Latest Cybersecurity News and Articles


Ransomware Tactics Evolve, Become Scrappier

13 February 2024
Ransomware attacks surged in 2023, with the United States accounting for almost half of all attacks according to Malwarebytes, and cybercriminals evolving their tactics to target a higher volume of victims simultaneously.

FCC Orders Telecom Carriers to Report PII Data Breaches Within 30 Days

13 February 2024
Major U.S. telecom carriers such as Verizon, T-Mobile, and AT&T have experienced significant data breaches in recent years, highlighting the crucial need for aligning FCC's data breach rules with federal and state laws applicable to other sectors.

Protecting Against AI-Enhanced Email Threats

13 February 2024
Combining traditional email security measures with AI-based solutions and empowering cybersecurity personnel with AI skills is crucial for organizations to defend against evolving cyber threats.

China Targets US Hacking Ops in Media Offensive

13 February 2024
The campaign involves collaboration between Chinese cybersecurity firms, government agencies, and state media to amplify allegations of hacking operations by the United States.

Bugcrowd Attains $102M Strategic Growth Funding Round

13 February 2024
Bugcrowd, which has already attracted $90 million in prior investments, plans to use the funds to enhance its bug bounty programs, vulnerability disclosure, and crowdsourced penetration testing.

CISA Warns of Roundcube Email Server Bug Now Exploited in Attacks

13 February 2024
The Roundcube email server vulnerability (CVE-2023-43770) is actively exploited in cross-site scripting (XSS) attacks, posing a significant risk to both federal agencies and private organizations worldwide.

Ivanti Vulnerability Exploited to Install 'DSLog' Backdoor on 670+ IT Infrastructures

13 February 2024
Threat actors are leveraging a recently disclosed security flaw impacting Ivanti Connect Secure, Policy Secure, and ZTA gateways to deploy a backdoor codenamed DSLog on susceptible devices. That's according to findings from Orange Cyberdefense, which said it observed the exploitation of CVE-2024-21893 within hours of the public release of the proof-the-concept (PoC) code.

Ex-Post Office boss ‘gave Fujitsu bonus contract despite warnings’

13 February 2024
Ex-Post Office boss ‘gave Fujitsu bonus contract despite warnings’ Exclusive: Whistleblowers say Paula Vennells agreed to move archive, which risked destroying data that could clear operatorsThe former Post Office boss Paula Vennells gave Fujitsu a bonus contract in 2013 to take over an archive of branch data, despite warnings such a move would destroy evidence that might clear operators, whistleblowers have said.Transaction information was “replatformed” on cost grounds from a “gold standard” external storage system known as Centera to one owned by the Japanese software company running the Post Office’s Horizon IT network. Continue reading...

Alert: CISA Warns of Active 'Roundcube' Email Attacks - Patch Now

12 February 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a medium-severity security flaw impacting Roundcube email software to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The issue, tracked as CVE-2023-43770 (CVSS score: 6.1), relates to a cross-site scripting (XSS) flaw that stems from the handling of

Man arrested in Malta in global operation to shut down cybercrime network targeting Australians

12 February 2024
Man arrested in Malta in global operation to shut down cybercrime network targeting Australians Federal police warn they will track down alleged criminals using Warzone trojan softwareFollow our Australia news live blog for latest updatesGet our morning and afternoon news emails, free app or daily news podcastA man has been arrested as part of an international operation to shut down a global cybercrime network targeting Australians as Australian federal police warn they will track down other people alleged to be involved in the use of the malicious software.Daniel Meli, 27, was arrested in Malta on 7 February for allegedly selling and training criminals in the use of Warzone, a remote access trojan software that bypasses security systems and remotely accesses computers without the victims’ knowledge.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...

10M reward offered for information on Hive ransomware members

12 February 2024
The United States Department of State is offering monetary rewards for those who can aid in the location and apprehension of Hive ransomware members. 

Ongoing Azure Compromises Target Senior Executives, Microsoft 365 Apps

12 February 2024
Threat actors are targeting Microsoft Azure corporate clouds with sophisticated and tailored phishing attacks, compromising a wide range of user accounts for activities such as data exfiltration and financial fraud.

Decryptor for Rhysida Ransomware is Available

12 February 2024
Files encrypted by Rhysida ransomware can be successfully decrypted, due to a implementation vulnerability discovered by Korean researchers and leveraged to create a decryptor.

Cohesity, Veritas Combine as New Data Protection Company

12 February 2024
The deal will result in the formation of a separate company called DataCo to handle Veritas' remaining assets, while Cohesity will follow a "no customer left behind" approach.

CISA Partners with OpenSSF to Release Principles for Package Repository Security Framework

12 February 2024
This initiative aligns with CISA's Open Source Software Security Roadmap's objective of collaborating with relevant working groups to develop security principles for package managers.

Ransomware Attack Forces 18 Romanian Hospitals to Go Offline

12 February 2024
The Hipocrate Information System (HIS) used by hospitals to manage medical activity and patient data was targeted over the weekend and is now offline after its database was encrypted.

UN Experts Investigating 58 Suspected North Korean Cyberattacks Valued at About $3 Billion

12 February 2024
The United Nations is investigating 58 suspected cyberattacks by North Korea, totaling around $3 billion, which are believed to be funding the country's development of weapons of mass destruction.

Consumers lost over $10 billion to fraud in 2023

12 February 2024
The Federal Trade Commission (FTC) released data revealing that consumers lost over $10 billion to fraud in 2023, at 14% increase from 2022.

National Cyber Director Urges Private Sector Collaboration to Counter Nation-State Cyber Threat

12 February 2024
National Cyber Director Harry Coker emphasized the need for a collaborative effort between the government and industry to address cyber threats, harmonize regulations, and build a diverse cybersecurity workforce.

Rhysida Ransomware Cracked, Free Decryption Tool Released

12 February 2024
Cybersecurity researchers have uncovered an "implementation vulnerability" that has made it possible to reconstruct encryption keys and decrypt data locked by Rhysida ransomware. The findings were published last week by a group of researchers from Kookmin University and the Korea Internet and Security Agency (KISA). "Through a comprehensive analysis of Rhysida Ransomware, we identified an