Latest Cybersecurity News and Articles


Update: Black Basta, Bl00dy Ransomware Gangs Join ScreenConnect Attacks

28 February 2024
The Black Basta and Bl00dy ransomware gangs are exploiting a critical authentication bypass vulnerability (CVE-2024-1709) in unpatched ScreenConnect servers to gain admin access and deploy ransomware.

Calendar Meeting Links Used to Spread Mac Malware

28 February 2024
Malicious hackers are targeting people in the cryptocurrency space in attacks that start with a link added to the target’s account at Calendly, a popular free calendar application for scheduling appointments and meetings. The attackers impersonate established cryptocurrency investors and ask to schedule a video conference call. But clicking the meeting link provided by the scammers prompts the user to run a script that quietly installs malware on macOS systems.

Update: Ransomware Gang Seeks $3.4 Million After Attacking Children’s Hospital

28 February 2024
The hospital, which serves a large number of pediatric patients, is still providing care despite disruptions caused by the cyberattack. The ransomware group is attempting to sell stolen data from the hospital for 60 bitcoins.

Broken China? Separating fact from fiction

28 February 2024
In episode 20 of The Cybersecurity and Geopolitical Discussion, our trio of hosts discuss how, from the outside, China appears very different. However, is this really the case?

47% of cloud storage billing is allocated to data and usage fees

28 February 2024
Cloud storage was analyzed in a recent report finding that 93% of organizations plan to grow their public cloud storage capacity in 2024.

HSCC Issues Cyber 'Call to Action' Plan for Health Sector

28 February 2024
The plan includes 12 measurable objectives, such as increasing cybersecurity practices, developing cross-sector risk management strategies, and implementing automation and emerging technologies.

Iran-Linked UNC1549 Hackers Target Middle East Aerospace & Defense Sectors

28 February 2024
An Iran-nexus threat actor known as UNC1549 has been attributed with medium confidence to a new set of attacks targeting aerospace, aviation, and defense industries in the Middle East, including Israel and the U.A.E. Other targets of the cyber espionage activity likely include Turkey, India, and Albania, Google-owned Mandiant said in a new analysis. UNC1549 is said to overlap with 

Third-party attack vectors are responsible for 29% of breaches

28 February 2024
A recent report reveals that third-party attack vectors are involved in at least 29% of breaches, emphasizing the importance of third-party risk management. 

LabHost Cybercrime Service Lets Anyone Phish Canadian Bank Users

28 February 2024
LabHost offers three membership tiers targeting banks and online services, along with a real-time phishing management tool called LabRat that enables cybercriminals to steal 2FA protection.

Malicious Code in Tornado Cash Governance Proposal Puts User Funds at Risk

28 February 2024
The compromise was introduced via a governance proposal, and the Tornado Cash Developers confirmed the compromise, urging users to withdraw old deposit notes and token holders to cancel their votes for the malicious proposal.

TimbreStealer Campaign Targets Mexican Users with Financial Lures

28 February 2024
The malware comes with embedded modules for orchestration, decryption, and protection, while also conducting checks to avoid sandbox environments and targeting specific industries like manufacturing and transportation sectors.

Cybersecurity Agencies Warn Ubiquiti EdgeRouter Users of APT28's MooBot Threat

28 February 2024
Organizations are urged to perform a hardware factory reset, upgrade firmware, change default credentials, and implement firewall rules to protect against the MooBot attacks.

FBI Warns U.S. Healthcare Sector of Targeted BlackCat Ransomware Attacks

28 February 2024
The U.S. government is warning about the resurgence of BlackCat (aka ALPHV) ransomware attacks targeting the healthcare sector as recently as this month. "Since mid-December 2023, of the nearly 70 leaked victims, the healthcare sector has been the most commonly victimized," the government said in an updated advisory. "This is likely in response to the ALPHV/BlackCat administrator's

US Agencies Warn of ALPHV/Blackcat Ransomware Threat to Healthcare Providers

28 February 2024
ALPHV/Blackcat ransomware affiliates use advanced social engineering techniques and open-source research to gain initial access to victim networks, posing as IT or helpdesk staff to obtain credentials.

Russia and Belarus Targeted by at Least 14 Nation-State Hacker Groups, Researchers Say

28 February 2024
State-sponsored hacker groups targeted Russia and former Soviet Union members with destructive or espionage campaigns, indicating an increase in politically motivated cyber attacks in the region.

Building Your Privacy-Compliant Customer Data Platform (CDP) with First-Party Data

28 February 2024
In today's digital era, data privacy isn't just a concern; it's a consumer demand. Businesses are grappling with the dual challenge of leveraging customer data for personalized experiences while navigating a maze of privacy regulations. The answer? A privacy-compliant Customer Data Platform (CDP). Join us for a transformative webinar where we unveil Twilio Segment's state-of-the-art CDP.

Germany's Hessen Consumer Center Says Systems Encrypted by Ransomware

28 February 2024
The organization is working with external IT security experts to restore its communication channels and is committed to informing affected individuals if a data compromise is confirmed.

Enterprises’ Progress in Digital Trust Implementation is Far From Great

28 February 2024
Enterprises face challenges in managing the complexity of digital trust in a rapidly evolving technology landscape, which impacts their ability to protect digital assets.

Pharmaceutical Giant Cencora Says Data was Stolen in a Cyberattack

28 February 2024
The company has initiated containment measures, enlisted the help of law enforcement and cybersecurity experts, and is currently investigating the incident, with no confirmation yet on the impact to their finances or operations.

Meta to Assign Special Teams in Europe to Fight Election Disinformation, AI Abuse

28 February 2024
The company plans to set up a team in Europe to identify and mitigate election-related threats on its platforms in real time. It will also expand its fact-checking network with new partners in Bulgaria, France, and Slovakia.