Latest Cybersecurity News and Articles


Cybersecurity Startup Protexxa Closes $10M Series A Round

24 July 2024
Protexxa, a Toronto-based B2B SaaS cybersecurity company founded by Claudette McGowan, has secured $10 million in Series A funding from various investors including Bell Ventures and private investors like Sonia Baxendale and Annette Verschuren.

Malware Campaigns Target Hamster Kombat Players

24 July 2024
Threat actors are targeting Hamster Kombat's 250 million players with fake Android and Windows software that install spyware and malware. The clicker mobile game allows players to earn fictional currency by completing simple tasks.

Philippines to End Online Casinos, Maybe Scams Too

24 July 2024
The Philippines has decided to shut down its online gambling industry to tackle illegal activities such as financial scams and human trafficking. President Ferdinand Marcos Jr instructed PAGCOR to cease operations of POGOs by the end of the year.

DeFi Crypto Exchange dYdX v3 Website Hacked in DNS Hijacking Attack

24 July 2024
dYdX's decentralized finance (DeFi) exchange v3 website was hacked in a DNS hijack attack, compromising the platform. Users were warned not to visit or interact with the hacked website and to avoid withdrawing assets until the platform was safe.

Russia Shifts Cyber Focus to Battlefield Intelligence in Ukraine

24 July 2024
Multiple Russian cyber units are targeting frontline Ukrainian military computers and mobile devices in preparation for a summer offensive. This change reflects Russia's adaptation to the demands of a prolonged war in Ukraine.

Security leaders share thoughts on Microsoft-Crowdstrike outage

24 July 2024
Security leaders have shared their thoughts about the Microsoft-Crowdstrike outage and advice for other organizations to protect themselves.

SEC establishes Interagency Securities Council (ISC)

24 July 2024
The SEC has established the Interagency Securities Council (ISC) to support collaboration between federal, state and local agencies. 

Telegram App Flaw Exploited to Spread Malware Hidden in Videos

24 July 2024
A zero-day security flaw in Telegram's mobile app for Android called EvilVideo made it possible for attackers to malicious files disguised as harmless-looking videos. The exploit appeared for sale for an unknown price in an underground forum on June 6, 2024, ESET said. Following responsible disclosure on June 26, the issue was addressed by Telegram in version 10.14.5 released on July 11. "

Fake CrowdStrike Repair Manual Pushes New Infostealer Malware

24 July 2024
The Daolpu malware collects account credentials, browser history, and cookies from Chrome, Edge, Firefox, and other browsers. It is spread through malicious document attachments in phishing emails that contain malicious macros.

How a Trust Center Solves Your Security Questionnaire Problem

24 July 2024
Security questionnaires aren’t just an inconvenience — they’re a recurring problem for security and sales teams. They bleed time from organizations, filling the schedules of professionals with monotonous, automatable work. But what if there were a way to reduce or even altogether eliminate security questionnaires? The root problem isn’t a lack of great questionnaire products — it’s the

Report: HHS Needs to Beef up Cloud Security and Skills

24 July 2024
The Department of Health and Human Services is facing cloud security issues, with weaknesses in security controls and inventories of cloud systems. Over 30% of their systems are in the cloud, putting them at risk of compromise.

Chinese Espionage Group Upgrades Malware Arsenal to Target All Major Operating Systems

24 July 2024
The new Macma macOS backdoor is capable of data exfiltration through functionalities like device fingerprinting, keylogging, audio capture, and file uploading and downloading.

Alphabet's Reported $23B Bet on Wiz Fizzles Out

24 July 2024
Alphabet's planned $23 billion acquisition of cybersecurity firm Wiz has fallen through, leading Wiz to pursue its own path toward an IPO and aiming for $1 billion in annual recurring revenue (ARR).

How to Reduce SaaS Spend and Risk Without Impacting Productivity

24 July 2024
There is one simple driver behind the modern explosion in SaaS adoption: productivity. We have reached an era where purpose-built tools exist for almost every aspect of modern business and it’s incredibly easy (and tempting) for your workforce to adopt these tools without going through the formal IT approval and procurement process. But this trend has also increased the attack surface—and with

Infostealer Campaign Exploits Microsoft Windows SmartScreen Flaw to Spread Payloads

24 July 2024
A security flaw in Microsoft Defender SmartScreen was exploited to deliver ACR, Lumma, and Meduza stealers in a recent campaign. The campaign targeted Spain, Thailand, and the U.S. by using booby-trapped files exploiting CVE-2024-21412.

The Power and Peril of RMM Tools

24 July 2024
RMM tools have become essential in managing remote devices, but they also pose risks if exploited by threat actors. Attackers can gain remote access to devices, exfiltrate data, and remain undetected.

Patchwork Hackers Target Bhutan with Advanced Brute Ratel C4 Tool

24 July 2024
The threat actor known as Patchwork has been linked to a cyber attack targeting entities with ties to Bhutan to deliver the Brute Ratel C4 framework and an updated version of a backdoor called PGoShell. The development marks the first time the adversary has been observed using the red teaming software, the Knownsec 404 Team said in an analysis published last week. The activity cluster, also

Possible APT28-linked Hackers Target Ukraine’s Scientific Institutions

24 July 2024
APT28-linked hackers have targeted Ukraine's scientific institutions in a cyber-espionage campaign, believed to have ties to the Kremlin-backed group APT28, also known as Fancy Bear and BlueDelta.

Google Abandons Plan to Drop Third-Party Cookies in Chrome

24 July 2024
Google has decided to continue supporting third-party cookies, instead proposing a new approach that allows users to opt-in to their Privacy Sandbox. This comes after criticism and regulatory pressure over privacy concerns and competition issues.

Chinese ‘Cybercrime Syndicate’ Behind Gambling Sites Advertised at European Sporting Events

24 July 2024
Infoblox revealed a Chinese cybercrime syndicate called Vigorish Viper behind illegal online gambling brands advertised at European football stadiums. The group is linked to online gambling and cyber fraud-related human trafficking in Southeast Asia.