Latest Cybersecurity News and Articles


83% of organizations faced at least one account takeover the past year

05 June 2024
A new survey reveals that account takeovers are a prominent threat.

Chinese State-Backed Cyber Espionage Targets Southeast Asian Government

05 June 2024
An unnamed high-profile government organization in Southeast Asia emerged as the target of a "complex, long-running" Chinese state-sponsored cyber espionage operation codenamed Crimson Palace. "The overall goal behind the campaign was to maintain access to the target network for cyberespionage in support of Chinese state interests," Sophos researchers Paul Jaramillo, Morgan Demboski, Sean

Who are Qilin, the cybercriminals thought behind the London hospitals hack?

05 June 2024
Who are Qilin, the cybercriminals thought behind the London hospitals hack? Russian-speaking ransomware gang lets hackers use its tools in exchange for cut of proceedsA Russian-speaking ransomware criminal gang called Qilin is thought to be behind the cyber-attack on NHS medical services provider Synnovis, that halted tests and operations at hospital trusts to a halt and affected GPs across London.Although the location of the group is unknown, if it is based in Russia, it will be difficult for British law enforcement to directly target it. The Russian state has long had a ban on extraditing criminals overseas, and since it launched a full-scale invasion of Ukraine, it has largely ended all cooperation on cybersecurity matters so long as the hackers focus their attacks on foreign targets. Continue reading...

Unpacking 2024's SaaS Threat Predictions

05 June 2024
Early in 2024, Wing Security released its State of SaaS Security report, offering surprising insights into emerging threats and best practices in the SaaS domain. Now, halfway through the year, several SaaS threat predictions from the report have already proven accurate. Fortunately, SaaS Security Posture Management (SSPM) solutions have prioritized mitigation capabilities to address many of

Rebranded Knight Ransomware Targeting Healthcare and Businesses Worldwide

05 June 2024
An analysis of a nascent ransomware strain called RansomHub has revealed it to be an updated and rebranded version of Knight ransomware, itself an evolution of another ransomware known as Cyclops. Knight (aka Cyclops 2.0) ransomware first arrived in May 2023, employing double extortion tactics to steal and encrypt victims' data for financial gain. It's operational across multiple platforms,

Zyxel Releases Patches for Firmware Vulnerabilities in EoL NAS Models

05 June 2024
Zyxel has released security updates to address critical flaws impacting two of its network-attached storage (NAS) devices that have currently reached end-of-life (EoL) status. Successful exploitation of three of the five vulnerabilities could permit an unauthenticated attacker to execute operating system (OS) commands and arbitrary code on affected installations. Impacted models include NAS326

Celebrity TikTok Accounts Compromised Using Zero-Click Attack via DMs

05 June 2024
Popular video-sharing platform TikTok has acknowledged a security issue that has been exploited by threat actors to take control of high-profile accounts on the platform. The development was first reported by Semafor and Forbes, which detailed a zero-click account takeover campaign that allows malware propagated via direct messages to compromise brand and celebrity accounts without having to

Security leaders respond to Ticketmaster breach

05 June 2024
The ShinyHunters threat operation has claimed to hack Ticketmaster, and security leaders are sharing their thoughts. 

Security’s Top 5 – April 2024

05 June 2024
Top stories and new developments from across the security industry throughout April.

Women face nearly twice as much exclusion in cybersecurity than men

04 June 2024
A recent report finds notable gender disparities in the cybersecurity industry.

Russian Power Companies, IT Firms, and Govt Agencies Hit by Decoy Dog Trojan

04 June 2024
Russian organizations are at the receiving end of cyber attacks that have been found to deliver a Windows version of a malware called Decoy Dog. Cybersecurity company Positive Technologies is tracking the activity cluster under the name Operation Lahat, attributing it to an advanced persistent threat (APT) group called HellHounds. "The Hellhounds group compromises organizations they select and

Telerik Report Server Flaw Could Let Attackers Create Rogue Admin Accounts

04 June 2024
Progress Software has rolled out updates to address a critical security flaw impacting the Telerik Report Server that could be potentially exploited by a remote attacker to bypass authentication and create rogue administrator users. The issue, tracked as CVE-2024-4358, carries a CVSS score of 9.8 out of a maximum of 10.0. "In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or

Administrator of 911 S5 botnet arrested, botnet dismantled

04 June 2024
A coordinated international operation had led to the apprehension of the alleged 911 S5 botnet administrator. 

The Next Generation of RBI (Remote Browser Isolation)

04 June 2024
The landscape of browser security has undergone significant changes over the past decade. While Browser Isolation was once considered the gold standard for protecting against browser exploits and malware downloads, it has become increasingly inadequate and insecure in today's SaaS-centric world. The limitations of Browser Isolation, such as degraded browser performance and inability to tackle

Hackers Use MS Excel Macro to Launch Multi-Stage Malware Attack in Ukraine

04 June 2024
A new sophisticated cyber attack has been observed targeting endpoints geolocated to Ukraine with an aim to deploy Cobalt Strike and seize control of the compromised hosts. The attack chain, per Fortinet FortiGuard Labs, involves a Microsoft Excel file that carries an embedded VBA macro to initiate the infection, "The attacker uses a multi-stage malware strategy to deliver the notorious 'Cobalt

Snowflake Warns: Targeted Credential Theft Campaign Hits Cloud Customers

04 June 2024
Cloud computing and analytics company Snowflake said a "limited number" of its customers have been singled out as part of a targeted campaign. "We have not identified evidence suggesting this activity was caused by a vulnerability, misconfiguration, or breach of Snowflake’s platform," the company said in a joint statement along with CrowdStrike and Google-owned Mandiant. "We have not identified

DarkGate Malware Replaces AutoIt with AutoHotkey in Latest Cyber Attacks

04 June 2024
Cyber attacks involving the DarkGate malware-as-a-service (MaaS) operation have shifted away from AutoIt scripts to an AutoHotkey mechanism to deliver the last stages, underscoring continued efforts on the part of the threat actors to continuously stay ahead of the detection curve. The updates have been observed in version 6 of DarkGate released in March 2024 by its developer RastaFarEye, who

39% of MSPs adapting to new technologies is their biggest challenge

04 June 2024
39% of MSPs state that their greatest challenge is keeping up with emerging cybersecurity solutions and technologies.

Oracle WebLogic Server OS Command Injection Flaw Under Active Attack

03 June 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a security flaw impacting the Oracle WebLogic Server to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Tracked as CVE-2017-3506 (CVSS score: 7.4), the issue concerns an operating system (OS) command injection vulnerability that could be exploited to obtain unauthorized

49% of organizations feel somewhat prepared to handle a breach

03 June 2024
A report found that insufficient or ineffective cybersecurity training and resources are the two biggest items missing from a cybersecurity approach.