Latest Cybersecurity News and Articles


Ex-Google Engineer Arrested for Stealing AI Technology Secrets for China

07 March 2024
The U.S. Department of Justice (DoJ) announced the indictment of a 38-year-old Chinese national and a California resident of allegedly stealing proprietary information from Google while covertly working for two China-based tech companies. Linwei Ding (aka Leon Ding), a former Google engineer who was arrested on March 6, 2024, "transferred sensitive Google trade secrets and other confidential

Update: Europol, DOJ, NCA Deny Involvement in Recent ALPHV/BlackCat ‘Shutdown’

07 March 2024
The incident highlights the common occurrence of theft and exit scams within criminal ransomware organizations, and experts anticipate the group's return under a new identity after their hiatus.

Update: CMS Rolls Out Provider Flexibilities Amid Fallout From Change Healthcare Cyberattack

07 March 2024
Provider groups, such as the American Hospital Association and the American Medical Association, are urging the government to provide further financial assistance, particularly for smaller practices, in response to the cyberattack's impact.

US Government Sanctions Intellexa Consortium Individuals and Entities Behind Predator Spyware Attacks

07 March 2024
The U.S. government sanctioned individuals and entities linked to the development and distribution of the Predator spyware, which was used to target Americans and U.S. government officials.

Hackers Abuse QEMU to Covertly Tunnel Network Traffic in Cyberattacks

07 March 2024
Threat actors used the open-source hypervisor QEMU as a network tunneling tool to create a covert communication channel, demonstrating the diverse methods attackers use to remain stealthy.

CISA Adds Android Pixel and Sunhillo SureLine Bugs to its Known Exploited Vulnerabilities Catalog

07 March 2024
The CISA added Android Pixel and Sunhillo SureLine vulnerabilities to its Known Exploited Vulnerabilities catalog, with the potential for local information disclosure and OS command injection.

TA4903 Threat Actor Spoofs U.S. Government, Small Businesses in Phishing, BEC Bids

07 March 2024
The actor uses tactics such as spoofing government agencies, incorporating QR codes in phishing campaigns, and adopting new themes to lure victims into credential phishing and BEC activities.

New Python-Based Snake Info Stealer Spreading Through Facebook Messages

07 March 2024
Facebook messages are being used by threat actors to a Python-based information stealer dubbed Snake that’s designed to capture credentials and other sensitive data. “The credentials harvested from unsuspecting users are transmitted to different platforms such as Discord, GitHub, and Telegram,” Cybereason researcher Kotaro Ogino said in a technical report. Details about the campaign&

Watch Out for Spoofed Zoom, Skype, Google Meet Sites Delivering Malware

07 March 2024
Threat actors have been leveraging fake websites advertising popular video conferencing software such as Google Meet, Skype, and Zoom to deliver a variety of malware targeting both Android and Windows users since December 2023. “The threat actor is distributing Remote Access Trojans (RATs) including SpyNote RAT for Android platforms, and NjRAT and DCRat for Windows

Insider-driven data loss incidents cost an average of $15 million

06 March 2024
Data loss caused by insider events costs an average of $15 million, highlighting the importance of information protection. 

Hackers Exploit Misconfigured YARN, Docker, Confluence, Redis Servers for Crypto Mining

06 March 2024
Threat actors are targeting misconfigured and vulnerable servers running Apache Hadoop YARN, Docker, Atlassian Confluence, and Redis services as part of an emerging malware campaign designed to deliver a cryptocurrency miner and spawn a reverse shell for persistent remote access. “The attackers leverage these tools to issue exploit code, taking advantage of common misconfigurations and

69% of financial services consumers prioritize fraud protection

06 March 2024
According to a report, 69% of consumers rank good fraud protection in their top three considerations when choosing a financial service provider.

Exit Scam: BlackCat Ransomware Group Vanishes After $22 Million Payout

06 March 2024
The threat actors behind the BlackCat ransomware have shut down their darknet website and likely pulled an exit scam after uploading a bogus law enforcement seizure banner. "ALPHV/BlackCat did not get seized. They are exit scamming their affiliates," security researcher Fabian Wosar said. "It is blatantly obvious when you check the source code of the new takedown notice." "There

Organizations are Knowingly Releasing Vulnerable Applications

06 March 2024
Application security responsibilities have shifted to involve both AppSec managers and developers, with a high percentage of companies knowingly releasing vulnerable applications due to time and business pressures.

Boston Red Sox partner with Centripetal for cyber network security

06 March 2024
A partnership between the Boston Red Sox and Centripetal seeks to bolster the stadium's cyber network security.  

CrowdStrike to Buy Israeli Data Defense Vendor Flow Security

06 March 2024
CrowdStrike has announced plans to acquire Tel Aviv-based Flow Security, a data security posture management startup, for an undisclosed amount with the deal expected to close by the end of April.

Hornetsecurity Buys Vade to Fuel Strength in France, Germany

06 March 2024
The joint company plans to integrate their products and teams by the end of 2024, enabling MSPs to manage security, compliance, and data loss prevention for Microsoft 365 from a single control portal.

Researchers Warn of Stuxnet-Style Web-Based PLC Malware

06 March 2024
Researchers from the Georgia Institute of Technology have developed web-based malware called IronSpider, targeting modern programmable logic controllers (PLCs) used in industrial control systems.

A New Way To Manage Your Web Exposure: The Reflectiz Product Explained

06 March 2024
An in-depth look into a proactive website security solution that continuously detects, prioritizes, and validates web threats, helping to mitigate security, privacy, and compliance risks.  [Reflectiz shields websites from client-side attacks, supply chain risks, data breaches, privacy violations, and compliance issues] You Can’t Protect What You Can’t See Today’s websites are connected

DTEX Systems Raises $50M in Series E Funding

06 March 2024
The funding round was led by CapitalG, with James Luo joining the DTEX board of directors. The company plans to utilize the funding to expand its U.S. engineering team and grow its global go-to-market operations.