Latest Cybersecurity News and Articles


WordPress Plugin Alert - Critical SQLi Vulnerability Threatens 200K+ Websites

27 February 2024
A critical security flaw (CVE-2024-1071) in the Ultimate Member WordPress plugin allowed unauthenticated attackers to perform SQL injection and extract sensitive data, affecting users who enabled the "Enable custom table for usermeta" option.

Report: CVE Count Set to Rise by 25% in 2024

27 February 2024
A report from Coalition predicts a 25% increase in common vulnerabilities and exposures (CVEs) in 2024, reaching 34,888 vulnerabilities. This sharp rise in CVEs raises concerns about software vulnerability and the potential for ransomware attacks.

New IDAT Loader Version Uses Steganography to Push Remcos RAT

27 February 2024
The attackers employed sophisticated techniques such as code injection, execution modules, and dynamic loading of Windows API functions to evade detection by automated security products.

MGM Resorts’ Cyberattack Headache Continues as Regulators Launch Investigations

27 February 2024
MGM Resorts is facing regulatory investigations and potential fines following a cyberattack that disrupted its operations, with the possibility of incurring losses from legal proceedings.

UK: NCSC to Offer Cyber Governance Guidance to Boards

27 February 2024
Boards have a legal responsibility to understand and manage cyber-governance within their organizations and should seek practical guidance to enhance their cybersecurity understanding.

PayPal Files Patent for New Method to Detect Stolen Cookies

27 February 2024
PayPal has filed a patent application for a method to detect when "super-cookies" are stolen, aiming to improve cookie-based authentication and prevent account takeover attacks.

Earth Lusca Uses Geopolitical Lure to Target Taiwan Before Elections

27 February 2024
The attack involved a multi-stage infection chain, including spear phishing, obfuscated JavaScript files, and DLL hijacking, ultimately leading to the deployment of a Cobalt Strike payload.

WordPress Plugin Alert - Critical SQLi Vulnerability Threatens 200K+ Websites

27 February 2024
A critical security flaw has been disclosed in a popular WordPress plugin called Ultimate Member that has more than 200,000 active installations. The vulnerability, tracked as CVE-2024-1071, carries a CVSS score of 9.8 out of a maximum of 10. Security researcher Christiaan Swiers has been credited with discovering and reporting the flaw. In an advisory published last week, WordPress

48% of executives focus AI strategy on SaaS applications

26 February 2024
According to the report, more than 90% of enterprises are currently experiencing limitations integrating AI into their technology stack.

The UK has seen an increase in cyberattacks against higher education

26 February 2024
A recent report discusses the rise in attacks on higher education institutions in the UK, highlighting the need for cybersecurity strategies. 

Russia-based LockBit ransomware hackers attempt comeback

26 February 2024
Russia-based LockBit ransomware hackers attempt comeback Gang sets up new site on dark web and releases rambling statement explaining how it was infiltrated by law enforcement agenciesThe LockBit ransomware gang is attempting a comeback days after its operations were severely disrupted by a coordinated international crackdown.The Russia-based group has set up a new site on the dark web to advertise a small number of alleged victims and leak stolen data, as well as releasing a rambling statement explaining how it had been hobbled by the UK’s National Crime Agency, the FBI, Europol and other police agencies in an operation last week. Continue reading...

HHS OCR Tells Congress it Needs More Funding for HIPAA Work

26 February 2024
The number of reported health data breaches and HIPAA complaints has been increasing, posing a significant challenge for the Department of Health and Human Services' Office for Civil Rights to keep up with their workload.

Microsoft Releases PyRIT - A Red Teaming Tool for Generative AI

26 February 2024
The tool can be used to assess the robustness of large language model (LLM) endpoints against various harm categories, such as fabrication, misuse, prohibited content, security harms, and privacy harms.

New IDAT Loader Attacks Using Steganography to Deploy Remcos RAT

26 February 2024
Ukrainian entities based in Finland have been targeted as part of a malicious campaign distributing a commercial remote access trojan known as Remcos RAT using a malware loader called IDAT Loader. The attack has been attributed to a threat actor tracked by the Computer Emergency Response Team of Ukraine (CERT-UA) under the moniker UAC-0184. "The attack, as part of the IDAT Loader, used

California AG Settles with DoorDash Over Selling Consumer Data Without Notice

26 February 2024
The settlement includes a $375,000 civil penalty, a review of vendor agreements, and the requirement to provide annual reports on potential sale or sharing of consumer information.

8,000+ Subdomains of Trusted Brands Hijacked for Massive Spam Operation

26 February 2024
More than 8,000 subdomains belonging to legitimate brands and institutions have been hijacked as part of a sophisticated distribution architecture for spam proliferation and click monetization. Guardio Labs is tracking the coordinated malicious activity, which has been ongoing since at least September 2022, under the name SubdoMailing. The emails range from "counterfeit package delivery alerts

CISA, EPA, FBI Publish Top Cyber Steps for Water System Operators

26 February 2024
Water and wastewater systems need to enhance their cybersecurity measures to protect against potential cyberattacks due to vulnerabilities in their operational technology (OT) and information technology (IT) systems.

Change Healthcare provides update on cyberattack

26 February 2024
Change Healthcare, a technology company primarily used for pharmaceutical communication, has notified users and patients of a cyberattack.

North Korean Hackers Targeting Developers with Malicious npm Packages

26 February 2024
The malicious packages contained scripts capable of stealing credentials from web browsers, downloading additional harmful scripts, and establishing connections to known North Korean threat actors.

Update: Authorities Uncover 30,000 Bitcoin Wallet Addresses Linked to LockBit

26 February 2024
Law enforcement's takedown of LockBit's infrastructure revealed 2,200 unspent bitcoins worth over $110 million, highlighting the extensive scale of the group's operations.