Latest Cybersecurity News and Articles
28 February 2024
Traditional perimeter-based security has become costly and ineffective. As a result, communications security between people, systems, and networks is more important than blocking access with firewalls. On top of that, most cybersecurity risks are caused by just a few superusers – typically one out of 200 users. There’s a company aiming to fix the gap between traditional PAM and IdM
28 February 2024
A security vulnerability (CVE-2023-40000) in the LiteSpeed Cache plugin for WordPress allowed unauthenticated users to escalate their privileges, posing a significant risk to over five million installations.
28 February 2024
The increased connectivity between IT and OT systems, along with the rise in third-party access, introduces serious new risks that can leave organizations exposed to safety and security threats if access and connectivity are not properly controlled.
28 February 2024
The notorious Akira ransomware group has targeted the municipality of Bjuv in South Sweden, threatening to leak nearly 200GB of stolen data, including confidential documents and personal HR files.
28 February 2024
Corporate finance chiefs are less involved in SEC cybersecurity breach disclosure processes compared to chief information security officers, potentially leading to decision-making mistakes.
28 February 2024
Identifying and securing secrets in code is challenging due to the wide variety of secret types, but AI and ML can reduce false positives by as much as 86%, improving risk prioritization.
28 February 2024
The data breach occurred when an unauthorized party encrypted software used by medQ and hosted by a third-party data center, resulting in the exposure of confidential consumer data.
28 February 2024
Malware campaigns are evolving, using email attachments to deliver RAT infections, as demonstrated by the example of a PDF attachment impersonating Booking.com to lure victims.
28 February 2024
Mexican users have been targeted with tax-themed phishing lures at least since November 2023 to distribute a previously undocumented Windows malware called TimbreStealer.
Cisco Talos, which discovered the activity, described the authors as skilled and that the "threat actor has previously used similar tactics, techniques and procedures (TTPs) to distribute a banking trojan known
28 February 2024
Morphisec found that the UAC-0184 threat actor used steganography to deliver the Remcos RAT via the IDAT Loader, targeting a Ukrainian entity in Finland. The incident comes a few weeks after ASEC discovered that Remcos RAT is being distributed disguised as adult games through webhards. Researchers highlight that organizations must deploy behavioral-based endpoint protection solutions as an additional layer of security to thwart such attacks.
28 February 2024
In a new joint advisory, cybersecurity and intelligence agencies from the U.S. and other countries are urging users of Ubiquiti EdgeRouter to take protective measures, weeks after a botnet comprising infected routers was felled by law enforcement as part of an operation codenamed Dying Ember.
The botnet, named MooBot, is said to have been used by a Russia-linked threat actor known as
28 February 2024
How can security leaders prepare themselves for the unexpected? Answer this question and more on this episode of The Security Podcasts.
27 February 2024
The multi-stage dissemination of Xeno RAT via Discord CDN demonstrates the use of deceptive tactics such as disguised shortcut files to deliver and execute the open-source malware.
27 February 2024
A recent survey has revealed that less than half of IT leaders are assured in their IoT security plans.
27 February 2024
The cyberattack left LoanDepot's customers unable to make payments or access their online accounts, and the company expects the incident to impact its fiscal first quarter earnings by $12 to $17 million.
27 February 2024
The Federal Trade Commission (FTC) has banned software company Avast from selling or licensing web browsing data for advertising purposes.
27 February 2024
Cybersecurity researchers discovered a vulnerability in the Hugging Face Safetensors conversion service that could be exploited by attackers to compromise machine learning models submitted by users, leading to supply chain attacks.
27 February 2024
Zyxel has identified and patched four critical vulnerabilities in its firewall and access point products, including flaws that could lead to remote code execution and denial-of-service attacks.
27 February 2024
According to a report, nearly 75% of commercial codebases assessed for risk contain open source components impacted by high-risk vulnerabilities.
27 February 2024
The new version of Pikabot features simpler encryption algorithms, anti-debugging methods, and plaintext bot configuration, indicating a new codebase with potential future improvements.