Latest Cybersecurity News and Articles
29 February 2024
The open-source tool supports various payload delivery chains and has future plans to add more image polyglots, file extensions, and EML file support for stealthy payload delivery.
29 February 2024
While customer, supplier, and colleague information was not compromised, the incident may have involved a social engineering attack known as business email compromise (BEC).
29 February 2024
Threat hunters have discovered a new Linux malware called GTPDOOR that’s designed to be deployed in telecom networks that are adjacent to GPRS roaming exchanges (GRX)
The malware is novel in the fact that it leverages the GPRS Tunnelling Protocol (GTP) for command-and-control (C2) communications.
GPRS roaming allows subscribers to access their GPRS services while they are
29 February 2024
The notorious Lazarus Group actors exploited a recently patched privilege escalation flaw in the Windows Kernel as a zero-day to obtain kernel-level access and disable security software on compromised hosts.
The vulnerability in question is CVE-2024-21338 (CVSS score: 7.8), which can permit an attacker to gain SYSTEM privileges. It was resolved by Microsoft earlier this month as part
29 February 2024
As an IT leader, staying on top of the latest cybersecurity developments is essential to keeping your organization safe. But with threats coming from all around — and hackers dreaming up new exploits every day — how do you create proactive, agile cybersecurity strategies? And what cybersecurity approach gives you the most bang for your buck, mitigating your risks and maximizing the value of your
29 February 2024
The 2023 Cyber Threat Landscape report from France’s National Cybersecurity Agency (ANSSI) highlights a significant increase in cyber espionage campaigns targeting individuals and non-governmental organizations.
29 February 2024
Hochschule Kempten, a university of applied sciences in Germany, has been targeted by a criminal cyberattack. The attack has affected access to several IT systems, including email, while the telephone system remains operational.
29 February 2024
Russian hacktivist groups' attacks have minimal impact and are more psychological than kinetic, aiming to degrade confidence in governments and rally support for Russian President Vladimir Putin.
29 February 2024
Chinese threat actor UNC5325 is adept at using novel malware and "living off the land" techniques to persist in hacked devices even after factory resets and system upgrades.
29 February 2024
Per a Proofpoint report, over two-thirds of organizations experienced a successful ransomware incident in the past year, with close to 60% reporting four or more separate ransomware incidents.
29 February 2024
Ukraine's military intelligence has reported that Russia has invested over $1 billion in a disinformation campaign called "Maidan-3" aimed at diminishing Western support for Kyiv and sowing distrust among Ukrainian citizens.
29 February 2024
The FTC's aggressive approach to enforcing privacy regulations reflects a commitment to ensuring that AI model refinement does not compromise people's privacy or security.
29 February 2024
A previously undocumented threat actor dubbed SPIKEDWINE has been observed targeting officials in European countries with Indian diplomatic missions using a new backdoor called WINELOADER.
The adversary, according to a report from Zscaler ThreatLabz, used a PDF file in emails that purported to come from the Ambassador of India, inviting diplomatic staff to a wine-tasting
29 February 2024
The notorious North Korean state-backed hacking group Lazarus uploaded four packages to the Python Package Index (PyPI) repository with the goal of infecting developer systems with malware.
The packages, now taken down, are pycryptoenv, pycryptoconf, quasarlib, and swapmempool. They have been collectively downloaded 3,269 times, with pycryptoconf accounting for the most
29 February 2024
The new executive order targets the unregulated data broker industry and prohibits the sale of genomic, biometric, health, geolocation, and financial data to the identified countries.
29 February 2024
According to Imperva's State of API Security Report, attacks on the business logic of APIs, including credential stuffing and data scraping, account for the largest share (27%) of API attacks.
29 February 2024
The cybersecurity firm Mandiant has identified a suspected Iranian hacking group, UNC1549, targeting aerospace and defense industries across the Middle East, including in Israel and the United Arab Emirates.
29 February 2024
At least two different suspected China-linked cyber espionage clusters, tracked as UNC5325 and UNC3886, have been attributed to the exploitation of security flaws in Ivanti Connect Secure VPN appliances.
UNC5325 abused CVE-2024-21893 to deliver a wide range of new malware called LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK, as well as attempted to maintain
29 February 2024
U.S. President Joe Biden has issued an Executive Order that prohibits the mass transfer of citizens' personal data to countries of concern.
The Executive Order also "provides safeguards around other activities that can give those countries access to Americans' sensitive data," the White House said in a statement.
This includes sensitive information such as genomic data, biometric data,
28 February 2024
Security experts weigh in on the CISA's advisory, which reveals that cyberattackers are adapting to the increased use of cloud infrastructure.