Anviz Multiple Products
Anviz systems have critical authentication flaws (CVSS 5.3-9.8) exposing camera feeds, credentials, and root access. Vendor declined CISA's patching efforts, leaving systems unprotected.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
Latest cybersecurity breaches news, analysis, and intelligence.
Anviz systems have critical authentication flaws (CVSS 5.3-9.8) exposing camera feeds, credentials, and root access. Vendor declined CISA's patching efforts, leaving systems unprotected.
Microsoft paid $2.3M in record bounties at Zero Day Quest 2026 to identify zero-day vulnerabilities. The competition demonstrates the company's commitment to proactive security research and sets new standards for corporate bug bounty programs.
** Compromised service accounts and forgotten API keys drove 68% of 2024 cloud breaches. With 40-50 non-human identities per employee, orphaned NHIs are now the top cloud attack vector.
** A Microsoft Defender zero-day, ongoing SonicWall SSL-VPN brute-force attacks, and a 17-year-old Excel RCE headline a packed threat week. Patch urgently, enforce MFA, and assume endpoint tooling is
McGraw Hill's Salesforce environment was breached by ShinyHunters extortion group, exposing 13.5 million user accounts including students, educators, and institutions. The threat actors leaked data samples online to pressure the company into ransom negotiations.
Hackers breached Venice's flood defense for $600 ransom, exposing critical infrastructure vulnerabilities. Combined with AI tools automating exploit discovery, incidents reveal an asymmetric security advantage now favoring attackers across the board.
30+ WordPress plugins in EssentialPlugin were compromised with obfuscated malware, granting attackers backdoor admin access and enabling data theft on thousands of sites in a critical supply chain attack.
Microsoft awarded $2.3M to researchers for critical cloud and AI vulnerabilities enabling privilege escalation and data access. The record bounty underscores the severity of enterprise security threats in cloud-native environments.
Kraken faces extortion from hackers claiming insider access to internal systems storing customer data. The exchange confirmed the threat but found no evidence customer funds were compromised, and law enforcement is investigating the breach.
McGraw-Hill suffered a breach via misconfigured Salesforce, exploited by extortionists demanding payment. It exposed personal data and underscores risks of cloud misconfigurations.
Stolen credentials are in 60% of breaches. Zero Trust shifts from trusting the firewall to validating every access request, making identity verification the new security perimeter.
**Europe's largest gym chain disclosed a breach affecting 1 million members across 12+ countries, exposing personal data including health metrics, payment information, and identity documents. Unauthorized access persisted for approximately 8-10 months before detection.** (186 characters, 2 sentence
Dutch fitness chain Basic-Fit exposed approximately 1 million gym members' personal data across Europe after attackers breached its systems. The intrusion was discovered during routine security monitoring, making it one of the largest incidents targeting the fitness industry.
ShinyHunters breached Anodot's analytics platform, exposing Rockstar Games customer data. After failed ransom demands, the gang published the stolen files, demonstrating third-party vendor risks.
Booking.com disclosed a data breach exposing millions of users' reservation data and credentials, prompting mandatory password resets. The breach may have persisted undetected for an extended period before discovery through unusual account activity and unauthorized login attempts.
OpenAI rotated macOS code-signing certificates after malicious Axios ran in its CI/CD pipeline. Stolen certs could let attackers sign trojanzied software appearing legitimate, bypassing user trust.
Booking.com confirmed a breach without disclosing how many customers were affected. The incident raises concerns about unauthorized access to sensitive payment and personal information.
APT37 uses Facebook to slowly build fake friendships before delivering RokRAT malware to high-value targets, exploiting social media's normalized trust mechanisms for advanced cyber espionage.
OpenAI revoked its macOS certificate after a compromised Axios dependency infiltrated its code-signing workflow. No user data was exfiltrated, but the incident exposes supply chain vulnerabilities in modern software development.
Threat actors breached CPUID in April 2025 for 19 hours, distributing STX RAT malware via trojanized CPU-Z and HWMonitor downloads. Millions of IT professionals and system administrators unknowingly received compromised hardware monitoring tools in the supply chain attack.
Hims' breach exposed sensitive PHI for hundreds of thousands—prescriptions, diagnoses, payment data, genetic info—creating major fraud and identity theft risks.
Modern breaches hide in plain sight by mimicking routine business activity. Attackers now prioritize stealth and long-term access (averaging 204 days undetected) over dramatic exploits, using legitimate credentials to evade traditional security defenses.
CPUID was compromised, redirecting CPU-Z and HWMonitor downloads to serve malware. This supply chain attack impacted millions of users relying on official software sources.
Iranian state-linked threat actors have mapped ~4,000 Internet-exposed Rockwell Automation industrial controllers controlling US critical infrastructure like power grids and water systems. The systematic targeting suggests strategic staging for future large-scale cyberattacks on essential services.
Iran-attributed groups escalate ICS attacks on critical infrastructure. They've shifted from random scanning to highly targeted intrusions with sophisticated multi-stage operations.
CPUID's distribution was compromised, injecting malware into official CPU-Z and HWMonitor packages. Users downloading these widely-trusted system tools unknowingly received malicious versions.
Nextend's update servers were compromised, distributing backdoored Smart Slider 3 Pro to thousands of WordPress sites. Attackers exploited the trusted update mechanism to inject malware undetected.
Google is launching cookie theft protections in Chrome to prevent session hijacking. Stolen cookies enable attackers to bypass authentication and access user accounts without passwords.
Ceasefires rarely curb state-sponsored cyberattacks due to attribution challenges and weak international agreements. Iranian cyber actors like IRGC Cyber Command operate in diplomatic gray zones, continuing operations despite military truces.
Attackers hijacked Smart Slider 3 Pro's update system to distribute backdoors affecting 100,000+ WordPress/Joomla sites, granting persistent administrative access through legitimate-appearing updates. This supply chain attack exemplifies the trend of targeting popular CMS plugins for maximum impact.