Latest Cybersecurity News and Articles


Infisical: Open-source secret management platform - Help Net Security

25 July 2024
Infisical is an open-source secret management platform used by developers to centralize application configurations and secrets like API keys and database credentials, as well as manage internal PKI.

Echoes of Braodo Tales from the Cyber Underworld

25 July 2024
The Braodo Stealer, a Vietnamese-based malware, is infiltrating victims' systems to steal sensitive information like credentials and banking details for identity theft and financial harm.

Meta Removes 63,000 Instagram Accounts Linked to Nigerian Sextortion Scams

25 July 2024
Meta Platforms on Wednesday said it took steps to remove around 63,000 Instagram accounts in Nigeria that were found to target people with financial sextortion scams. "These included a smaller coordinated network of around 2,500 accounts that we were able to link to a group of around 20 individuals," the company said. "They targeted primarily adult men in the U.S. and used fake accounts to mask

Webinar: Securing the Modern Workspace: What Enterprises MUST Know about Enterprise Browser Security

25 July 2024
The browser is the nerve center of the modern workspace. Ironically, however, the browser is also one of the least protected threat surfaces of the modern enterprise. Traditional security tools provide little protection against browser-based threats, leaving organizations exposed. Modern cybersecurity requires a new approach based on the protection of the browser itself, which offers both

Phish-Friendly Domain Registry “.top” Put on Notice

25 July 2024
ICANN has warned the Chinese company responsible for the “.top” domain registry to improve its system for managing phishing reports or risk losing its license. ".top" was found to be a popular choice for phishing websites, behind only “.com.”

Fraudsters Abuse Legitimate Blockchain Protocols to Steal Your Cryptocurrency Wallet

25 July 2024
Research conducted by Check Point has revealed how fraudsters are exploiting legitimate blockchain protocols to carry out sophisticated scams. The Uniswap Protocol and Safe.global are among the platforms targeted by these attackers.

Okta Browser Plugin Reflected Cross-Site Scripting CVE-2024-0981

25 July 2024
Okta Browser Plugin versions 6.5.0 through 6.31.0 are vulnerable to cross-site scripting, prompting users to save credentials in Okta Personal. The issue was fixed in version 6.32.0 for Chrome, Edge, Firefox, and Safari.

Researchers Reveal ConfusedFunction Vulnerability in Google Cloud Platform

25 July 2024
Cybersecurity researchers have disclosed a privilege escalation vulnerability impacting Google Cloud Platform's Cloud Functions service that an attacker could exploit to access other services and sensitive data in an unauthorized manner. Tenable has given the vulnerability the name ConfusedFunction. "An attacker could escalate their privileges to the Default Cloud Build Service Account and

Russia-Linked Brute-Force Campaign Targets EU via Microsoft Infrastructure

25 July 2024
The attackers are primarily targeting High-Value Targets (HVTs) in key infrastructure cities like Edinburgh and Dublin. Over half of the attack IPs are from Moscow, with the rest traced back to Amsterdam and Brussels.

CISA Adds Two Known Exploited Vulnerabilities to Catalog

25 July 2024
The vulnerabilities are as follows: CVE-2012-4792, a decade-old vulnerability in Internet Explorer allowing remote code execution, and CVE-2024-39891, an information disclosure flaw in Twilio Authy.

Critical Docker Engine Flaw Allows Attackers to Bypass Authorization Plugins

25 July 2024
Docker is warning of a critical flaw impacting certain versions of Docker Engine that could allow an attacker to sidestep authorization plugins (AuthZ) under specific circumstances. Tracked as CVE-2024-41110, the bypass and privilege escalation vulnerability carries a CVSS score of 10.0, indicating maximum severity. "An attacker could exploit a bypass using an API request with Content-Length set

CISA Warns of Exploitable Vulnerabilities in Popular BIND 9 DNS Software

25 July 2024
The Internet Systems Consortium (ISC) has released patches to address multiple security vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 Domain Name System (DNS) software suite that could be exploited to trigger a denial-of-service (DoS) condition. "A cyber threat actor could exploit one of these vulnerabilities to cause a denial-of-service condition," the U.S. Cybersecurity and

New Chrome Feature Scans Password-Protected Files for Malicious Content

25 July 2024
Google said it's adding new security warnings when downloading potentially suspicious and malicious files via its Chrome web browser. "We have replaced our previous warning messages with more detailed ones that convey more nuance about the nature of the danger and can help users make more informed decisions," Jasika Bawa, Lily Chen, and Daniel Rubery from the Chrome Security team said. To that

12.9 million individuals affected by MediSecure cyber breach

25 July 2024
Sensitive data, including personal and health information, was exposed in a cyber incident against MediSecure. 

Two Vulnerabilities Discovered in LangChain GenAI Framework

24 July 2024
Researchers identified two vulnerabilities in LangChain, an open-source generative AI framework with over 81,000 stars on GitHub: CVE-2023-46229 and CVE-2023-44467 (LangChain Experimental).

Cybersecurity Startup Protexxa Closes $10M Series A Round

24 July 2024
Protexxa, a Toronto-based B2B SaaS cybersecurity company founded by Claudette McGowan, has secured $10 million in Series A funding from various investors including Bell Ventures and private investors like Sonia Baxendale and Annette Verschuren.

Malware Campaigns Target Hamster Kombat Players

24 July 2024
Threat actors are targeting Hamster Kombat's 250 million players with fake Android and Windows software that install spyware and malware. The clicker mobile game allows players to earn fictional currency by completing simple tasks.

Philippines to End Online Casinos, Maybe Scams Too

24 July 2024
The Philippines has decided to shut down its online gambling industry to tackle illegal activities such as financial scams and human trafficking. President Ferdinand Marcos Jr instructed PAGCOR to cease operations of POGOs by the end of the year.

DeFi Crypto Exchange dYdX v3 Website Hacked in DNS Hijacking Attack

24 July 2024
dYdX's decentralized finance (DeFi) exchange v3 website was hacked in a DNS hijack attack, compromising the platform. Users were warned not to visit or interact with the hacked website and to avoid withdrawing assets until the platform was safe.

Russia Shifts Cyber Focus to Battlefield Intelligence in Ukraine

24 July 2024
Multiple Russian cyber units are targeting frontline Ukrainian military computers and mobile devices in preparation for a summer offensive. This change reflects Russia's adaptation to the demands of a prolonged war in Ukraine.