Latest Cybersecurity News and Articles


UN Experts Investigating 58 Suspected North Korean Cyberattacks Valued at About $3 Billion

12 February 2024
The United Nations is investigating 58 suspected cyberattacks by North Korea, totaling around $3 billion, which are believed to be funding the country's development of weapons of mass destruction.

Consumers lost over $10 billion to fraud in 2023

12 February 2024
The Federal Trade Commission (FTC) released data revealing that consumers lost over $10 billion to fraud in 2023, at 14% increase from 2022.

National Cyber Director Urges Private Sector Collaboration to Counter Nation-State Cyber Threat

12 February 2024
National Cyber Director Harry Coker emphasized the need for a collaborative effort between the government and industry to address cyber threats, harmonize regulations, and build a diverse cybersecurity workforce.

Rhysida Ransomware Cracked, Free Decryption Tool Released

12 February 2024
Cybersecurity researchers have uncovered an "implementation vulnerability" that has made it possible to reconstruct encryption keys and decrypt data locked by Rhysida ransomware. The findings were published last week by a group of researchers from Kookmin University and the Korea Internet and Security Agency (KISA). "Through a comprehensive analysis of Rhysida Ransomware, we identified an

Report: AI cybersecurity market projected to exceed $133 billion

12 February 2024
According to a recent report, the global AI cybersecurity market is expected to pass $133 billion from 2023 to 2030. 

Hackers Leak Alleged Partial Facebook Marketplace Database

12 February 2024
The partial Facebook Marketplace database was allegedly leaked by a threat actor, exposing sensitive personal information of approximately 200,000 users, including full names, Facebook IDs, phone numbers, physical IDs, and email addresses.

QR Code 'Quishing' Attacks on Executives Surge, Evading Email Security

12 February 2024
Email attacks using QR codes, known as "quishing," have surged, especially targeting corporate executives and managers, highlighting the need for enhanced digital protections for business leadership.

CISA and other US agencies release advisory on PRC threat actor

12 February 2024
CISA published a cybersecurity advisory alongside other agencies due to malicious activity by a PRC state-sponsored cyber actor known as Volt Typhoon.

CISA Blitzes Super Bowl With Cyber Campaign as Businesses Fumble Security

12 February 2024
The Cybersecurity and Infrastructure Security Agency (CISA) partnered with the NFL to promote cybersecurity awareness during the Super Bowl, aiming to encourage strong passwords, multifactor authentication, and phishing reporting.

New Fortinet RCE Bug is Actively Exploited, CISA Confirms

12 February 2024
CISA confirmed active exploitation of a critical remote code execution (RCE) bug in Fortinet's FortiOS, urging immediate security updates or SSL VPN disabling to mitigate the risk.

4 Ways Hackers use Social Engineering to Bypass MFA

12 February 2024
When it comes to access security, one recommendation stands out above the rest: multi-factor authentication (MFA). With passwords alone being simple work for hackers, MFA provides an essential layer of protection against breaches. However, it's important to remember that MFA isn't foolproof. It can be bypassed, and it often is.  If a password is compromised, there are several options

How AI is Revolutionizing Identity Fraud

12 February 2024
Businesses and consumers are facing heightened levels of identity-focused attacks, with over 30% of businesses reporting growth in data and security breaches, impacting industries beyond the financial sector, according to AuthenticID.

CISA and OpenSSF Release Framework for Package Repository Security

12 February 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced that it's partnering with the Open Source Security Foundation (OpenSSF) Securing Software Repositories Working Group to publish a new framework to secure package repositories. Called the Principles for Package Repository Security, the framework aims to establish a set of foundational rules for package

Americans Lost Record $10 Billion to Fraud in 2023, FTC Warns

12 February 2024
In 2023, the U.S. FTC reported that Americans lost over $10 billion to scammers, a 14% increase from the previous year. Imposter scams were the most frequently reported, followed by online shopping scams and investment scams.

Cybersecurity Teams Recognized as Key Enablers of Business Goals

12 February 2024
As per a new study by CybSafe, 97% of office workers in the United Kingdom and United States trust their cybersecurity teams to prevent or minimize damage from cyberattacks.

US offers $10M reward for info on Hive ransomware group leaders

12 February 2024
The US government is offering rewards of up to $10 million for information leading to the identification, location, arrest, and conviction of members of the Hive ransomware group.

Exploiting a Vulnerable Minifilter Driver to Create a Process Killer

12 February 2024
The technique involves using a vulnerable signed Minifilter Driver to create a program capable of terminating a targeted process, particularly to evade detection by security solutions like EDR.

Why Are Compromised Identities the Nightmare to IR Speed and Efficiency?

12 February 2024
Incident response (IR) is a race against time. You engage your internal or external team because there's enough evidence that something bad is happening, but you’re still blind to the scope, the impact, and the root cause. The common set of IR tools and practices provides IR teams with the ability to discover malicious files and outbound network connections. However, the identity aspect - namely

Ransomware Actors Hit Zero-Day Exploits Hard in 2023

12 February 2024
According to a report by Chainalysis, ransomware attacks caused a record-breaking $1.1 billion in financial damage in 2023, with a 49% increase in victim organizations being publicly threatened.

AI-Generated Voices in Robocalls Now Illegal

12 February 2024
A new FCC Declaratory Ruling recognizes AI-generated voices in robocalls as "artificial" and illegal, giving State Attorneys General new tools to crack down on these scams and protect the public.