Latest Cybersecurity News and Articles


A Close Up Look at the Consumer Data Broker Radaris

08 March 2024
If you live in the United States, the data broker Radaris likely knows a great deal about you, and they are happy to sell what they know to anyone. But how much do we know about Radaris? Publicly available data indicates that in addition to running a dizzying array of people-search websites, the co-founders of Radaris operate multiple Russian-language dating services and affiliate programs. It also appears many of their businesses have ties to a California marketing firm that works with a Russian state-run media conglomerate currently sanctioned by the U.S. government.

CISA expresses concerns with VPNs, and security leaders respond

08 March 2024
A recent announcement from the CISA warns that malicious actors are exploiting vulnerabilities within VPN services. 

Tazama: Open-Source Real-Time Fraud Management

08 March 2024
Tazama is an open-source platform that offers scalable and cost-effective solutions for fraud management in digital payment systems, aiming to democratize access to advanced financial monitoring tools.

New Python-Based Snake Info-Stealer Spreads Through Facebook Messages

08 March 2024
The Snake malware campaign has been active since at least August 2023 and is attributed to Vietnamese-speaking individuals based on indicators such as targeted browsers and comments in the scripts.

National Intelligence Agency of Moldova Warns of Russia Attacks Ahead of the Presidential Election

08 March 2024
The Russian cyber operations are expected to manipulate public sentiment, interfere with the referendum to join the EU, and discredit pro-European candidates during the presidential elections.

CISA, NSA Share Best Practices for Securing Cloud Services

08 March 2024
The NSA and CISA have issued five joint bulletins outlining best practices for securing cloud environments, covering identity and access management, key management, encryption, data security, and mitigating risks from managed service providers.

China-Linked Evasive Panda APT Leverages Monlam Festival to Target Tibetans

08 March 2024
The attacks involved compromising websites, such as the Kagyu International Monlam Trust's website, to specifically target users in India, Taiwan, Hong Kong, Australia, and the U.S.

Cybersecurity Leader Claroty Secures $100M for Strategic Expansion and Innovation

08 March 2024
The company reported annual recurring revenue (ARR) surpassing $100 million and secured investments from major players such as Delta-v Capital, Standard Investments, and Rockwell Automation.

Ransomware Spikes Against Critical Infrastructure, Says FBI

08 March 2024
According to the latest Internet Crime Complaint Center (IC3) annual report, digital crimes reported to the FBI in 2023 resulted in potential monetary losses of over $12.5 billion, marking a 22 percent increase from the previous year.

Cisco Secure Client Carriage Return Line Feed Injection Vulnerability Patched

08 March 2024
The vulnerability impacts Secure Client for Windows, Linux, and macOS, and has been addressed in specific versions, with Amazon security researcher Paulos Yibelo Mesfin credited with discovering and reporting the flaw.

Secrets Sensei: Conquering Secrets Management Challenges

08 March 2024
In the realm of cybersecurity, the stakes are sky-high, and at its core lies secrets management — the foundational pillar upon which your security infrastructure rests. We're all familiar with the routine: safeguarding those API keys, connection strings, and certificates is non-negotiable. However, let's dispense with the pleasantries; this isn't a simple 'set it and forget it' scenario. It's

Ex-Google Engineer Charged with Stealing AI Secrets

08 March 2024
Former Google engineer Linwei Ding has been charged with stealing trade secrets related to artificial intelligence (AI) and supercomputing data centres while secretly working for Chinese companies.

MitM Phishing Attack can Let Attackers Unlock and Steal a Tesla

08 March 2024
The attack exploited the lack of proper authentication security when linking a new phone key to a Tesla, allowing an attacker to add a new "Phone Key" and gain unauthorized access to the vehicle.

AnyCubic Fixes Exploited 3D Printer Zero Day Flaw With New Firmware

08 March 2024
AnyCubic released new firmware for its Kobra 3D printers to fix a zero-day vulnerability that allowed hackers to send security warnings to the printers. This vulnerability was due to insecure permissions in the company's MQTT server.

Cisco Issues Patch for High-Severity VPN Hijacking Bug in Secure Client

08 March 2024
Cisco has released patches to address a high-severity security flaw impacting its Secure Client software that could be exploited by a threat actor to open a VPN session with that of a targeted user. The networking equipment company described the vulnerability, tracked as CVE-2024-20337 (CVSS score: 8.2), as allowing an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF

QEMU Emulator Exploited as Tunneling Tool to Breach Company Network

08 March 2024
Threat actors have been observed leveraging the QEMU open-source hardware emulator as tunneling software during a cyber attack targeting an unnamed "large company" to connect to their infrastructure. While a number of legitimate tunneling tools like Chisel, FRP, ligolo, ngrok, and Plink have been used by adversaries to their advantage, the development marks the first QEMU that has been

CISA Warns of Actively Exploited JetBrains TeamCity Vulnerability

08 March 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting JetBrains TeamCity On-Premises software to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability, tracked as CVE-2024-27198 (CVSS score: 9.8), refers to an authentication bypass bug that allows for a complete

Minnesota's South St. Paul Public Schools Investigating Potential Cybersecurity Threat

07 March 2024
This incident is impacting online platforms, emails, and other digital services. The school district is working to restore its systems and maintain a secure online environment for students and staff.

Canadian City Says Timeline for Recovery From Ransomware Attack ‘Unknown’

07 March 2024
The city of Hamilton, Canada, is recovering from a ransomware attack that has disrupted online government services, forcing residents to use cash transactions and manual methods for payments.

Ransomware Attackers Leak Sensitive Swiss Government Documents, Login

07 March 2024
The leaked data included 65,000 documents, with 5% related to the federal government. Most of the leaked federal government files contained personal data, technical information, classified data, and passwords.