Latest Cybersecurity News and Articles


Report: Info-Stealers Target Stored Browser Credentials

04 March 2024
Hackers are increasingly targeting saved passwords in browsers and using various malware and info stealers to steal credentials, leading to a growing number of stolen logs and compromised accounts.

US Coast Guard Expands Cyber Command to Combat New Threats

04 March 2024
The U.S. Coast Guard is expanding its cybersecurity capabilities and building out cybersecurity protection teams to assess, identify, and respond to cyber risks and threats in the maritime transportation system.

Eken Camera Doorbells Allow Ill-Intentioned Individuals to Spy on You

04 March 2024
Camera doorbells manufactured by Eken Group Ltd under the brands EKEN and Tuck have major vulnerabilities that could allow threat actors to view footage from the devices or control them completely.

Phobos Ransomware Aggressively Targeting U.S. Critical Infrastructure

04 March 2024
U.S. cybersecurity and intelligence agencies have warned of Phobos ransomware attacks targeting government and critical infrastructure entities, outlining the various tactics and techniques the threat actors have adopted to deploy the file-encrypting malware. “Structured as a ransomware as a service (RaaS) model, Phobos ransomware actors have targeted entities including municipal and

Taiwan's Biggest Telco Breached by Suspected Chinese Hackers

02 March 2024
Hackers stole sensitive information, including military and government documents, from Chunghwa Telecom and sold it on the dark web. The leaked data included documents from the armed forces, foreign affairs ministry, coast guard, and other units.

Police Seized Crimemarket, the Largest German-Speaking Cybercrime Marketplace

02 March 2024
The platform had over 180,000 registered users and was accessible through both the "Darknet" and the "Clearnet." The investigation is ongoing, with plans to identify and target the platform's users.

CISA adds Microsoft Streaming Service bug to its Known Exploited Vulnerabilities catalog

02 March 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the CVE-2023-29360 Microsoft Streaming Service vulnerability to its Known Exploited Vulnerabilities catalog, which allows attackers to gain SYSTEM privileges.

U.S. Court Orders NSO Group to Hand Over Pegasus Spyware Code to WhatsApp

02 March 2024
A U.S. judge has ordered NSO Group to hand over its source code for Pegasus and other products to Meta as part of the social media giant's ongoing litigation against the Israeli spyware vendor. The decision, which marks a major legal victory for Meta, which filed the lawsuit in October 2019 for using its infrastructure to distribute the spyware to approximately

UK Unveils Draft Cybersecurity Governance Code

02 March 2024
The UK Department for Science, Innovation and Technology (DSIT) has revealed what its future Cybersecurity Governance Code of Practice will look like and the five principals it will include.

CryptoChameleon: New Phishing Tactics Exhibited in FCC-Targeted Attack

02 March 2024
A sophisticated phishing kit with novel tactics targets cryptocurrency platforms and the FCC through a combination of email, SMS, and voice phishing, successfully stealing high-quality data from mobile device users in the United States.

U.S. Charges Iranian Hacker, Offers $10 Million Reward for Capture

01 March 2024
The U.S. Department of Justice (DoJ) on Friday unsealed an indictment against an Iranian national for his alleged involvement in a multi-year cyber-enabled campaign designed to compromise U.S. governmental and private entities. More than a dozen entities are said to have been targeted, including the U.S. Departments of the Treasury and State, defense contractors that support U.S. Department of

Golden Corral Restaurant Chain Suffers Data Breach Impacting 183,000 People

01 March 2024
The stolen data may include a wide range of personal information such as Social Security numbers, financial account details, medical information, and usernames and passwords.

FBI, CISA Release IoCs for Phobos Ransomware

01 March 2024
The Phobos ransomware strain, distributed through ransomware-as-a-service, has targeted a wide range of organizations, including governments, healthcare, education, and critical infrastructure sectors.

New Bifrost Variant Uses Domain Deception Tactic to Deceive Users

01 March 2024
The latest variant of BIFROSE masquerades as VMware by reaching out to a deceptive domain. There has been a spike in BIFROSE activity since October 2023, and a new Arm version of the malware has been discovered.

Researchers Found a Zero-Click Facebook Account Takeover

01 March 2024
The critical vulnerability in Facebook's password reset process involved a rate-limiting issue in a specific endpoint, which could be exploited to brute-force a nonce and gain access to a user's account.

Security leaders discuss ONCD's call for memory-safe software

01 March 2024
Security leaders weigh in on the recent announcement by the ONCD, which encourages technological manufactures to develop software with memory safety in mind.

Leaky Database Spilled 2FA Codes for Global Tech Giants

01 March 2024
An exposed database belonging to YX International leaked sensitive data including one-time security codes for major tech and online companies like Facebook, Google, and TikTok.

Law Firm Reports Data Breach Affecting More Than 325,000 People

01 March 2024
The breached data included names, Social Security numbers, financial account information, and medical information. An unauthorized third party accessed the firm's network, leading to a data breach.

Update: Irish Foreign Affairs Ministry Says ‘No Evidence’ of Cyber Breach Following Extortion Claim

01 March 2024
The Department of Foreign Affairs in Ireland has found no evidence to support the claim of a cyber extortion group called Mogilevich that it stole data from their IT systems.

New Phishing Kit Leverages SMS, Voice Calls to Target Cryptocurrency Users

01 March 2024
A novel phishing kit has been observed impersonating the login pages of well-known cryptocurrency services as part of an attack cluster designed to primarily target mobile devices. “This kit enables attackers to build carbon copies of single sign-on (SSO) pages, then use a combination of email, SMS, and voice phishing to trick the target into sharing usernames, passwords, password reset URLs,