Latest Cybersecurity News and Articles


Abyss Locker Ransomware Attacks Both Windows And Linux Users

01 March 2024
This ransomware steals and encrypts files, demanding ransom for decryption and not releasing stolen data. It is based on the HelloKitty ransomware source code and has been observed in various regions.

Research finds that cybersecurity leaders are taking on multiple roles

01 March 2024
A new study shows trends in cybersecurity leader employment, compensation and retention.

Chinese PC-Maker Acemagic Shipped Machines Infected with Malware

01 March 2024
The company attributed the infection to software adjustments made by developers to reduce boot times, which inadvertently affected network settings and omitted digital signatures.

New Silver SAML Attack Bypasses Golden SAML MItigations

01 March 2024
The technique works with identity providers like Microsoft Entra ID and can enable attackers to access applications by forging SAML responses with compromised private keys.

Utility Regulators Take Steps to Raise Sector’s Cybersecurity ‘Baselines’

01 March 2024
The cybersecurity baselines aim to improve the security of distribution systems and distributed energy resources by including cybersecurity requirements in utilities’ procurement processes.

4 Instructive Postmortems on Data Downtime and Loss

01 March 2024
More than a decade ago, the concept of the ‘blameless’ postmortem changed how tech companies recognize failures at scale. John Allspaw, who coined the term during his tenure at Etsy, argued postmortems were all about controlling our natural reaction to an incident, which is to point fingers: “One option is to assume the single cause is incompetence and scream at engineers to make them

20 Million Cutout.Pro User Records Leaked on Data Breach Forum

01 March 2024
Users of Cutout.Pro are advised to reset their passwords immediately and be cautious of targeted phishing scams due to the potential threat of threat actors brute-forcing the leaked password hashes.

New BIFROSE Linux Malware Variant Using Deceptive VMware Domain for Evasion

01 March 2024
Cybersecurity researchers have discovered a new Linux variant of a remote access trojan (RAT) called BIFROSE (aka Bifrost) that uses a deceptive domain mimicking VMware. "This latest version of Bifrost aims to bypass security measures and compromise targeted systems," Palo Alto Networks Unit 42 researchers Anmol Maurya and Siddharth Sharma said. BIFROSE is one of the long-standing

Epic Games Says “Zero Evidence” of Hacking by Mogilevich Gang

01 March 2024
Epic Games found no evidence of a cyberattack or data theft after the Mogilevich group claimed to have breached their servers. The group offered to sell stolen data for $15,000 but only shared samples with those who proved they had the funds.

New Variant of AMOS Stealer Targets Safari Cookies and Crypto Wallets

01 March 2024
The new Atomic variant of the AMOS Stealer targets macOS users, combining multiple malware functionalities to steal sensitive data and has an unusual technique of combining Python with Apple Scripting.

Airbnb Scammers Pose as Hosts, Redirect Users to Fake Tripadvisor Site

01 March 2024
The scammers use emails and fake websites to trick users into making off-platform bookings and sharing their payment card details. Airbnb warns against off-platform activity and urges users to be cautious of emails and websites impersonating it.

Okta Reports ‘Minimal’ Financial Impact Following Support Portal Attack

01 March 2024
Despite the attack, the company is focusing on enhancing security and regaining customer trust. Okta plans to prioritize security in the upcoming fiscal year, with a $50 million investment in cybersecurity initiatives.

JPCERT/CC Warns of Malicious PyPI Packages Created by North Korean Hackers

01 March 2024
The malicious packages were disguised as legitimate Python packages, and although they have been removed from PyPI, they were downloaded over 3,000 times, compromising thousands of systems.

Kali Linux 2024.1 Released with New Tools, New Look, New Kali NetHunter Kernels

01 March 2024
The latest release of Kali Linux, version 2024.1, includes new tools, an updated kernel, and improvements to the desktop environments. The release also features updates to the Kali NetHunter mobile platform.

Savvy Seahorse Gang Uses DNS CNAME Records to Power Investor Scams

01 March 2024
Personal data of victims is collected through registration forms on fake investment platforms, and the actor tracks user information while preventing revisits from crawlers and security vendors.

Lazarus Hackers Exploited Windows Zero-Day to Gain Kernel Privileges

01 March 2024
The exploit allowed Lazarus to enhance its FudModule rootkit, enabling it to evade detection and disable security protections. Additionally, a previously undocumented remote access trojan (RAT) used by Lazarus was discovered.

Five Eyes Agencies Warn of Active Exploitation of Ivanti Gateway Vulnerabilities

01 March 2024
The Five Eyes (FVEY) intelligence alliance has issued a new cybersecurity advisory warning of cyber threat actors exploiting known security flaws in Ivanti Connect Secure and Ivanti Policy Secure gateways, noting that the Integrity Checker Tool (ICT) can be deceived to provide a false sense of security. "Ivanti ICT is not sufficient to detect compromise and that a cyber threat actor may be able

GitHub Rolls Out Default Secret Scanning Push Protection for Public Repositories

01 March 2024
GitHub on Thursday announced that it’s enabling secret scanning push protection by default for all pushes to public repositories. “This means that when a supported secret is detected in any push to a public repository, you will have the option to remove the secret from your commits or, if you deem the secret safe, bypass the block,” Eric Tooley and Courtney Claessens said. Push protection&

92% of companies experienced an application-related breach last year

01 March 2024
A study reveals that 92% of companies surveyed had experienced a breach in the prior year due to vulnerabilities of applications developed in-house.

Fulton County, Security Experts Call LockBit’s Bluff

29 February 2024
The ransomware group LockBit told officials with Fulton County, Ga. they could expect to see their internal documents published online this morning unless the county paid a ransom demand. Instead, LockBit removed Fulton County's listing from its victim shaming website this morning, claiming county officials had paid. But county officials said they did not pay, nor did anyone make payment on their behalf. Security experts say LockBit was likely bluffing and probably lost most of the data when the gang's servers were seized this month by U.S. and U.K. law enforcement.