exercise that can arm you for real control environment versus presumed conflict situations.
  • More alerts are making your team slower, and an outcome-based SOC fixes that July 20, 2026
  • These actions create urgency for organizations to re-examine their compliance obligations, decrease/HASTEN incident response timelines, and strengthen controls for vendor risk management.
  • Cybersecurity experts are urging ICICI Bank to act swiftly to mitigate risks, including enhancing security protocols and collaborating with law enforcement.

cybersecurity updates

Agentic artificial intelligence is creating enough risks for organizations to demand a security reframe. Dark Reading editors reflect on two decades of dramatic change — from perimeter defense to assume-breach strategies — and warn that while AI, cloud, and COVID-19 have transformed the threat landscape, organizations are still failing at fundamental security hygiene that could stop sophisticated attacks in their tracks. Interlock ransomware targeted DC’s public housing agency; Play posted five victims across four countries; Nova added three more in a multi-group batch. Elastic Security Labs disclosed TELEPUZ, a C-based malware distributed through a ClickFix-to-Vidar chain with VirusTotal volumes indicating a MaaS operation.