Latest Cybersecurity News and Articles


Critical Fortinet Flaw May Impact 150,000 Exposed Devices

11 March 2024
Approximately 150,000 Fortinet FortiOS and FortiProxy secure web gateway systems are vulnerable to CVE-2024-21762, a critical security issue that allows code execution without authentication.

Update: Change Healthcare Systems Expected to Come back Online in Mid-March

11 March 2024
UnitedHealth Group is providing additional financial relief to healthcare providers affected by the cyberattack, including advancing funds and expanding temporary financing programs.

Microsoft Says Russian Hackers Stole Source Code After Spying on Its Executives

11 March 2024
Microsoft is facing an ongoing attack from a Russia state-sponsored threat actor that stole data from senior-level executives and is attempting to gain unauthorized access to the company's systems.

Lithuania Warns China Has Ramped up Espionage Campaigns

11 March 2024
The opening of Taiwan's Representative Office in Lithuania has prompted China to increase its focus on gathering information about the country's internal affairs and political landscape.

UK: Jersey Regulator’s Data Breach Leaks Names and Addresses

11 March 2024
The leak did not connect individuals to registered entities or roles, and the organization is working with the Jersey Office of the Information Commissioner to investigate further.

Proof-of-Concept Exploit Released for Progress Software OpenEdge Vulnerability

11 March 2024
Technical specifics and a proof-of-concept (PoC) exploit have been made available for a recently disclosed critical security flaw in Progress Software OpenEdge Authentication Gateway and AdminServer, which could be potentially exploited to bypass authentication protections. Tracked as CVE-2024-1403, the vulnerability has a maximum severity rating of 10.0 on the CVSS scoring system. It

Magnet Goblin Hacker Group Leveraging 1-Day Exploits to Deploy Nerbian RAT

11 March 2024
A financially motivated threat actor called Magnet Goblin is swiftly adopting one-day security vulnerabilities into its arsenal in order to opportunistically breach edge devices and public-facing services and deploy malware on compromised hosts. “Threat actor group Magnet Goblin’s hallmark is its ability to swiftly leverage newly disclosed vulnerabilities, particularly targeting

Cybersecurity and the current skills gap

11 March 2024
Staffing shortages and limited skillsets negatively impact security.

Canva Warns of Three Security Vulnerabilities in Fonts

09 March 2024
The first, CVE-2023-45139, involved a high-severity bug in the FontTools library. The second and third vulnerabilities, CVE-2024-25081 and CVE-2024-25082, were related to naming conventions and compression.

Tycoon and Storm-1575 Linked to Phishing Attacks on US Schools

09 March 2024
The Tycoon and Storm-1575 threat groups use stealthy tactics, social engineering, and phishing techniques to bypass MFA protections and target Microsoft 365 credentials at large US school districts.

Flaws in Public Records Management Tool Could Let Hackers Nab Sensitive Data Linked to Requests

09 March 2024
The GovQA platform, used by state and local governments for public records requests, had vulnerabilities that could have allowed hackers to access sensitive personal information, edit requests, and download unsecured files.

New Malware Campaign Found Exploiting Stored XSS in Popup Builder

09 March 2024
A new malware campaign was found targeting the Popup Builder WordPress plugin, exploiting a vulnerability disclosed in November 2023. The campaign injects malicious code into websites, leading to over 3,300 infections.

CISA Adds Apple iOS and iPadOS Memory Corruption Bugs to its Known Exploited Vulnerabilities Catalog

09 March 2024
These memory corruption vulnerabilities, tracked as CVE-2024-23225 and CVE-2024-23296, were exploited in attacks against iPhone devices. Apple released emergency security updates to address these zero-day vulnerabilities.

Microsoft Confirms Russian Hackers Stole Source Code, Some Customer Secrets

08 March 2024
Microsoft on Friday revealed that the Kremlin-backed threat actor known as Midnight Blizzard (aka APT29 or Cozy Bear) managed to gain access to some of its source code repositories and internal systems following a hack that came to light in January 2024. "In recent weeks, we have seen evidence that Midnight Blizzard is using information initially exfiltrated from our

Law Enforcement Personnel Say LexisNexis Retaliated When Asked to Remove Data

08 March 2024
More than 18,000 New Jersey law enforcement personnel are alleging that LexisNexis retaliated against them by freezing their credit and falsely reporting them as identity theft victims after they requested their information to remain private.

Today’s Biggest AI Security Challenges

08 March 2024
Adversaries can exploit AI-powered applications to manipulate information, create harmful content, and develop deep fake media, posing significant risks to organizations.

Report: 78% of MSPs Identify Cybersecurity as Prime IT Challenge

08 March 2024
Investment in the right technology and IT partners has led to fewer SMBs experiencing cyberattacks, with 64% of MSPs reporting less than 10% of their SMB customers being hit, according to Kaseya.

Russian Influence Operations Against Baltic States and Poland Having ‘Significant Impact’ on Society

08 March 2024
These campaigns aim to downplay the impact of Western sanctions on Russia's economy, fuel confrontation among Western countries, and spread fear and panic among the targeted populations.

Google Releases Android March 2024 Patches, Including Fixes for Two Critical Issues

08 March 2024
Google has released the Android March 2024 security patches, addressing a total of 38 vulnerabilities, including two critical issues. These vulnerabilities could lead to remote code execution and elevation of privilege for attackers.

Meta Details WhatsApp and Messenger Interoperability to Comply with EU's DMA Regulations

08 March 2024
Meta has offered details on how it intends to implement interoperability in WhatsApp and Messenger with third-party messaging services as the Digital Markets Act (DMA) went into effect in the European Union. “This allows users of third-party providers who choose to enable interoperability (interop) to send and receive messages with opted-in users of either Messenger or WhatsApp – both designated