Cybersecurity provider Huntress has identified a major security threat. What appeared to be an unassuming potentially unwanted program (PUP) has transformed into a threat that can disable antivirus systems and put thousands of endpoints at risk. As mentioned in a recent blog, the cyberattack involves the signing of an application via Dragon Boss Solutions, which researchers term adware. The software uses an apparently legitimate update service to download and run a malicious payload that has been quietly disarming antivirus tools on endpoints around the world, including universities, government agencies, power utilities, hospitals, and Fortune 500 companies. This malware was first spotted in March when some unusual events associated…
Kirsten Doyle
Hims & Hers, a telehealth company, has disclosed a data breach involving its third-party customer support ticketing system after hackers gained access between 4 and 7 February 2026. In a letter to customers, it warned of a data security incident that might have exposed their personal information. On 5 February, the company said it became aware of suspicious activity affecting its third-party customer service platform. “We promptly took steps to secure our customer service platform and initiated an investigation into the nature and scope of the potential security incident.” It added that certain tickets sent to its customer service team were accessed or acquired without authorization. “In response, we undertook a comprehensive review of the affected service tickets to determine what…
The European Commission has confirmed a cyberattack affecting its Europa.eu web platform, with initial reports indicating that the attackers accessed the data from the cloud infrastructure provided by AWS. The incident was detected on 24 March, with the commission stating that the attack was contained while the investigation is still underway. Actors affiliated with the ShinyHunters group have claimed responsibility, stating that they accessed over 350 gigabytes of data from the commission’s databases and internal documents. The Commission stated that the group accessed some of its data but did not verify the full extent. It said those affected are being notified. In a statement, the Commission said its internal systems were not affected by the…
Researchers at Endor Labs, have discovered a supply chain attack on the popular Python package LiteLLM on PyPI, with malicious code injected into versions 1.82.7 and 1.82.8, which have been withdrawn. The package is used in AI environments and developer tools, with an estimated 95 million downloads per month. The malicious packages included credential-stealing malware, including a .pth file that can run automatically when Python is started, enabling bad actors to harvest SSH keys, cloud credentials, API keys, and environment variables from infected systems. In some cases, the malware was also designed to access Kubernetes secrets and implant persistent backdoors on the compromised systems. The incident…
No longer are geopolitical standoffs settled on the traditional battlefields of diplomacy and arms; now, the digital realm has emerged as the arena for these conflicts. In this article, we bring together industry experts to discuss the dynamics of the development of cyber threats during unstable international circumstances, the role of automation and AI in the realm of cyber war, and the key issues that organisations, regardless of their level of proximity to the current geopolitical hotspot, need to be focusing on to ensure their survival in this increasingly hostile digital arena. Know thy enemy and know yourself Carl von Clausewitz famously…
The US Federal Communications Commission (FCC) has announced a plan to prevent the authorization and import of new consumer routers produced outside the US, adding them to its “Covered List” of items that pose a national security risk. This decision is a result of a government assessment that found routers produced abroad pose a critical cybersecurity and supply chain risk to US infrastructure, which has, in the past, been used in cyber incidents and could be used for network disruption, espionage, or data theft, similar to previous decisions regarding drones produced abroad. Consumer routers produced abroad dominate the US market, with an…
A newly disclosed flaw in Ubuntu’s Snap ecosystem is raising fresh concerns about local privilege escalation risks in default Linux environments. Researchers at Qualys have identified CVE-2026-3888, a high-severity vulnerability that allows a low-privileged local user to escalate access to full root control on affected systems. The problem affects default installs of Ubuntu Desktop versions 24.04 and later. In essence, the problem is caused by an unexpected interaction between two trusted components of the system: snap-confine, which is a component of application sandboxing, and systemd-tmpfiles, which is a component of temporary file cleaning. Although these components are intended to improve the security and hygiene of the system, the…
Companies House, the UK’s official registrar of companies, has disclosed a security flaw in its WebFiling service that exposed sensitive data tied to more than five million registered businesses. The issue traces back to a system update rolled out in October 2025 and went unnoticed for five months before it was flagged. The vulnerability meant logged-in users could access other companies’ records simply by manipulating browser navigation. That potentially put home addresses, email addresses, and dates of birth of company officers in view, and in some cases, may even have opened the door to unauthorized changes to filings. In response, the organisation pulled the affected service offline to…
Since the outbreak of the Middle East conflict on 28 February 2026, Akamai has seen a surge of 245% in cyberattacks against key businesses and institutions in North America, Europe, and some Asian Pacific countries. One group in particular, Handala (widely believed to have ties to Iranian intelligence) has claimed responsibility for a destructive data-wiping attack on Stryker, the global medical technology firm based in Michigan. At the same time, geopolitically motivated hacktivists are increasingly routing activity through proxy infrastructure in countries such as Russia and China, generating billions of connection attempts specifically engineered for abuse. The bulk of this malicious traffic is hitting a…
The Qualys Threat Research Unit (TRU) has identified nine vulnerabilities in AppArmor, a Linux Security Module. The vulnerability has been present since 2017 (version v4.11). AppArmor is the default mandatory access control system for Ubuntu, Debian, SUSE, and several cloud platforms. Its presence in all these systems and its use in all these platforms make the threat landscape much wider. This vulnerability, disclosed in the “CrackArmor” advisory, is a confused deputy vulnerability. It allows unprivileged users to manipulate security profiles via pseudo-files and to execute arbitrary kernel code. These weaknesses, in turn, lead to local privilege escalation to the root account through intricate interactions with tools like…
