Latest Cybersecurity News and Articles


15% of adults have been targeted by inheritance scams

20 March 2024
Payment and financial scams were analyzed in a recent report by Visa, finding that adults were losing more money to scams from June to December 2023.

Russia-Linked APT28 Targets Victims Worldwide for Intelligence Gathering

20 March 2024
Fancy Bear has utilized at least 11 unique lures in campaigns targeting organizations in Argentina, Ukraine, Georgia, Belarus, Kazakhstan, Poland, Armenia, Azerbaijan, and the United States.

Infosec Teams Must be Allowed to Fail, Argues Gartner

20 March 2024
Zero tolerance of failure by infosec professionals is unrealistic, and makes it harder for cybersecurity folk to do the essential part of their job: recovering fast from inevitable attacks, according to Gartner analysts Chris Mixter and Dennis Xu.

Pokémon Resets Some Users’ Passwords After Hacking Attempts

20 March 2024
“The account system was not compromised. What we did experience and catch was an attempt to log in to some accounts. To protect our customers we have reset some passwords which prompted the message,” said Daniel Benkwitt, a company spokesperson said.

50,000 Vulnerabilities Discovered in DoD Systems Through Bug Bounty

20 March 2024
The DoD Cyber Crime Center (DC3) reported on March 15, 2024, that it processed its 50,000th vulnerability since introducing its crowd-sourced ethical hacking scheme in November 2016.

TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types

20 March 2024
Threat actors can exploit CVE-2024-27198 to perform a variety of malicious operations, including dropping the Jasmin ransomware, XMRig miner, Cobalt Strike beacons, SparkRAT backdoor, and executing domain discovery and persistence commands.

Ransomware Groups: Trust Us. Uh, Don't.

20 March 2024
Double extortion demands from ransomware groups aren't subtle: Pay us, or we'll publish stolen internal data for all the world to see. Being listed on the group's dark web leak sites is an intermediary step.

A new report predicts the threats that will be most prevalent in 2024

20 March 2024
A recent report has analyzed emerging threat trends as well as potential trends that may grow in influence in the coming months. 

Pharmaceutical Development Company Investigating Cyberattack After LockBit Posting

20 March 2024
A Nasdaq-listed pharmaceutical development company said it is investigating a cybersecurity incident following claims from the LockBit ransomware gang that data was stolen.

Ransomware Payment Debate Resurfaces Amid Change Healthcare Incident

20 March 2024
A hotly debated flashpoint in the cybersecurity community is getting renewed attention as healthcare stakeholders work to rebound from a major ransomware attack that’s roiled the U.S. health insurance market over the past month.

Generative AI Security - Secure Your Business in a World Powered by LLMs

20 March 2024
Did you know that 79% of organizations are already leveraging Generative AI technologies? Much like the internet defined the 90s and the cloud revolutionized the 2010s, we are now in the era of Large Language Models (LLMs) and Generative AI. The potential of Generative AI is immense, yet it brings significant challenges, especially in security integration. Despite their powerful capabilities,

TeamCity Flaw Leads to Surge in Ransomware, Cryptomining, and RAT Attacks

20 March 2024
Multiple threat actors are exploiting the recently disclosed security flaws in JetBrains TeamCity software to deploy ransomware, cryptocurrency miners, Cobalt Strike beacons, and a Golang-based remote access trojan called Spark RAT. The attacks entail the exploitation of CVE-2024-27198 (CVSS score: 9.8) that enables an adversary to bypass authentication measures and gain administrative

FTC Warns Scammers are Impersonating its Employees to Steal Money

20 March 2024
FTC staff has received numerous reports from consumers who have fallen victim to scams in which fraudsters exploited the identities of agency personnel to coerce them via phone calls, email, or text messages into transferring or wiring money.

What’s Material to the SEC, Three Months Into Cyber Disclosure Rules?

20 March 2024
Three months since the launch of the Securities and Exchange Commission’s cyber incident reporting rule, companies are grappling with the question of when the impact of a breach or attack is considered material.

LockBit Attempts to Stay Afloat With a New Version

20 March 2024
Recently, researchers came into possession of a sample believed to represent a new evolution of LockBit: an in-development version of a platform-agnostic malware-in-testing that is different from previous versions.

US is Still Chasing Down Pieces of Chinese Hacking Operation, NSA Official Says

20 March 2024
The U.S. government has yet to learn the full extent of a massive Chinese espionage campaign that targeted American critical infrastructure, according to a senior National Security Agency official.

CISA Shares Critical Infrastructure Defense Tips Against Chinese Hackers

20 March 2024
U.S. authorities are concerned that this Chinese group may exploit access to Operational Technology (OT) assets to further disrupt critical infrastructure and cause disruptions during military conflicts or geopolitical tensions.

New BunnyLoader Malware Variant Surfaces with Modular Attack Features

20 March 2024
Cybersecurity researchers have discovered an updated variant of a stealer and malware loader called BunnyLoader that modularizes its various functions as well as allow it to evade detection. "BunnyLoader is dynamically developing malware with the capability to steal information, credentials and cryptocurrency, as well as deliver additional malware to its victims," Palo Alto Networks

Threat Environment is Changing for Individuals and SMBs, White House Order Shows

20 March 2024
An executive order is trying to prevent the large-scale transfer of Americans’ data, as countries seek troves of U.S. data for blackmail, AI training, and analysis, among a multitude of other purposes.

Researchers Uncover New “Conversation Overflow” Tactics

20 March 2024
An advisory published by SlashNext today called the tactic a “Conversation Overflow” attack, a method that circumvents advanced security measures to deliver phishing messages directly into victims’ inboxes.