Latest Cybersecurity News and Articles


Update: BlackCat Ransomware Gang Claims They Stole 6TB of Change Healthcare Data

29 February 2024
The BlackCat/ALPHV ransomware gang claimed responsibility for a cyberattack on Optum, affecting the Change Healthcare platform and potentially compromising sensitive data of millions of individuals and organizations.

European Diplomats Targeted by SPIKEDWINE Actors with WINELOADER Backdoor

29 February 2024
The adversary used a PDF file posing as an invitation from the Ambassador of India to a wine-tasting event, which contained a malicious link leading to the WINELOADER malware.

LockBit Ransomware Returns to Attacks With New Encryptors, Servers

29 February 2024
LockBit has set up new data leak and negotiation sites, and is actively recruiting experienced pentesters to join their operation, indicating a potential increase in future attacks.

Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor

29 February 2024
The model’s payload grants the attacker a shell on the compromised machine, enabling them to gain full control over victims’ machines through what is commonly referred to as a “backdoor”.

More than 60% of consumers would avoid a retailer post-breach

29 February 2024
A recent report studies consumer trends after an organization experiences a data breach, highlighting a breach's impact on reputation and customer base. 

GTPDOOR Linux Malware Targets Telecoms, Exploiting GPRS Roaming Networks

29 February 2024
GTPDOOR is a new Linux malware designed for telecom networks that leverages the GPRS Tunnelling Protocol (GTP) for command-and-control communications, posing a threat to subscriber information and call metadata.

Senator Asks FTC to Investigate Automakers’ Data Privacy Practices

29 February 2024
Senator Edward Markey has called for an investigation into the data privacy practices of the automotive industry, urging Federal Trade Commission (FTC) Chair Lina Khan to take action.

GitHub Besieged by Millions of Malicious Repositories in Ongoing Attack

29 February 2024
The attack involves the automated forking of legitimate repositories, resulting in millions of malicious forks with names identical to the original ones, making detection and removal challenging for GitHub.

DoE Invests $45 Million to Prevent Cyberattacks on US Energy Systems

29 February 2024
The Department of Energy's Office of Cybersecurity, Energy Security, and Emergency Response (CESER) has allocated $45 million for 16 projects aimed at developing new technologies to prevent cyberattacks and reduce energy disruptions.

Anycubic 3D Printers Hacked Worldwide to Expose Security Flaw

29 February 2024
The hackers have urged Anycubic to open-source their 3D printers due to software deficiencies and have warned affected customers to disconnect their printers from the Internet until the security issue is patched.

Cryptojacking is No Longer the Sole Focus of Cloud Attackers

29 February 2024
Cloud-focused malware campaigns are increasingly targeting services like Docker, Redis, Kubernetes, and Jupyter, requiring security teams to reassess their approaches to identifying and responding to emerging cloud threats.

Exploitation of vulnerabilities affecting Ivanti Connect Secure and Ivanti Policy Secure

29 February 2024
Organisations are encouraged to take immediate action to mitigate vulnerabilities affecting Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS) gateways (CVE-2023-46805, CVE-2024-21887, CVE-2024-21888 and CVE-2024-21893, CVE-2024-22024), and follow the latest vendor advice.

New Silver SAML Attack Evades Golden SAML Defenses in Identity Systems

29 February 2024
Cybersecurity researchers have disclosed a new attack technique called Silver SAML that can be successful even in cases where mitigations have been applied against Golden SAML attacks. Silver SAML “enables the exploitation of SAML to launch attacks from an identity provider like Entra ID against applications configured to use it for authentication, such as Salesforce,” Semperis

Report: Ads for Zero-Day Exploit Sales Surge 70% Annually

29 February 2024
Threat actors are increasingly using zero-day exploits to enhance the success of advanced targeted attacks, with a 70% increase in public ads selling zero-day exploits observed between 2022 and 2023, according to Group-IB.

Biden administration issues executive order to secure U.S. ports

29 February 2024
Security experts offer their perspective on the recent Biden-Harris executive order, which is intended to secure the nation's ports. 

Report: Vishing, Smishing, and Phishing Attacks Rise 1,265% Post-ChatGPT

29 February 2024
According to a report by Enea, 76% of enterprises lack sufficient voice and messaging fraud protection as AI-powered vishing and smishing skyrocketed following the launch of ChatGPT.

Report: Most Commercial Code Contains High-Risk Open Source Bugs

29 February 2024
The ninth annual Open Source Security and Risk Analysis (OSSRA) report by Synopsys revealed that 74% of commercial codebases contain high-risk open source vulnerabilities, an increase from 48% in 2022.

New analysis highlights strength of Ukraine's defence against “unprecedented” Russian offensive

29 February 2024
Report from the European Cyber Conflict Research Initiative (ECCRI) gives new insights into the role of cyber criminals and political hacktivists in a conflict, and critical questions around industry support to Ukraine's cyber resilience.

Australian Spy Chief Fears Critical Infrastructure Sabotage

29 February 2024
Adversaries are actively conducting sophisticated cyber reconnaissance on critical infrastructure networks in Australia, posing a significant threat to national security.

BEAST Attack on AI Models can Break LLM Guardrails in a Minute

29 February 2024
Computer scientists have developed a fast and efficient method, called BEAST, to generate harmful prompts that elicit undesirable responses from large language models using an Nvidia RTX A6000 GPU with 48GB of memory.