Latest Cybersecurity News and Articles
14 February 2024
The Minnesota-based Internet provider U.S. Internet Corp. has a business unit called Securence, which specializes in providing filtered, secure email services to businesses, educational institutions and government agencies worldwide. But until it was notified last week, U.S. Internet was publishing more than a decade's worth of its internal email -- and that of thousands of Securence clients -- in plain text out on the Internet and just a click away for anyone with a Web browser.
14 February 2024
The company has reported the security breach to law enforcement and regulatory authorities and is conducting an ongoing investigation to assess the full impact of the incident.
14 February 2024
The Government Accountability Office (GAO) suffered a data breach affecting thousands of current and former employees, which was carried out through a vulnerability in the Atlassian Confluence workforce collaboration tool.
14 February 2024
Security researchers have lately observed new builds and incremental changes to the malware, indicating that someone with access to its source code is experimenting with it.
14 February 2024
Nation-state actors associated with Russia, North Korea, Iran, and China are experimenting with artificial intelligence (AI) and large language models (LLMs) to complement their ongoing cyber attack operations.
The findings come from a report published by Microsoft in collaboration with OpenAI, both of which said they disrupted efforts made by five state-affiliated actors that used its
14 February 2024
A recent report analyzes the trends regarding generative AI usage and how it may influence organizational security.
14 February 2024
Cybersecurity researchers have found that it's possible for threat actors to exploit a well-known utility called command-not-found to recommend their own rogue packages and compromise systems running Ubuntu operating system.
"While 'command-not-found' serves as a convenient tool for suggesting installations for uninstalled commands, it can be inadvertently manipulated by attackers through the
14 February 2024
One of the zero-days, CVE-2024-21412, allows attackers to bypass security features and deploy malware. The other zero-day, CVE-2024-21351, enables attackers to bypass SmartScreen protections and potentially gain remote code execution capabilities.
14 February 2024
A 20-plus-year-old design flaw in the DNSSEC specification, named KeyTrap, can be exploited by a single packet to disable vulnerable DNS servers, affecting web clients and other applications relying on them.
14 February 2024
The breach involved sensitive details such as full names, dates of birth, contact information, and Social Security Numbers. The threat actor demanded a ransom and threatened to sell the stolen data if their demands were not met.
14 February 2024
The Cyberdome initiative at Boise State University is helping to address the shortage of cybersecurity talent in rural areas by providing hands-on work experience to students and cybersecurity services to organizations in need.
14 February 2024
The landscape of cybersecurity in financial services is undergoing a rapid transformation. Cybercriminals are exploiting advanced technologies and methodologies, making traditional security measures obsolete. The challenges are compounded for community banks that must safeguard sensitive financial data against the same level of sophisticated threats as larger institutions, but often with more
14 February 2024
The infamous malware loader and initial access broker known as Bumblebee has resurfaced after a four-month absence as part of a new phishing campaign observed in February 2024.
Enterprise security firm Proofpoint said the activity targets organizations in the U.S. with voicemail-themed lures containing links to OneDrive URLs.
"The URLs led to a Word file with names such as "
14 February 2024
PlayDapp offered a $1 million reward to the hacker for returning the stolen contracts and assets, but the hackers continued to mint more tokens, leading to the suspension of PLA trading and efforts to freeze the hacker's wallets on exchanges.
14 February 2024
Cyber Fusion Centers (CFCs) enable threat intelligence operationalization, information sharing, and automation of threat response, providing a unified and efficient approach to cybersecurity in the financial sector.
14 February 2024
According to Resecurity, malicious cyber-activity has increased by 100% between 2023 and early 2024, with threat actors aiming to acquire and exploit voter data for potential propaganda campaigns and electoral interference.
14 February 2024
The breach occurred from February 3, 2023, through February 20, 2023, and involved email messages containing personally identifiable information (PII) associated with individuals supporting or seeking employment with the DOD.
14 February 2024
Iranian state-backed actors have consistently targeted the U.S. and Israel with cyberattacks, including destructive malware and influence campaigns, before and after the Israel-Hamas war.
14 February 2024
The vulnerabilities, CVE-2023-50358 and CVE-2023-47218, are command injection flaws in the QTS firmware, with potential for remote code execution, impacting a large number of devices globally.
14 February 2024
The company plans to notify 5-10% of its customer base, potentially affecting 230,000 to 460,000 people. The breach, attributed to the Black Basta ransomware group, led to the theft of data from a limited part of the company's server estate.