Latest Cybersecurity News and Articles


US Disrupts Russian Military Intelligence Botnet

16 February 2024
U.S. law enforcement disrupted a criminal botnet, "Moobot," which Russian military hackers had repurposed for global cyberespionage, leading to the FBI obtaining a warrant to modify infected routers and shut down the botnet.

U.S. State Government Network Breached via Former Employee's Account

16 February 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed state government organization's network environment was compromised via an administrator account belonging to a former employee. "This allowed the threat actor to successfully authenticate to an internal virtual private network (VPN) access point," the agency said in a joint advisory published

Newly Emerged JKwerlo Ransomware Targets Victims in France and Spain

16 February 2024
JKwerlo's utilization of lateral movement techniques and exploitation of legitimate services like Dropbox and GitHub highlight its capability to spread across networks and evade traditional security measures.

Cyware and GreyNoise's Webinar Shows How Threat Intelligence Enables Efficient Detection and Prioritization to Save Time

16 February 2024
This joint webinar by Cyware and GreyNoise aims to demonstrate how organizations can save time and money in cybersecurity by understanding the nature of threats in their security environments by effectively utilizing threat intelligence.

U.S. Government Disrupts Russian-Linked Botnet Engaged in Cyber Espionage

16 February 2024
The U.S. government on Thursday said it disrupted a botnet comprising hundreds of small office and home office (SOHO) routers in the country that was put to use by the Russia-linked APT28 actor to conceal its malicious activities. "These crimes included vast spear-phishing and similar credential harvesting campaigns against targets of intelligence interest to the Russian government, such as U.S.

Research shows that 15% of emails were malicious in 2023

15 February 2024
The malicious email trends seen in 2023 are expected to influence the threats security leaders will see in 2024. 

U.S. Internet Corp. Leaked Years of Internal, Customer Emails

15 February 2024
U.S. Internet Corp.'s subsidiary, Securence, inadvertently exposed over a decade's worth of internal and client emails, including those of government institutions, due to a misconfigured server, raising serious security concerns.

North Korean Hackers Target South Korean President's Office

15 February 2024
South Korea has accused North Korean hackers of breaching an administrator's email account in the Office of the President to access information about the president's communications and overseas trips.

Us Military Notifies 20,000 of Data Breach After Cloud Email Leak

15 February 2024
The U.S. Department of Defense has notified around 20,600 individuals that their personal information was exposed in an email data spill due to a misconfigured cloud email server hosted on Microsoft's platform.

Encryption Vital For Right to Privacy, European Court Rules

15 February 2024
The European Court of Human Rights ruled in favor of a Russian petitioner who challenged a Kremlin rule requiring telecom firms to provide backdoor access to servers for law enforcement data collection.

North Korea Turns to Designing Malware-Infected Gambling Websites for Cash

15 February 2024
The operation is carried out by an IT organization called "Gyeongheung," affiliated with North Korea's secretive Office 39. These websites are sold for $5,000 a month, with additional tech support for $3,000.

Russian Turla Hackers Target Polish NGOs with New TinyTurla-NG Backdoor

15 February 2024
The Russia-linked threat actor known as Turla has been observed using a new backdoor called TinyTurla-NG as part of a three-month-long campaign targeting Polish non-governmental organizations in December 2023. "TinyTurla-NG, just like TinyTurla, is a small 'last chance' backdoor that is left behind to be used when all other unauthorized access/backdoor mechanisms have failed or been

New Jersey Law Enforcement Officers Sue 118 Data Brokers for Not Removing Personal Information

15 February 2024
The lawsuits filed against data brokers in New Jersey highlight the need for stronger regulation of data brokers to protect the privacy of law enforcement personnel and all Americans.

Corporate Users Getting Tricked into Downloading AnyDesk

15 February 2024
Hackers are tricking victims into downloading an outdated but legitimate AnyDesk executable by directing them to fake websites posing as financial institutions. Once the program is run, attackers can gain control of the victim's machine.

Hackers got nearly 7 million people’s data from 23andMe. The firm blamed users in ‘very dumb’ move

15 February 2024
Hackers got nearly 7 million people’s data from 23andMe. The firm blamed users in ‘very dumb’ move The company pointed at people who ‘failed to update their passwords’ as sensitive data was offered for sale on forumsThree years ago, a man in Florida named JL decided, on a whim, to send a tube of his spit to the genetic testing site 23andMe in exchange for an ancestry report. JL, like millions of other 23andMe participants before him, says he was often asked about his ethnicity and craved a deeper insight into his identity. He said he was surprised by the diversity of his test results, which showed he had some Ashkenazi Jewish heritage.JL said he didn’t think much about the results until he learned of a huge breach at the company that exposed the data of nearly 7 million people, about half of the company’s customers. Worse, he later learned of a hacker going by the pseudonym “Golem” who had offered to sell the names, addresses and genetic heritage reportedly belonging to 1 million 23andMe customers with similar Ashkenazi Jewish heritage on a shadowy dark web forum. Suddenly, JL worried his own flippant decision to catalog his genes could put him and his family at risk. Continue reading...

Ivanti Pulse Secure Found Using 11-Year-Old Linux Version and Outdated Libraries

15 February 2024
A reverse engineering of the firmware running on Ivanti Pulse Secure appliances has revealed numerous weaknesses, once again underscoring the challenge of securing software supply chains. Eclypsiusm, which acquired firmware version 9.1.18.2-24467.1 as part of the process, said the base operating system used by the Utah-based software company for the device is CentOS 6.4. "Pulse Secure runs an

CISA Reveals JCDC’s 2024 Cybersecurity Priorities

15 February 2024
The priorities focus on defending against Advanced Persistent Threat (APT) operations, raising cybersecurity standards for critical infrastructure, and anticipating emerging technology risks.

German Battery Maker Varta Halts Production After Cyberattack

15 February 2024
The company has not yet determined the extent of the damage caused by the attack. VARTA is currently focused on ensuring data integrity and has formed a task force to aid in system restoration.

Report: Threat Actors Intensify Focus on NATO Member States

15 February 2024
A report from Flare indicates that Initial Access Brokers (IABs) are increasingly targeting entities within NATO member states through various techniques such as spear-phishing and exploiting vulnerabilities.

GoldPickaxe Trojan Uses Biometric Data and Deepfake Tech to Scam Banks

15 February 2024
The trojan captures facial biometric data to create deepfake videos for bypassing banking logins, demonstrating a high level of sophistication and operational maturity by the cybercriminal group GoldFactory.