Latest Cybersecurity News and Articles


U.S. Internet Leaked Years of Internal, Customer Emails

14 February 2024
The Minnesota-based Internet provider U.S. Internet Corp. has a business unit called Securence, which specializes in providing filtered, secure email services to businesses, educational institutions and government agencies worldwide. But until it was notified last week, U.S. Internet was publishing more than a decade's worth of its internal email -- and that of thousands of Securence clients -- in plain text out on the Internet and just a click away for anyone with a Web browser.

Prudential Financial Breached in Data Theft Cyberattack

14 February 2024
The company has reported the security breach to law enforcement and regulatory authorities and is conducting an ongoing investigation to assess the full impact of the incident.

Atlassian Vulnerability at Fault in GAO Breach

14 February 2024
The Government Accountability Office (GAO) suffered a data breach affecting thousands of current and former employees, which was carried out through a vulnerability in the Atlassian Confluence workforce collaboration tool.

More Signs of a Qakbot Resurgence

14 February 2024
Security researchers have lately observed new builds and incremental changes to the malware, indicating that someone with access to its source code is experimenting with it.

Microsoft, OpenAI Warn of Nation-State Hackers Weaponizing AI for Cyberattacks

14 February 2024
Nation-state actors associated with Russia, North Korea, Iran, and China are experimenting with artificial intelligence (AI) and large language models (LLMs) to complement their ongoing cyber attack operations. The findings come from a report published by Microsoft in collaboration with OpenAI, both of which said they disrupted efforts made by five state-affiliated actors that used its

55% of generative AI inputs comprised personally identifiable data

14 February 2024
A recent report analyzes the trends regarding generative AI usage and how it may influence organizational security. 

Ubuntu 'command-not-found' Tool Could Trick Users into Installing Rogue Packages

14 February 2024
Cybersecurity researchers have found that it's possible for threat actors to exploit a well-known utility called command-not-found to recommend their own rogue packages and compromise systems running Ubuntu operating system. "While 'command-not-found' serves as a convenient tool for suggesting installations for uninstalled commands, it can be inadvertently manipulated by attackers through the

Attackers Exploit Microsoft Security-Bypass Zero-Day Bugs

14 February 2024
One of the zero-days, CVE-2024-21412, allows attackers to bypass security features and deploy malware. The other zero-day, CVE-2024-21351, enables attackers to bypass SmartScreen protections and potentially gain remote code execution capabilities.

20-Year-Old DNSSEC Vulnerability Puts Big Chunk of the Internet at Risk

14 February 2024
A 20-plus-year-old design flaw in the DNSSEC specification, named KeyTrap, can be exploited by a single packet to disable vulnerable DNS servers, affecting web clients and other applications relying on them.

Integris Health Says Data Breach Impacts 2.4 Million Patients

14 February 2024
The breach involved sensitive details such as full names, dates of birth, contact information, and Social Security Numbers. The threat actor demanded a ransom and threatened to sell the stolen data if their demands were not met.

Boise State Pilot Program Aims to Boost Cybersecurity by Pairing Students With Local Institutions

14 February 2024
The Cyberdome initiative at Boise State University is helping to address the shortage of cybersecurity talent in rural areas by providing hands-on work experience to students and cybersecurity services to organizations in need.

Cybersecurity Tactics FinServ Institutions Can Bank On in 2024

14 February 2024
The landscape of cybersecurity in financial services is undergoing a rapid transformation. Cybercriminals are exploiting advanced technologies and methodologies, making traditional security measures obsolete. The challenges are compounded for community banks that must safeguard sensitive financial data against the same level of sophisticated threats as larger institutions, but often with more

Bumblebee Malware Returns with New Tricks, Targeting U.S. Businesses

14 February 2024
The infamous malware loader and initial access broker known as Bumblebee has resurfaced after a four-month absence as part of a new phishing campaign observed in February 2024. Enterprise security firm Proofpoint said the activity targets organizations in the U.S. with voicemail-themed lures containing links to OneDrive URLs. "The URLs led to a Word file with names such as "

Hackers Steal $290 Million in Crypto From PlayDapp Gaming Platform

14 February 2024
PlayDapp offered a $1 million reward to the hacker for returning the stolen contracts and assets, but the hackers continued to mint more tokens, leading to the suspension of PLA trading and efforts to freeze the hacker's wallets on exchanges.

Financial Institutions Embrace Cyber Fusion Centers for Unified Approach to Evolving Risks

14 February 2024
Cyber Fusion Centers (CFCs) enable threat intelligence operationalization, information sharing, and automation of threat response, providing a unified and efficient approach to cybersecurity in the financial sector.

Global Malicious Activity Targeting Elections is Skyrocketing

14 February 2024
According to Resecurity, malicious cyber-activity has increased by 100% between 2023 and early 2024, with threat actors aiming to acquire and exploit voter data for potential propaganda campaigns and electoral interference.

DOD Notifying People Who May be Impacted by a Year-Old Data Breach

14 February 2024
The breach occurred from February 3, 2023, through February 20, 2023, and involved email messages containing personally identifiable information (PII) associated with individuals supporting or seeking employment with the DOD.

Iranian Cyberattacks Targeting U.S. and Israeli Entities

14 February 2024
Iranian state-backed actors have consistently targeted the U.S. and Israel with cyberattacks, including destructive malware and influence campaigns, before and after the Israel-Hamas war.

Urgent Patches Available for QNAP Vulnerabilities, One Zero-Day

14 February 2024
The vulnerabilities, CVE-2023-50358 and CVE-2023-47218, are command injection flaws in the QTS firmware, with potential for remote code execution, impacting a large number of devices globally.

Update: Southern Water Notifies Customers and Employees of Data Breach

14 February 2024
The company plans to notify 5-10% of its customer base, potentially affecting 230,000 to 460,000 people. The breach, attributed to the Black Basta ransomware group, led to the theft of data from a limited part of the company's server estate.