Latest Cybersecurity News and Articles


Android Bug can Leak DNS Traffic With VPN Kill Switch Enabled

04 May 2024
The Android bug discovered by a Mullvad VPN user reveals that Android devices can leak DNS queries even with the "Always-on VPN" feature and "Block connections without VPN" option enabled.

“Dirty Stream” Attack Affects Popular Android Apps

03 May 2024
A vulnerability in popular Android apps like Xiaomi File Manager and WPS Office could allow malicious apps to overwrite files in the vulnerable app's home directory, potentially leading to code execution and unauthorized access to user data.

More Than Two Dozen Android Vulnerabilities Fixed

03 May 2024
Xiaomi resolved 20 flaws, ensuring user safety by fixing issues like arbitrary access to system components and data leaks. Google also fixed six vulnerabilities, including geolocation access through the camera and arbitrary file access.

North Korean Hackers Spoofing Journalist Emails to Spy on Experts

03 May 2024
North Korean threat actors, specifically the Kimsuky group, are exploiting weakly configured DMARC protocols to spoof the email addresses of legitimate journalists, academics, and other experts in East Asian affairs.

Verizon 2024 Data Breach Report shows the risk of the human element

03 May 2024
The 2024 Data Breach Investigations Report reveals the role that the human element plays in cyber threats, and security leaders are weighing in. 

DeepKeep Secures $10M in Seed Funding to Boost GenAI Protection Endeavors

03 May 2024
Founded in 2021 by Rony Ohayon, DeepKeep specializes in AI-Native Trust, Risk, and Security Management (TRiSM). The platform caters to large corporations reliant on AI, GenAI, and LLM technologies for risk management and growth protection.

reNgine: Open-Source Automated Reconnaissance Framework for Web Applications

03 May 2024
Developed to address limitations in existing tools, reNgine is beneficial for bug bounty hunters, penetration testers, and corporate security teams by automating and enhancing their information collection processes.

Cybersecurity Consultant Arrested After Allegedly Extorting IT Firm

03 May 2024
Vincent Cannady, a former cybersecurity consultant, was arrested for allegedly extorting a publicly traded IT company by threatening to disclose confidential data unless they paid him $1.5 million.

Expert-Led Webinar - Uncovering Latest DDoS Tactics and Learn How to Fight Back

03 May 2024
In today's rapidly evolving digital landscape, the threat of Distributed Denial of Service (DDoS) attacks looms more significant than ever. As these cyber threats grow in sophistication, understanding and countering them becomes crucial for any business seeking to protect its online presence. To address this urgent need, we are thrilled to announce our upcoming webinar, "Uncovering Contemporary

REvil Ransomware Affiliate Sentenced to Over 13 Years in Prison

03 May 2024
Yaroslav Vasinskyi, a 24-year-old Ukrainian national and affiliate of the notorious REvil ransomware-as-a-service (RaaS) group, has been sentenced to 13 years and 7 months in prison by a US court.

Hackers Increasingly Abusing Microsoft Graph API for Stealthy Malware Communications

03 May 2024
Threat actors have been increasingly weaponizing Microsoft Graph API for malicious purposes with the aim of evading detection. This is done to "facilitate communications with command-and-control (C&C) infrastructure hosted on Microsoft cloud services," the Symantec Threat Hunter Team, part of Broadcom, said in a report shared with The Hacker News.

AI-Driven Phishing Attacks Deceive Even the Most Aware Users

03 May 2024
By automating and personalizing various aspects of the attack process, such as crafting convincing emails and creating realistic phishing pages, threat actors can deceive even the most aware users.

Report: The cost and complexity of data compliance impedes innovation

03 May 2024
Organizations are utilizing data to promote innovation; however, less than 2% can access sensitive data within a week’s time. 

Investigation Uncovers Substantial Spyware Exports to Indonesia

03 May 2024
An investigation by Amnesty International's Security Lab revealed that Indonesia has been procuring powerful and invasive commercial spyware and surveillance products from international vendors, brokers, and resellers.

New Guide Explains How to Eliminate the Risk of Shadow SaaS and Protect Corporate Data

03 May 2024
SaaS applications are dominating the corporate landscape. Their increased use enables organizations to push the boundaries of technology and business. At the same time, these applications also pose a new security risk that security leaders need to address, since the existing security stack does not enable complete control or comprehensive monitoring of their usage.

US Charges 16 Over ‘Depraved’ Grandparent Scams

03 May 2024
The scam involved call center workers impersonating the victims' relatives, claiming they were in legal trouble or had been in an accident, and convincing the victims to send thousands of dollars to help them.

Cybercriminals and Nation-State Actors Found Sharing Compromised Networks

03 May 2024
Nation-state threat actors like Sandworm used their own dedicated proxy botnets, while APT group Pawn Storm had access to a criminal proxy botnet of Ubiquiti EdgeRouters.

Essential Steps for Zero-Trust Strategy Implementation

03 May 2024
According to Gartner, 63% of organizations worldwide have fully or partially implemented a zero-trust strategy. For 78% of organizations implementing a zero-trust strategy, this investment represents less than 25% of the overall cybersecurity budget.

NSA, FBI Alert on N. Korean Hackers Spoofing Emails from Trusted Sources

03 May 2024
The U.S. government on Thursday published a new cybersecurity advisory warning of North Korean threat actors' attempts to send emails in a manner that makes them appear like they are from legitimate and trusted parties. The joint bulletin was published by the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and the Department of State. "The

Attack Report: Custom QR Code Phishing Templates

03 May 2024
Hackers are using custom QR code templates that are personalized for each target organization, making the attacks appear more legitimate and increasing their chances of success.