Security news

Latest security news

70 of 1,256 storiesTopic: Nation StateClear all

Mon, 7 Sept 2026

  1. How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

    If you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed. Read more in my article on the Hot for Security blog.

    Graham Cluley

Fri, 4 Sept 2026

  1. DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

    Overview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engage in long-term surveillance. The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected. Operating alongside this are an SSH keylogger, a curl-based RAT, and a stager. The RAT maintains a watchdog thread dedicated to tracking HAProxy’s health, and reporting it back to the operator’s infrastructure. The earliest uploads on VirusTotal date back to mid-2025 and the

    Rapid7 BlogLinux

Tue, 1 Sept 2026

  1. White House Launches Pilot Program in Texas to Protect Water Infrastructure

    Project Watershed 250 will see water providers in Texas provided with federal and private sector cybersecurity resources amid rising nation-state threats

    Infosecurity Magazine

Fri, 28 Aug 2026

  1. Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more

    More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm - two men now face charges over TeamPCP's global hacking spree. Read more in my article on the Hot for Security blog.

    Graham Cluley

Thu, 27 Aug 2026

  1. Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

    Introduction Despite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social Security numbers (SSNs) represent a far more permanent and dangerous tier within the cybercrime ecosystem, because unlike payment cards, they cannot simply be deactivated. Once exposed, an SSN can support enabling unauthorized lines of credit, synthetic identity fraud, and sophisticated tax scams. When exposed identity data belongs to corporate executives, board members, and other high-profile employees, the risk can extend beyond the individual. Threat actors target these high-profile individuals not just for their premium credit profiles, but to leverage their compromised identities for executive impersonation, corporate espionage, and downstream extortion. Rapid7’s recent alert telemetry underscores the severity of this targeted exposure: since early 2026 alone, we iden

    Rapid7 Blog
  2. Russian Hackers Phish EU Officials Over Messaging Apps

    EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.

    Dark Reading

Wed, 26 Aug 2026

  1. Dark Caracal Adds New Malware to Cyber Espionage Arsenal

    GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.

    Dark Reading
  2. Red Flags That Expose Fake North Korean IT Workers

    North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.

    Dark Reading

Fri, 21 Aug 2026

  1. North Korean Hackers Tied to Rust Supply Chain Attack

    Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks

    Infosecurity Magazine

Fri, 14 Aug 2026

  1. APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

    Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

    SecurelistWindows

About this news

1,256
Stories
39
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets