Latest Cybersecurity News and Articles


Women working in tech are less likely to be employed full time

26 March 2024
A recent report found that fewer women technology professionals reported receiving an increase in pay over the last year compared to men.

Agent Tesla's New Ride: The Rise of a Novel Loader

26 March 2024
Recently, SpiderLabs identified a phishing email with an attached archive that included a Windows executable disguised as a fraudulent bank payment. This action initiated an infection chain culminating in the deployment of Agent Tesla.

Malicious NuGet Package Linked to Industrial Espionage Targets Developers

26 March 2024
Threat hunters have identified a suspicious package in the NuGet package manager that's likely designed to target developers working with tools made by a Chinese firm that specializes in industrial- and digital equipment manufacturing. The package in question is SqzrFramework480, which ReversingLabs said was first published on January 24, 2024. It has been downloaded 

Agenda Ransomware Propagates to vCenters and ESXi via Custom PowerShell Script

26 March 2024
Agenda ransomware group uses RMM tools, as well as Cobalt Strike for deployment of the ransomware binary. It can also propagate via PsExec and SecureShell, while also making use of different vulnerable SYS drivers for defense evasion.

67% of businesses sync on-premises passwords to cloud environments

26 March 2024
New research provides key insights and classifications regarding the threats that identity security teams face. 

Recent ‘MFA Bombing’ Attacks Targeting Apple Users

26 March 2024
Several Apple customers recently reported being targeted in elaborate phishing attacks that involve what appears to be a bug in Apple's password reset feature. In this scenario, a target's Apple devices are forced to display dozens of system-level prompts that prevent the devices from being used until the recipient responds "Allow" or "Don't Allow" to each prompt. Assuming the user manages not to fat-finger the wrong button on the umpteenth password reset request, the scammers will then call the victim while spoofing Apple support in the caller ID, saying the user's account is under attack and that Apple support needs to "verify" a one-time code.

Canadian Discount Retailer Giant Tiger Says Customer Data Was Compromised in Third-Party Breach

26 March 2024
The retailer first learned of the security incident on March 4, and concluded that customer information was involved by March 15, the company wrote in an email to customers.

US Indicts Accused APT31 Chinese Hackers for Hire

26 March 2024
U.S. federal prosecutors indicted seven Chinese nationals they accuse of hacking for a Beijing economic and intelligence espionage group whose operations reacted to geopolitical trends.

New Zealand Government Discloses Cyberattacks by China-Linked APT40 on Two Parliamentary Agencies

26 March 2024
New Zealand's admission it's been on the receiving end came a day after the UK and United States detailed Chinese-supported attacks on government institutions – including the UK's Electoral Register.

New Tycoon 2FA Phishing Kit Raises Cybersecurity Concerns

26 March 2024
An analysis by Sekoia revealed that the kit has emerged as one of the most prevalent AiTM phishing kits, with over 1,100 domain names detected between October 2023 and February 2024.

New ZenHammer Memory Attack Impacts AMD CPUs Based on Zen Architecture

26 March 2024
Academic researchers developed ZenHammer, the first variant of the Rowhammer DRAM attack that works on CPUs based on a recent AMD Zen microarchitecture that maps physical addresses on DDR4 and DDR5 memory chips.

Hospitals Lobby Feds to Clarify Breach Duties in UHG Attack

26 March 2024
The AHA is asking the Department of Health and Human Services' Office for Civil Rights for a "unified notification process" if a breach occurred in the February 21 cyberattack on UnitedHealth Group's Change Healthcare unit.

UK Privacy Watchdog Updates Guidance on Data Protection Fines

26 March 2024
After suffering a data breach, organizations in the United Kingdom that work closely and transparently with regulators and cybersecurity officials will be treated with greater leniency if their case results in penalties and a fine.

U.S. Charges 7 Chinese Nationals in Major 14-Year Cyber Espionage Operation

26 March 2024
The U.S. Department of Justice (DoJ) on Monday unsealed indictments against seven Chinese nationals for their involvement in a hacking group that targeted U.S. and foreign critics, journalists, businesses, and political officials for about 14 years. The defendants include Ni Gaobin (倪高彬), Weng Ming (翁明), Cheng Feng (程锋), Peng Yaowen (彭耀文), Sun Xiaohui (孙小辉), Xiong Wang (熊旺), and Zhao Guangzong (

Senator Demands Answers From HHS About $7.5 Million Cyber Theft in 2023

26 March 2024
HHS has not issued a public statement about the incident, and its Office of the Inspector General declined to confirm or deny an investigation was underway when pressed about it in January.

Cybercriminals can leverage March Madness as bait for attacks

26 March 2024
March Madness, like any other major public event, may provide a platform for malicious actors to work. 

Crafting Shields: Defending Minecraft Servers Against DDoS Attacks

26 March 2024
Minecraft, with over 500 million registered users and 166 million monthly players, faces significant risks from distributed denial-of-service (DDoS) attacks, threatening server functionality, player experience, and the game’s reputation. Despite the prevalence of DDoS attacks on the game, the majority of incidents go unreported, leaving a gap in awareness and protection. This article explains

Scams are Becoming More Convincing and Costly

26 March 2024
Scams directly targeting consumers continue to increase in both complexity and volume, according to Visa. Consumers are increasingly targeted by scammers, who rely on heightened emotions to create fraud opportunities.

St. Cloud Most Recent in String of Florida Cities Hit with Ransomware Attacks

26 March 2024
The city of St. Cloud said Monday it discovered a ransomware attack affecting city services and warned that while “many” city departments are affected they are “operating as best as possible until the issue is resolved.”

95% of Companies Face API Security Problems

26 March 2024
The ubiquity of APIs means they have become one of cybercriminals’ favourite gateways for account takeover attacks. In a recent survey by Fastly, 84% of respondents admitted to not having advanced API security in place.