Latest Cybersecurity News and Articles


Google Postpones Third-Party Cookie Deprecation Amid U.K. Regulatory Scrutiny

25 April 2024
Google has once again pushed its plans to deprecate third-party tracking cookies in its Chrome web browser as it works to address outstanding competition concerns from U.K. regulators over its Privacy Sandbox initiative. The tech giant said it's working closely with the U.K. Competition and Markets Authority (CMA) and hopes to achieve an agreement by the end of the year. As part of the

Maximum Severity Flowmon Bug has a Public Exploit, Patch Now

25 April 2024
Flowon developer Progress Software first alerted about the flaw on April 4, warning that it impacts versions of the product v12.x and v11.x. The company urged system admins to upgrade to the latest releases, v12.3.4 and 11.1.14.

CISA Warns of Cisco and CrushFTP Vulnerabilities Being Actively Exploited

25 April 2024
On Wednesday, the Cybersecurity and Infrastructure Security Agency (CISA) added two Cisco product vulnerabilities — CVE-2024-20353 and CVE-2024-20359 — as well as one vulnerability affecting popular file transfer tool CrushFTP.

State-Sponsored Hackers Exploit Two Cisco Zero-Day Vulnerabilities for Espionage

25 April 2024
A new malware campaign leveraged two zero-day flaws in Cisco networking gear to deliver custom malware and facilitate covert data collection on target environments. Cisco Talos, which dubbed the activity ArcaneDoor, attributing it as the handiwork of a previously undocumented sophisticated state-sponsored actor it tracks under the name UAT4356 (aka Storm-1849 by Microsoft). "

Google Meet opens client-side encrypted calls to non Google users

25 April 2024
Google announced it is updating the client-side encryption mechanism for Google Meet to allow external participants, including those without Google accounts, to join encrypted calls.

Chinese, Russian Espionage Campaigns Increasingly Targeting Edge Devices

25 April 2024
Chinese and Russian hackers have turned their focus to edge devices — like VPN appliances, firewalls, routers and Internet of Things (IoT) tools — amid a startling increase in espionage attacks, according to Google security firm Mandiant.

Security Bugs in a Popular Phone-Tracking App Exposed Users’ Precise Locations

24 April 2024
A security researcher discovered vulnerabilities in the popular phone-tracking app iSharing, which has over 35 million users. The bugs allowed a user to access others' precise coordinates, even if the user wasn't actively sharing their location data.

73% of security professionals failed to act upon security alerts

24 April 2024
Many small and medium-sized enterprises lack the resources and abilities to properly handle the large volume security alerts received. 

Google Ad for Facebook Redirects to Scam

24 April 2024
Researchers observed a malicious ad campaign targeting Facebook users via Google search. The ad, which appears at the top of Google search results for the keyword "Facebook," redirects users to a scam page.

Exploitation of vulnerabilities affecting Cisco Firewall Platforms

24 April 2024
The NCSC advises organisations to take immediate action to mitigate vulnerabilities affecting Cisco devices running Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software (CVE-2024-20353, CVE-2024-20358, CVE-2024-20359) and follow the latest vendor advice.

Researchers Detail Multistage Attack Hijacking Systems with SSLoad, Cobalt Strike

24 April 2024
"SSLoad is designed to stealthily infiltrate systems, gather sensitive information and transmit its findings back to its operators," security researchers Den Iuzvyk, Tim Peck, and Oleg Kolesnikov said in a report shared with The Hacker News.

Iran Dupes US Military Contractors, Gov't Agencies in Cyber Campaign

24 April 2024
An Iranian state-sponsored hacking group successfully infiltrated hundreds of thousands of employee accounts at US companies and government agencies, including the US Treasury and State Department, as part of a five-year cyber espionage campaign.

NCSC and partners issue advice to help network defenders mitigate targeting of CISCO firewall platforms

24 April 2024
Joint advisory and malware analysis reports published to help mitigate malicious activity targeting certain Cisco devices.

Major Security Flaws Expose Keystrokes of Over One Billion Chinese Keyboard App Users

24 April 2024
The vulnerabilities could be exploited to "completely reveal the contents of users' keystrokes in transit," researchers Jeffrey Knockel, Mona Wang, and Zoë Reichert said.

Report: Attacker Dwell Time Down, Ransomware up in 2023

24 April 2024
According to a new report by Mandiant, which is based on Mandiant Consulting investigations during 2023, the global median dwell time for attackers fell to its lowest point since the company began tracking the metric in 2011.

U.S. Treasury Sanctions Iranian Firms and Individuals Tied to Cyber Attacks

24 April 2024
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) on Monday sanctioned two firms and four individuals for their involvement in malicious cyber activities on behalf of the Iranian Islamic Revolutionary Guard Corps Cyber Electronic Command (IRGC-CEC) from at least 2016 to April 2021. This includes the front companies Mehrsam Andisheh Saz Nik (MASN) and Dadeh

Researchers Detail Multistage Attack Hijacking Systems with SSLoad, Cobalt Strike

24 April 2024
Cybersecurity researchers have discovered an ongoing attack campaign that's leveraging phishing emails to deliver malware called SSLoad. The campaign, codenamed FROZEN#SHADOW by Securonix, also involves the deployment of Cobalt Strike and the ConnectWise ScreenConnect remote desktop software. "SSLoad is designed to stealthily infiltrate systems, gather sensitive

Hackers Publish Fake Story About Ukrainians Attempting To Assassinate Slovak President

24 April 2024
An unidentified attacker hacked a Czech news service's website and published a fake story on Tuesday claiming that an assassination attempt had been made against the newly elected Slovak president Petr Pellegrini.

Report: Fifth of UK Companies Admit Staff Leaked Data via GenAI

24 April 2024
One in five UK companies has experienced sensitive corporate data exposure due to employees' use of generative AI (GenAI), according to a report by cybersecurity services provider RiverSafe.

US Gov Slaps Visa Restrictions on Spyware Honchos

24 April 2024
The US State Department is imposing visa restrictions on 13 people involved in the development and sale of commercial spyware, as well as their spouses and children. The State Department can deny these people entrance to the United States.