Latest Cybersecurity News and Articles


New ZenHammer Attack Bypasses Rowhammer Defenses on AMD CPUs

28 March 2024
Cybersecurity researchers from ETH Zurich have developed a new variant of the RowHammer DRAM (dynamic random-access memory) attack that, for the first time, successfully works against AMD Zen 2 and Zen 3 systems despite mitigations such as Target Row Refresh (TRR). "This result proves that AMD systems are equally vulnerable to Rowhammer as Intel systems, which greatly increases the attack

CISA Adds One Known Exploited Vulnerability in Microsoft Sharepoint Server to Catalog

28 March 2024
The vulnerability, tracked as CVE-2023-24955 (CVSS score: 7.2), is a critical remote code execution flaw that allows an authenticated attacker with Site Owner privileges to execute arbitrary code.

Trezor’s Twitter Account Hijacked by Cryptocurrency Scammers via Bogus Calendly Invite

28 March 2024
According to Trezor, someone posing as "a credible entity from the crypto space", using a Twitter account with thousands of followers, approached its PR team on February 29, 2024. The imposter asked to interview Trezor CEO Matej Zak.

UK: NCSC Warns of Hackers Hitting High-Risk Individuals' Personal Accounts

28 March 2024
Britain's National Cyber Security Center is warning that criminals and nation-state hacking groups, confronted with well-managed corporate cybersecurity defenses, have turned their sights to individual personal devices and accounts.

Telegram Offers Premium Subscription in Exchange for Using Your Number to Send OTPs

28 March 2024
In June 2017, a study of more than 3,000 Massachusetts Institute of Technology (MIT) students published by the National Bureau for Economic Research (NBER) found that 98% of them were willing to give away their friends' email addresses in exchange for free pizza. "Whereas people say they care about privacy, they are willing to relinquish private data quite easily when

Leaked Documents Reveal Australia Targeted by Chinese APT31 Hackers

27 March 2024
A Chinese cybersecurity company with links to the Communist Party government used its guns-for-hire hacking operation to target Australia, leaked documents from iSoon revealed.

US State Department Warns Employees of Fraud Scheme Targeting Payroll Systems

27 March 2024
The State Department alert said that cybercriminals are attempting to use “phishing, email account takeovers, and social engineering” to veer employee payroll deposits into their own bank accounts.

Airbus Enhances Cybersecurity Offerings with INFODAS Acquisition

27 March 2024
The acquisition is poised to significantly bolster Airbus’ cybersecurity portfolio, a critical component of its strategic vision aimed at enhancing the digital protection of its European and global clientele.

Finnish Police Linked APT31 to the 2021 Parliament Attack

27 March 2024
The investigation relied on an international information exchange, the National Bureau of Investigation collaborated with international entities and the Finnish Security and Intelligence Service

Breaking Boundaries: Mispadu's Infiltration Beyond LATAM

27 March 2024
Recently, Morphisec Labs identified a significant increase in activity linked to the Mispadu banking trojan. Initially concentrated on LATAM countries and Spanish-speaking individuals, Mispadu has broadened its scope in the latest campaign.

Two Chinese APT Groups Found Targeting ASEAN Entities

27 March 2024
Over the past 90 days, Unit 42 researchers identified two Chinese APT groups conducting cyberespionage activities against entities and member countries affiliated with the Association of Southeast Asian Nations (ASEAN).

Feds Wave Sticks & Carrots at Health Sector to Bolster Cyber

27 March 2024
The Department of Health and Human Services' recently released budget proposal for fiscal 2025 includes $1.3 billion in financial help, such as grants, for hospitals to invest in cybersecurity over the next several years.

92% of IT leaders report cyberattacks are more frequent than last year

27 March 2024
Cyberattacks are growing in volume and sophistication, and security leaders must adapt to face increasingly complex threats. 

TheMoon Malware Infects 6,000 ASUS Routers in 72 Hours for Proxy Service

27 March 2024
TheMoon is linked to the "Faceless" proxy service, which uses some of the infected devices as proxies to route traffic for cybercriminals who wish to anonymize their malicious activities.

Hackers Hit Indian Defense, Energy Sectors with Malware Posing as Air Force Invite

27 March 2024
Indian government entities and energy companies have been targeted by unknown threat actors with an aim to deliver a modified version of an open-source information stealer malware called HackBrowserData and exfiltrate sensitive information in some cases by using Slack as command-and-control (C2). "The information stealer was delivered via a phishing email, masquerading as an invitation letter

Tech Industry’s Focus on Innovation Leaves Security Behind

27 March 2024
The rapid digital transformation and technological progress within the technology sector have enlarged the attack surface for companies operating in this space, according to Trustwave.

Patched Microsoft Edge Flaw Could be Used for Covert Extension Installation

27 March 2024
This flaw could have allowed an attacker to exploit a private API, initially intended for marketing purposes, to covertly install additional browser extensions with broad permissions without the user’s knowledge.

Portugal Forces Worldcoin to Stop Collecting Biometric Data

27 March 2024
The Portuguese National Data Protection Commission (Comissão Nacional de Proteção de Dados, or CNPD) announced on March 26 that it ordered Worldcoin to suspend its ‘orb’ device from collecting data in the country.

Japan Runs Inaugural Cyber Defense Drills With Pacific Island Nations

27 March 2024
Japan held cyber defense exercises with five Pacific island nations last month in an effort to shore up cybersecurity defenses in the region. The cybersecurity exercise event, held in Guam in mid-February, was a first for Japan.

CISA Warns: Hackers Actively Attacking Microsoft SharePoint Vulnerability

27 March 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting the Microsoft Sharepoint Server to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2023-24955 (CVSS score: 7.2), is a critical remote code execution flaw that allows an authenticated attacker with