Latest Cybersecurity News and Articles


CISA Urges Software Devs to Weed out SQL Injection Vulnerabilities

26 March 2024
Parameterized queries are a better option for a secure-by-design approach compared to input sanitization techniques because the latter can be bypassed and are difficult to enforce at scale.

Report Urges Congress to Form an Armed Cyber Military Branch

26 March 2024
The U.S. military requires a seventh branch to serve as an independent cyber armed service amid growing threats in cyberspace, according to a leading national security think tank.

CISA Adds Three Known Exploited Vulnerabilities to its Catalog

26 March 2024
This includes CVE-2023-48788 in Fortinet FortiClient EMS, CVE-2021-44529 in Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA), and CVE-2019-7256 in Nice Linear eMerge E3-Series.

Update: Vans Says Cybercriminals Didn’t Nab Customers’ Financial Information

26 March 2024
In an email to customers, VF Corporation promised that cybercriminals didn't swipe their credit card or bank account details. And, it added, there's "no evidence" suggesting any stolen personal information has been used for nefarious purposes.

GitLab Acquires Oxeye to Bolster SAST in DevSecOps Workflow

26 March 2024
GitLab has bought a static application security testing startup led by an Imperva and Check Point veteran to improve application-layer risk detection and reduce false positives.

Shadow AI is the Latest Cybersecurity Threat You Need to Prepare For

26 March 2024
Shadow IT – the use of software, hardware, systems, and services that haven’t been approved by an organization’s IT/IT Sec departments – has been a problem for the last couple of decades, and a difficult area for IT leaders to manage effectively.

UK Calls Out China State-Affiliated Actors for Targeting of UK Democratic Institutions and Parliamentarians

26 March 2024
The NCSC assesses that the Chinese state-linked APT31 was almost certainly responsible for conducting online reconnaissance activity in 2021 against the email accounts of UK parliamentarians.

U.S. Sanctions 3 Cryptocurrency Exchanges for Helping Russia Evade Sanctions

26 March 2024
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned three cryptocurrency exchanges for offering services used to evade economic restrictions imposed on Russia following its invasion of Ukraine in early 2022. This includes Bitpapa IC FZC LLC, Crypto Explorer DMCC (AWEX), and Obshchestvo S Ogranichennoy Otvetstvennostyu Tsentr Obrabotki Elektronnykh Platezhey (

CISA Alerts on Active Exploitation of Flaws in Fortinet, Ivanti, and Nice Products

26 March 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday placed three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities added are as follows - CVE-2023-48788 (CVSS score: 9.3) - Fortinet FortiClient EMS SQL Injection Vulnerability CVE-2021-44529 (CVSS score: 9.8) - Ivanti

Google’s New AI Search Results Promotes Sites Pushing Malware, Scams

25 March 2024
Google's new AI-powered 'Search Generative Experience' algorithms recommend scam sites that redirect visitors to unwanted Chrome extensions, fake iPhone giveaways, browser spam subscriptions, and tech support scams.

UK calls out China state-affiliated actors for malicious cyber targeting of UK democratic institutions and parliamentarians

25 March 2024
APT31, a China state-affiliated actor, was almost certainly responsible for targeting UK parliamentarians’ emails in 2021.

Scammers Steal Millions From FTX, BlockFi Claimants

25 March 2024
Customers of bankrupt crypto platform BlockFi have been targeted with a very convincing phishing email impersonating the platform, asking them to connect their wallet to complete the withdrawal of remaining funds.

Sandworm-Linked Group Likely Knocked Down Ukrainian Internet Providers

25 March 2024
Russian state-backed hackers are likely behind recent attacks on four Ukrainian internet providers, disrupting their operations for over a week. A group known as Solntsepek claimed responsibility for the incidents on its Telegram channel last week.

UN Probing 58 Alleged Crypto Heists by North Korea Worth $3 Billion

25 March 2024
In a report released March 7, the U.N. experts said they tracked the activity of “cyberthreat actors subordinate to the Reconnaissance General Bureau (RGB), including Kimsuky, the Lazarus Group, Andariel and BlueNoroff,” between 2017 and 2023.

Police Bust Multimillion-Dollar Holiday Fraud Gang

25 March 2024
Police in Romania and Spain have struck a blow against a sophisticated cyber-fraud gang that tricked victims out of millions of dollars through fake ads and business email compromise (BEC) scams.

Supply Chain Attack Discovered Using Fake Python Infrastructure

25 March 2024
The multi-stage and evasive malicious payload harvests passwords, credentials, and more dumps of valuable data from infected systems and exfiltrates them to the attacker’s infrastructure.

Hackers Hijack GitHub Accounts in Supply Chain Attack Affecting Top-gg and Others

25 March 2024
Unidentified adversaries orchestrated a sophisticated attack campaign that has impacted several individual developers as well as the GitHub organization account associated with Top.gg, a Discord bot discovery site. "The threat actors used multiple TTPs in this attack, including account takeover via stolen browser cookies, contributing malicious code with verified commits, setting up a custom

Key Lesson from Microsoft’s Password Spray Hack: Secure Every Account

25 March 2024
In January 2024, Microsoft discovered they’d been the victim of a hack orchestrated by Russian-state hackers Midnight Blizzard (sometimes known as Nobelium). The concerning detail about this case is how easy it was to breach the software giant. It wasn’t a highly technical hack that exploited a zero-day vulnerability – the hackers used a simple password spray attack to take control of

Russian Hackers Target German Political Parties With WineLoader Malware

25 March 2024
The campaign has been active since late February and mainly uses phishing emails that appear to come from the German Christian Democratic Union, according to a report by Mandiant.

Air Europa Customers Warned Their Data May Have Been Leaked

25 March 2024
The parent company IAG has reportedly sent out a breach notification email to affected individuals, telling them that their names, dates of birth, nationalities, ID cards, passport information, and phone numbers, have all been taken by the hackers.