Latest Cybersecurity News and Articles
09 February 2024
While ransomware groups targeted a wide range of industries for profit, the demise of several groups in 2023 was attributed to increased pressure from law enforcement and cybersecurity organizations.
09 February 2024
The threat actor maintained long-term access to the victim's network, evading detection by using living-off-the-land binaries, side-loading backdoors, and leveraging open-source reverse proxy tools like Fast Reverse Proxy (FRP) and Venom.
09 February 2024
The shareholders, led by the state of Rhode Island's retirement system, accused Google of concealing the extent of the data breach and failing to notify users about the API flaw.
09 February 2024
Hyundai Motor Europe suffered a Black Basta ransomware attack, resulting in the theft of three terabytes of corporate data, impacting various departments including legal, sales, human resources, accounting, IT, and management.
09 February 2024
Chinese state actors used a zero-day exploit in a Fortinet VPN to breach Dutch military systems—in early 2023—to deploy the Coathanger backdoor, revealed intelligence agencies. The malware conceals its activities by intercepting system functions that might expose it. Organizations are urged to enhance their cybersecurity measures by applying timely updates and patches.
09 February 2024
Banking fraud prevention heads from TSB Bank, Santander, and Revolut testified before a U.K. Parliament committee, highlighting the prevalence of scams on Meta-owned online marketplaces like Facebook Marketplace.
09 February 2024
The Service Employees International Union (SEIU) Local 1000 in California is dealing with network disruptions following a cyber incident, which was claimed by the LockBit ransomware gang last month.
09 February 2024
Google is collaborating with the Singapore government to roll out a new security feature in Google Play Protect to block the installation of potentially risky side-loaded apps, aiming to protect Android users from malware-enabled scams.
09 February 2024
Introduction
The modern software supply chain represents an ever-evolving threat landscape, with each package added to the manifest introducing new attack vectors. To meet industry requirements, organizations must maintain a fast-paced development process while staying up-to-date with the latest security patches. However, in practice, developers often face a large amount of security work without
09 February 2024
The Akira ransomware group poses a significant threat to the U.S. healthcare sector and has targeted organizations in multiple industries, using tactics such as spear-phishing and exploiting vulnerabilities in VPN software.
09 February 2024
Sixty-one banking institutions, all of them originating from Brazil, are the target of a new banking trojan called Coyote.
"This malware utilizes the Squirrel installer for distribution, leveraging Node.js and a relatively new multi-platform programming language called Nim as a loader to complete its infection," Russian cybersecurity firm Kaspersky said in a Thursday report.
What
09 February 2024
A new report by Nozomi Networks highlighted an increasing threat to operational technology (OT) and Internet of Things (IoT) environments, with 885 new vulnerabilities disclosed in the second half of 2023.
09 February 2024
The group's access to exploits for vulnerabilities, such as CVE-2023-36802 and CVE-2023-29360, suggests ties to sophisticated developers and the purchase of external 64-bit executables rather than in-house development.
09 February 2024
The acquisition reflects Security Compass's commitment to providing top-tier cybersecurity training solutions and complements its existing offerings, including Application Security Training, SD Elements, and Just-In-Time Training.
09 February 2024
The XLoader Android malware, operated by the threat actor known as Roaming Mantis, has been found to automatically execute on infected devices without requiring user interaction.
09 February 2024
The cyberattack on AnyDesk's servers in Spain and Portugal did not result in the compromise of user credentials, and the company has taken steps to mitigate the incident.
09 February 2024
The criminal organization "Wail Crinal 213" claims to have accessed the bank's server and is allegedly selling sensitive customer data, including emails, usernames, account details, and more.
09 February 2024
The software company Ivanti has discovered a new vulnerability, CVE-2024-22024, in its products that allows unauthorized access to restricted resources. Although there is no evidence of exploitation, users are urged to promptly patch their systems.
09 February 2024
Cloud computing has innovated how organizations operate and manage IT operations, such as data storage, application deployment, networking, and overall resource management. The cloud offers scalability, adaptability, and accessibility, enabling businesses to achieve sustainable growth. However, adopting cloud technologies into your infrastructure presents various cybersecurity risks and
09 February 2024
ResumeLooters conducted a major cyber operation, compromising over 65 job search and retail websites across the Asia Pacific region and pilfering more than 2 million user records. The discovery of a new campaign serves as a reminder to secure databases and websites—which can be exploited by publicly available tools.