Latest Cybersecurity News and Articles


Report: Crypto-Money Laundering Records 30% Annual Decline

16 February 2024
In 2023, around $22bn of cryptocurrency was laundered, marking a 30% decrease from 2022, according to Chainalysis. Nefarious actors adapted their techniques to avoid detection, with a shift towards using new mixers and cross-chain bridges.

RustDoor macOS Backdoor Targets Cryptocurrency Firms with Fake Job Offers

16 February 2024
Several companies operating in the cryptocurrency sector are the target of a newly discovered Apple macOS backdoor codenamed RustDoor. RustDoor was first documented by Bitdefender last week, describing it as a Rust-based malware capable of harvesting and uploading files, as well as gathering information about the infected machines. It's distributed by masquerading itself as a Visual

U.S. State Government Network Breached via Former Employee's Account

16 February 2024
The breach occurred when a former employee's administrator account was used to access the network environment. The threat actor gained access to sensitive information and posted it on the dark web.

US State Department Puts $10M Bounty on ALPHV Ransomware Group

16 February 2024
The US State Department has announced a reward of up to $10 million for information on the leaders of the AlphV ransomware group, with an additional $5 million for details leading to the arrest of those involved in attacks.

RansomHouse Gang Automates VMware ESXi Attacks with New MrAgent Tool

16 February 2024
The MrAgent tool is designed to disable firewalls, automate ransomware deployment, and execute local commands on hypervisors, maximizing the impact of the attack while minimizing the chances of detection and intervention.

FTC Says It Will Go After Companies That ‘Quietly’ Change Privacy Policies to Mine User Data for AI

16 February 2024
The Federal Trade Commission (FTC) will strictly enforce data privacy laws and pursue companies that surreptitiously change their terms of service to exploit consumer data for AI development.

Unpacking North Korea's Gambling Web Service

16 February 2024
South Korea's National Intelligence Service reported that North Korea's Office 39 is selling pre-infected gambling websites to South Korean cybercrime groups. The scheme, believed to have generated billions, offers websites at $5,000/month with optional tech support for $3,000/month. The sites steal the personal data of South Korean citizens. 

Turla APT Spies on Polish NGOs Using TinyTurla Next Generation Backdoor

16 February 2024
The TinyTurla-NG backdoor uses compromised WordPress websites as command and control endpoints and deploys PowerShell scripts to exfiltrate key material used to secure password databases, indicating a concerted effort to steal login credentials.

Middle East & Africa CISOs Plan to Increase 2024 Budgets by 10%

16 February 2024
Cybersecurity spending in the Middle East, Turkey, and Africa is projected to exceed $6.5 billion in 2024 according to IDC, driven by increased cybercrime, regulatory enforcement, and government initiatives for improved cybersecurity.

Unprotected Cloud Database Exposed Over 384 Million Records Including Sensitive Logs and Customer Data

16 February 2024
A massive database leak from Zenlayer, a global network service provider, exposed 384,658,212 records, including sensitive customer data and internal operations logs, without basic password protection.

Bumblebee Resurfaces in a New Campaign

16 February 2024
Bumblebee returned after a four-month hiatus, employing social engineering tactics, sending emails with OneDrive URLs posing as voicemail notifications. The campaign stands out due to its utilization of VBA macro-enabled documents as most threat actors have nearly stopped using them after Microsoft began blocking macros by default. Protect your system by taking the right measures.

Why We Must Democratize Cybersecurity

16 February 2024
With breaches making the headlines on an almost weekly basis, the cybersecurity challenges we face are becoming visible not only to large enterprises, who have built security capabilities over the years, but also to small to medium businesses and the broader public. While this is creating greater awareness among smaller businesses of the need to improve their security posture, SMBs are often

Malicious 'SNS Sender' Script Abuses AWS for Bulk Smishing Attacks

16 February 2024
A malicious Python script known as SNS Sender is being advertised as a way for threat actors to send bulk smishing messages by abusing Amazon Web Services (AWS) Simple Notification Service (SNS). The SMS phishing messages are designed to propagate malicious links that are designed to capture victims' personally identifiable information (PII) and payment card details, SentinelOne 

We Can’t Risk Losing Staff to Alert Fatigue

16 February 2024
When important cybersecurity information is buried in inconsequential noise, the results can be dire. Cybersecurity teams need to prioritize their resources and focus on the areas where they are at the most risk.

AWS SNS Hijackings Fuel Cloud Smishing Campaign

16 February 2024
Threat actors are using AWS SNS and a custom bulk-messaging script called SNS Sender to carry out a smishing campaign impersonating the US Postal Service, posing significant risks to businesses' cloud instances.

Critical Software Vulnerabilities Impacting Credit Unions Discovered

16 February 2024
Organizations using versions prior to v7.75 of the web application are urged to upgrade, and all organizations using this CMS should enable multi-factor authentication immediately to prevent potential breaches.

White House’s Neuberger: Pace of Ransomware Takedown Operations Isn’t Enough

16 February 2024
The White House deputy national security advisor for cyber and emerging technologies, Anne Neuberger, spoke at the Munich Cyber Security Conference about the global efforts to combat ransomware attacks.

“TicTacToe Dropper” Malware Distribution Tactics Revealed

16 February 2024
The dropper is typically distributed through phishing emails containing .iso file attachments, aiming to evade antivirus detection, and utilize intricate obfuscation techniques to cloak the malicious intent of the payloads.

The Hidden Dangers Within Ubuntu's Package Suggestion System

16 February 2024
The interaction between Ubuntu’s command-not-found package and the snap package repository poses a significant security risk, potentially leading to the recommendation of malicious packages to users.

US Disrupts Russian Military Intelligence Botnet

16 February 2024
U.S. law enforcement disrupted a criminal botnet, "Moobot," which Russian military hackers had repurposed for global cyberespionage, leading to the FBI obtaining a warrant to modify infected routers and shut down the botnet.