Latest Cybersecurity News and Articles


Update: BlackCat Ransomware Turns off Servers Amid Claim They Stole $22 Million Ransom

05 March 2024
The shutdown may indicate an exit scam, with the affiliate claiming they still have critical data from Optum and other providers, while ALPHV/BlackCat has shut down its negotiation sites and messaging platform.

Hacktivist Collective NoName057(16) Strikes European Targets

05 March 2024
The cyber threat actor NoName057(16) is adapting its DDoS tactics with enhanced encryption and tailored software versions to target European entities, particularly those supporting Ukraine.

Security leaders weigh in on the recent UnitedHealth cyberattack

05 March 2024
UnitedHealth Group recently experienced a cyberattack caused by Blackcat, and experts are offering their insights on the ransomware group's behavior. 

Ukraine Claims it Hacked Russian Ministry of Defense Servers

05 March 2024
The Main Intelligence Directorate (GUR) of Ukraine's Ministry of Defense has announced that it successfully breached the servers of the Russian Ministry of Defense (Minoborony) and obtained sensitive documents.

South Korea Says Semiconductor Industry Targeted by Cyber-Spies From North Korea

05 March 2024
The National Intelligence Service (NIS) of South Korea reported that North Korean hackers targeted two South Korean microchip equipment companies, using "living-off-the-land" techniques to steal product designs and facility photos.

Self-Propagating Worm Created to Target Generative AI Systems

05 March 2024
Researchers from Israel Institute of Technology, Intuit and Cornell Tech have developed a computer worm called "Morris II" that targets generative AI (GenAI) applications to spread malware and steal personal data.

What is Exposure Management and How Does it Differ from ASM?

05 March 2024
Startups and scales-ups are often cloud-first organizations and rarely have sprawling legacy on-prem environments. Likewise, knowing the agility and flexibility that cloud environments provide, the mid-market is predominantly running in a hybrid state, partly in the cloud but with some on-prem assets. While there has been a bit of a backswing against the pricing and lock-in presented when using

Cybercriminals Using Novel DNS Hijacking Technique for Investment Scams

05 March 2024
A new DNS threat actor dubbed Savvy Seahorse is leveraging sophisticated techniques to entice targets into fake investment platforms and steal funds. “Savvy Seahorse is a DNS threat actor who convinces victims to create accounts on fake investment platforms, make deposits to a personal account, and then transfers those deposits to a bank in Russia,” Infoblox said in a report

Over 225,000 Compromised ChatGPT Credentials Up for Sale on Dark Web Markets

05 March 2024
More than 225,000 logs containing compromised OpenAI ChatGPT credentials were made available for sale on underground markets between January and October 2023, new findings from Group-IB show. These credentials were found within information stealer logs associated with LummaC2, Raccoon, and RedLine stealer malware. “The number of infected devices decreased slightly in mid- and late

Update: Optum Offering Financial Aid to Some Providers Hit by Outage

05 March 2024
UnitedHealth Group is offering short-term financial assistance to healthcare providers affected by the Change Healthcare IT outage, providing interest-free, fee-free funding.

Warning: Thread Hijacking Attack Targets IT Networks, Stealing NTLM Hashes

05 March 2024
The threat actor known as TA577 has been observed using ZIP archive attachments in phishing emails with an aim to steal NT LAN Manager (NTLM) hashes. The new attack chain “can be used for sensitive information gathering purposes and to enable follow-on activity,” enterprise security firm Proofpoint said in a Monday report. At least two campaigns taking advantage of this

ScreenConnect Flaws Exploited to Drop New ToddleShark Malware

05 March 2024
The North Korean hacking group Kimsuky is using newly disclosed ScreenConnect vulnerabilities to deploy a polymorphic malware variant called ToddleShark for espionage and data theft.

Securing Software Repositories Leads to Better OSS Security

05 March 2024
The OpenSSF has implemented various initiatives to improve open-source software security, including the creation of a Malicious Packages repository and partnering with CISA to develop a security maturity framework for package repositories.

Iowa Electric, Water Utility Says Information of Nearly 37,000 Leaked in January Ransomware Attack

05 March 2024
A utility company in eastern Iowa, Muscatine Power and Water, was hit by a ransomware attack in January, leading to the exposure of sensitive information of nearly 37,000 residents.

GitHub Push Protection Now on by Default for Public Repositories

05 March 2024
GitHub has implemented push protection as a default security feature for all public repositories to prevent accidental leaks of sensitive information such as API keys and tokens.

TA577 Exploits NTLM Authentication Vulnerability

05 March 2024
The group targeted hundreds of organizations globally with emails containing zipped HTML attachments designed to capture NTLM hashes. This method could enable password cracking or "Pass-The-Hash" attacks.

Exploit Available for New Critical JetBrains TeamCity Authentication Bypass Bug, Patch Now

05 March 2024
The JetBrains TeamCity On-Premises CI/CD solution has been found to have two critical vulnerabilities (CVE-2024-27198 and CVE-2024-27199) that can allow remote attackers to take control of the server and modify system settings without authentication.

Report: 95% Believe LLMs Making Phishing Detection More Challenging

05 March 2024
More than 95% of responding IT and security professionals believe social engineering attacks have become more sophisticated in the last year, according to a survey by LastPass.

How the Application ‘XHelper’ Is Powering the Indian Money-Laundering Gig Economy

05 March 2024
Cybercriminals in India are using the XHelper app to recruit money mules in order to launder illicitly obtained funds through fake payment gateways and cryptocurrency conversions.

Critical JetBrains TeamCity On-Premises Flaws Could Lead to Server Takeovers

04 March 2024
A new pair of security vulnerabilities have been disclosed in JetBrains TeamCity On-Premises software that could be exploited by a threat actor to take control of affected systems. The flaws, tracked as CVE-2024-27198 (CVSS score: 9.8) and CVE-2024-27199 (CVSS score: 7.3), have been addressed in version 2023.11.4. They impact all TeamCity On-Premises versions through 2023.11.3. “The