Latest Cybersecurity News and Articles


Low-Drama ‘Dark Angels’ Reap Record Ransoms

05 August 2024
A ransomware group called Dark Angels made headlines this past week when it was revealed the crime group recently received a record $75 million data ransom payment from a Fortune 50 company. Security experts say the Dark Angels have been around since 2021, but the group doesn't get much press because they work alone and maintain a low profile, picking one target at a time and favoring mass data theft over disrupting the victim's operations.

US Senate Confirms First DOD Cyber Policy Chief

05 August 2024
The Senate has confirmed Michael Sulmeyer as the first cyber policy chief at the Defense Department, where he will serve as the assistant secretary of Defense for cyber policy.

More Legal Records Stolen in 2023 Than Previous 5 Years Combined

05 August 2024
The sensitive nature of legal data makes law firms lucrative targets for hackers, who aim to access valuable information for specific purposes. Despite the costly demands, firms face the dilemma of paying the ransom or risking backlash from clients.

Organizations Fail to Log 44% of Cyberattacks, Major Exposure Gaps Remain

05 August 2024
According to Picus Security, organizations are failing to detect 44% of cyberattacks, revealing major exposure gaps. 40% of environments tested allowed for attack paths leading to domain admin access.

99% of Global 2000 organizations are linked to a supply chain breach

05 August 2024
99% of Global 2000 organizations have been directly linked to a supply chain breach.

Israeli Hacktivist Group Claims it Took Down Iran’s Internet

05 August 2024
WeRedEvils announced their intention to target Iranian systems on Telegram, claiming their attack was successful in infiltrating Iran's computer systems, stealing data, and causing the outage.

US Sues TikTok for Violating Children Privacy Protection Laws

05 August 2024
The lawsuit alleges that TikTok collected personal information from children under 13 without parental consent, failed to delete children-created accounts, and misled parents about data collection.

Surge in Magniber Ransomware Attacks Impact Home Users Worldwide

05 August 2024
Unlike other ransomware groups targeting businesses, Magniber focuses on individuals. Victims report their devices getting infected after running software cracks. Ransom demands start at $1,000 and escalate to $5,000 if not paid within three days.

CrowdStrike Outage Renews Supply Chain Concerns, Federal Officials Say

05 August 2024
Federal officials have raised concerns about the software supply chain and memory safety vulnerabilities following a global IT outage caused by a faulty CrowdStrike software update.

Evasive Panda Compromises ISP to Distribute Malicious Software Updates

05 August 2024
The group used DNS poisoning to redirect software update queries to attacker-controlled servers, infecting victims with malware. Volexity detected one attack in Hong Kong, which ceased when the ISP took action.

White House Officials Meet with Allies, Industry on Connected Car Risks

05 August 2024
Representatives from various countries and the European Union participated in the meeting, addressing cybersecurity and data risks in connected vehicles. The meeting highlighted the importance of connected cars as a critical part of infrastructure.

Linux Kernel Impacted by New SLUBStick Cross-Cache Attack

05 August 2024
A new Linux Kernel attack called SLUBStick has a 99% success rate in turning a limited heap vulnerability into a powerful memory read-and-write capability, allowing for privilege escalation and container escape.

Mozilla Follows Google in Distrusting Entrust’s TLS Certificates

05 August 2024
Mozilla has joined Google in no longer trusting Entrust as a root certificate authority due to compliance failures and inadequate responses. Google was the first to make this decision, citing concerning behaviors from Entrust.

Cryptonator Seized for Laundering Ransom Payments, Stolen Crypto

05 August 2024
The U.S. and German law enforcement have seized the domain of the Cryptonator crypto wallet platform, indicting its operator, Roman Boss, for money laundering and running an unlicensed money service business.

Researchers Uncover Flaws in Windows Smart App Control and SmartScreen

05 August 2024
Cybersecurity researchers have uncovered design weaknesses in Microsoft's Windows Smart App Control and SmartScreen that could enable threat actors to gain initial access to target environments without raising any warnings. Smart App Control (SAC) is a cloud-powered security feature introduced by Microsoft in Windows 11 to block malicious, untrusted, and potentially unwanted apps from being run

Kazakh Organizations Targeted by 'Bloody Wolf' Cyber Attacks

05 August 2024
Organizations in Kazakhstan are the target of a threat activity cluster dubbed Bloody Wolf that delivers a commodity malware called STRRAT (aka Strigoi Master). "The program selling for as little as $80 on underground resources allows the adversaries to take control of corporate computers and hijack restricted data," cybersecurity vendor BI.ZONE said in a new analysis. The cyber attacks employ

Protect AI Raises $60M in Series B Financing

05 August 2024
Protect AI, a Seattle-based AI and ML security company, raised $60M in Series B funding led by Evolution Equity Partners, with participation from 01 Advisors, StepStone Group, Samsung, and existing investors.

Alex Stamos named Chief Information Security Officer at SentinelOne

05 August 2024
Alex Stamos has been hired as Chief Information Security Officer (CISO) at Sentinel One. 

Australian Companies Will Soon Need to Report Ransom Payments

05 August 2024
Australian companies will soon be required to report ransom payments, in line with the upcoming Cyber Security Act in the country. The legislation aims to enhance the response to cyber incidents, similar to CIRCIA in the US.

New BlankBot Android Malware Targets Users' Banking Data

05 August 2024
BlankBot, which is still in development, has advanced features like screen recording, keylogging, and remote control, posing a significant threat due to its evasion techniques.