Latest Cybersecurity News and Articles


New Go Loader Pushes Rhadamanthys Stealer

23 March 2024
PuTTY is a very popular SSH and Telnet client for Windows used by IT admins for years. The threat actor bought an ad that claims to be the PuTTY homepage and appeared at the top of the Google search results page, right before the official website.

Mozilla Drops Onerep After CEO Admits to Running People-Search Networks

22 March 2024
The nonprofit organization that supports the Firefox web browser said today it is winding down its new partnership with Onerep, an identity protection service recently bundled with Firefox that offers to remove users from hundreds of people-search sites. The move comes just days after a report by KrebsOnSecurity forced Onerep's CEO to admit that he has founded dozens of people-search networks over the years.

New Details on TinyTurla’s Post-Compromise Activity Reveal Full Kill Chain

22 March 2024
Talos’ analysis, in coordination with CERT.NGO, reveals that Turla infected multiple systems in the compromised network of a European non-governmental organization (NGO).

Large-Scale StrelaStealer Campaign in Early 2024

22 March 2024
Recently, Unit 42 researchers have identified a wave of large-scale StrelaStealer campaigns impacting over 100 organizations across the EU and U.S. These campaigns deliver spam emails with attachments that eventually launch the DLL payload.

Report: Malware Stands Out as the Fastest-Growing Threat of 2024

22 March 2024
93% of IT professionals believe security threats are increasing in volume or severity, a significant rise from 47% last year, according to Thales. The number of enterprises experiencing ransomware attacks surged by over 27% in the past year.

Apple M-Series Chip Vulnerability Puts Encryption Keys at Risk

22 March 2024
Foresight News reported that the vulnerability poses a serious risk of leakage of wallet keys, The flaw operates as a side channel, facilitating the extraction of end-to-end keys during encrypted transactions.

Email Bomb Attacks: Filling Up Inboxes and Servers Near You

22 March 2024
The HHS' Health Sector Cybersecurity Coordination Center in an alert warned that email bomb attacks - also known as letter bomb attacks - pose a considerable potential threat.

Luxury Yacht Dealer Attack Claimed by Rhysida Gang

22 March 2024
MarineMax, which posted multibillion-dollar revenues last year, disclosed a cyberattack to the Securities and Exchange Commission (SEC) on March 10, saying portions of its business were disrupted as a result of the containment measures it enacted.

WebCopilot: Open-Source Automation Tool Enumerates Subdomains, Detects Bugs

22 March 2024
WebCopilot is an open-source automation tool that enumerates a target’s subdomains and discovers bugs using various free tools. It simplifies the application security workflow and reduces reliance on manual scripting.

South China Athletic Association Suffers Cyberattack Potentially Compromising 70,000 Members’ Data

22 March 2024
The South China Athletic Association (SCAA) was rocked by a cyberattack as unauthorized third parties breached the organization’s computer servers, sparking concerns over the security of member data.

New StrelaStealer Phishing Attacks Hit Over 100 Organizations in E.U. and U.S.

22 March 2024
Cybersecurity researchers have detected a new wave of phishing attacks that aim to deliver an ever-evolving information stealer referred to as StrelaStealer. The campaigns impact more than 100 organizations in the E.U. and the U.S., Palo Alto Networks Unit 42 researchers said in a new report published today. "These campaigns come in the form of spam emails with attachments that eventually

US Airlines’ Privacy Protection Practices to Get DOT Review

22 March 2024
The Department of Transportation (DOT) will review data collection practices for the country's 10 largest airlines in a bid to improve passenger privacy protections, Secretary Pete Buttigieg said on Thursday.

AWS Patches Critical 'FlowFixation' Bug in Airflow Service to Prevent Session Hijacking

22 March 2024
Cybersecurity researchers have shared details of a now-patched security vulnerability in Amazon Web Services (AWS) Managed Workflows for Apache Airflow (MWAA) that could be potentially exploited by a malicious actor to hijack victims' sessions and achieve remote code execution on underlying instances. The vulnerability, now addressed by AWS, has been codenamed FlowFixation by Tenable.

78% of organizations plan to increase ransomware protection

22 March 2024
Ransomware protection is top of mind for both CXOs and practitioners but most organizations continue to struggle in the wake of attacks.

Fake Data Breaches: Countering the Damage

22 March 2024
Amid the constant drumbeat of successful cyberattacks, some fake data breaches have also cropped up to make sensational headlines. Unfortunately, even fake data breaches can have real repercussions.

GitHub’s New AI-Powered Tool Auto-Fixes Vulnerabilities in Your Code

22 March 2024
GitHub introduced a new AI-powered feature capable of speeding up vulnerability fixes while coding. This feature is in public beta and automatically enabled on all private repositories for GitHub Advanced Security (GHAS) customers.

The CISA releases a secure software development attestation form

22 March 2024
The CISA has released a set of guidelines to ensure that software developers are creating secure software systems for the government.

Jacksonville Beach Report Data Breach Following Cyberattacks

22 March 2024
The city government of Jacksonville Beach was just the latest to report such an incident, disclosing Wednesday evening that 48,949 people had personal information accessed during a January cyberattack.

RaaS Groups Increasing Efforts to Recruit Affiliates

22 March 2024
Smaller RaaS groups are trying to recruit new and “displaced” LockBit and Alphv/BlackCat affiliates by foregoing deposits and paid subscriptions, offering better payout splits, 24/7 support, and other “perks.”

China-Linked Group Breaches Networks via Connectwise, F5 Software Flaws

22 March 2024
A China-linked threat cluster leveraged security flaws in Connectwise ScreenConnect and F5 BIG-IP software to deliver custom malware capable of delivering additional backdoors on compromised Linux hosts as part of an "aggressive" campaign. Google-owned Mandiant is tracking the activity under its uncategorized moniker UNC5174 (aka Uteus or Uetus), describing it as a "former