Latest Cybersecurity News and Articles


Hacker Arrested for Selling Bank Accounts of US, Canadian Users

21 February 2024
A 31-year-old Ukrainian cybercriminal was arrested for distributing trojanized software to gain access to American and Canadian users' bank accounts, selling the breached accounts on the dark web.

Iran and Hezbollah Hackers Launch Attacks to Influence Israel-Hamas Narrative

21 February 2024
Iranian and Hezbollah-backed hackers conducted cyber attacks to undermine public support for the Israel-Hamas war, using tactics such as destructive attacks, hack-and-leak operations, phishing campaigns, and information operations.

Permit.io Secures $8m in Series A for Revolutionary Authorization Service

21 February 2024
Permit.io, a provider of authorization-as-a-service solution has closed a successful $8m Series A funding round led by Scale Venture Partners and supported by other investors.

Israeli El Al Alleges Hackers Targeted Flights in Mid-Air Hijack Attempt

21 February 2024
The hackers tried to divert the planes, but the pilots detected the suspicious activity and took appropriate action to ensure the safety of the flights. This incident raises concerns about aircraft safety in the face of growing cybersecurity threats.

New 'VietCredCare' Stealer Targeting Facebook Advertisers in Vietnam

21 February 2024
Facebook advertisers in Vietnam are the target of a previously unknown information stealer dubbed VietCredCare at least since August 2022. The malware is “notable for its ability to automatically filter out Facebook session cookies and credentials stolen from compromised devices, and assess whether these accounts manage business profiles and if they maintain a positive Meta ad credit

Signal Introduces Usernames, Allowing Users to Keep Their Phone Numbers Private

21 February 2024
End-to-end encrypted (E2EE) messaging app Signal said it’s piloting a new feature that allows users to create unique usernames (not to be confused with profile names) and keep the phone numbers away from prying eyes. “If you use Signal, your phone number will no longer be visible to everyone you chat with by default,” Signal’s Randall Sarafa said. “People who have your number saved in their

LockBit Ransomware's Darknet Domains Seized in Global Law Enforcement Raid

21 February 2024
Law enforcement agencies from 11 countries, including the U.K. and the U.S., have collaborated in a joint effort, codenamed Operation Cronos, to seize multiple darknet domains operated by the ransomware group LockBit.

Russian Hackers Target Ukraine with Disinformation and Credential-Harvesting Attacks

21 February 2024
Cybersecurity researchers have unearthed a new influence operation targeting Ukraine that leverages spam emails to propagate war-related disinformation. The activity has been linked to Russia-aligned threat actors by Slovak cybersecurity company ESET, which also identified a spear-phishing campaign aimed at a Ukrainian defense company in October 2023 and a European Union agency in November 2023

VMware Alert: Uninstall EAP Now - Critical Flaw Puts Active Directory at Risk

21 February 2024
VMware is urging users to uninstall the deprecated Enhanced Authentication Plugin (EAP) following the discovery of a critical security flaw. Tracked as CVE-2024-22245 (CVSS score: 9.6), the vulnerability has been described as an arbitrary authentication relay bug. "A malicious actor could trick a target domain user with EAP installed in their web browser into requesting and relaying

Feds Seize LockBit Ransomware Websites, Offer Decryption Tools, Troll Affiliates

20 February 2024
U.S. and U.K. authorities have seized the darknet websites run by LockBit, a prolific and destructive ransomware group that has claimed more than 2,000 victims worldwide and extorted over $120 million in payments. Instead of listing data stolen from ransomware victims who didn't pay, LockBit's victim shaming website now offers free recovery tools, as well as news about arrests and criminal charges involving LockBit affiliates.

A penny per email could curb our enormous data use | Letters

20 February 2024
A penny per email could curb our enormous data use | Letters Mike McClelland proposes a 1p charge for messages in response to an article on the downside of Ireland’s datacentre boom. Plus a letter from Sue Stephenson The long read (Power grab: the hidden costs of Ireland’s datacentre boom, 15 February) highlights the enormous cost in terms of energy consumption and carbon emissions of our collective love affair with the seemingly free ability to send emails, text and WhatsApp messages every minute of the day. There is an enormous cost to us all in terms of data storage – a fact of which we are barely cognisant.Think how much money could be raised to counter the impact on our environment if we all paid just one penny for each digital message we blithely send. And tuppence if there is an attachment, and thruppence if it includes a digital photo of the meal you ate at a restaurant last night. Continue reading...

Industrial sector ransomware attacks increased by 50% in 2023

20 February 2024
Industrial cybersecurity was analyzed in a recent report by Dragos Inc, finding that ransomware attacks increased 50% over the last year.

New Migo Malware Targeting Redis Servers for Cryptocurrency Mining

20 February 2024
A novel malware campaign has been observed targeting Redis servers for initial access with the ultimate goal of mining cryptocurrency on compromised Linux hosts. "This particular campaign involves the use of a number of novel system weakening techniques against the data store itself," Cado security researcher Matt Muir said in a technical report. The cryptojacking attack is facilitated

Critical Flaws Found in ConnectWise ScreenConnect Software

20 February 2024
ConnectWise has released software updates to address two critical security flaws in its ScreenConnect remote desktop and access software. The vulnerabilities could allow remote code execution and unauthorized access to restricted directories.

Report: Malicious emails bypassing secure email gateways rose by 105%

20 February 2024
The report uncovers the latest information in email security and malicious email threats, emphasizing emerging techniques that security leaders must defend against. 

NCSC statement on law enforcement's disruption of LockBit ransomware operation

20 February 2024
The National Crime Agency (NCA) has announced that it is conducting a months-long campaign with international partners to disrupt the threat posed by the LockBit ransomware operation.

Over 28,500 Exchange Servers Vulnerable to Actively Exploited Bug

20 February 2024
The CVE-2024-21410 vulnerability allows remote unauthenticated actors to perform NTLM relay attacks, potentially leading to unauthorized access to confidential data and network exploitation.

Several Ukrainian Media Outlets Attacked by Russian Hackers

20 February 2024
Ukrainian authorities and cybersecurity agencies attributed the attack to Russian threat actors and described it as part of Russia's "information warfare" against Ukraine.

North Korean Hackers Linked to Defense Sector Supply-Chain Attack

20 February 2024
The German federal intelligence agency and South Korea's National Intelligence Service have issued a joint advisory warning about ongoing cyber-espionage operations targeting the global defense sector on behalf of North Korea.

Wyze Camera Breach Let 13,000 Strangers Look into Other People’s Homes

20 February 2024
The breach resulted from a system overload caused by incorrect mapping of device IDs, which was attributed to a third-party caching client library recently integrated into Wyze's system.