Latest Cybersecurity News and Articles


Critical Bootloader Vulnerability in Shim Impacts Nearly All Linux Distros

07 February 2024
The maintainers of shim have released version 15.8 to address six security flaws, including a critical bug that could pave the way for remote code execution under specific circumstances. Tracked as CVE-2023-40547 (CVSS score: 9.8), the vulnerability could be exploited to achieve a Secure Boot bypass. Bill Demirkapi of the Microsoft Security Response Center (MSRC) has been&

John Godfrey announced as Kansas Chief Information Security Officer

07 February 2024
Governor Laura Kelly recently announced that John Godfrey is the new Chief Information Security Officer (CISO) for the State of Kansas. 

Paying Ransoms is Becoming a Cost of Doing Business for Many

07 February 2024
Companies are bracing for a significant increase in cyber threats in 2024, with 96% of respondents expecting the threat of cyberattacks to their industry to rise, and 71% predicting an increase of more than 50%, according to Cohesity.

Hackers can Use Generative AI to Manipulate Live Conversations

07 February 2024
IBM researchers demonstrated a technique to intercept live conversations and replace keywords based on the context, allowing for the manipulation of information, financial fraud, and even real-time changes to news broadcasts and political speeches.

Linux Foundation Announces Post-Quantum Cryptography Alliance

07 February 2024
The Post-Quantum Cryptography Alliance aims to drive the adoption of post-quantum cryptography to address security risks posed by quantum computing, with support from industry leaders like Google, IBM, Amazon Web Services, and Cisco.

Business, Technology Groups Back SolarWinds Motion to Dismiss SEC Charges

07 February 2024
The U.S. Chamber of Commerce and the Business Roundtable argue that the SEC has expanded its interpretation of internal accounting controls provisions beyond Congress's original intent.

Spoutible API Exposed Encrypted Password Reset Tokens, 2FA Secrets of Users

07 February 2024
The social media platform Spoutible had a publicly exposed API that allowed hackers to scrape sensitive user information, including hashed passwords, authentication seeds, and password reset tokens.

ZeroFox to go private in $350M acquisition by Haveli Investments

07 February 2024
The acquisition, which has been approved by ZeroFox's Board of Directors, is expected to close in the first half of 2024. After the acquisition, ZeroFox will transition from a public entity to a privately held company.

Data Breach at French Healthcare Services Firm Viamedis Puts Millions at Risk

07 February 2024
Viamedis, a French healthcare services firm, suffered a cyberattack exposing the sensitive data of policyholders and healthcare professionals, leading to disruptions in healthcare services.

Attack Surface Management Platform Ionix Adds Another $15M to its $27M Series A Round

07 February 2024
Ionix (formerly Cyberpion) secured an additional $15 million in funding, bringing its total funding to $50.3 million. The company offers a platform to help enterprises manage their security posture and software supply chain across various platforms.

New Webinar: 5 Steps to vCISO Success for MSPs and MSSPs

07 February 2024
2024 will be the year of the vCISO. An incredible 45% of MSPs and MSSPs are planning to start offering vCISO services in 2024. As an MSP/MSSP providing vCISO services, you own the organization’s cybersecurity infrastructure and strategy. But you also need to position yourself as a reliable decision-maker, navigating professional responsibilities, business needs and leadership

UK and France Assemble Diplomats for International Agreement on Spyware

07 February 2024
The United Kingdom and France are co-hosting a diplomatic conference in London to address the proliferation of commercial cyber intrusion tools. The conference will include 35 nations, big tech leaders, legal experts, and human rights defenders.

Businesses Banning or Limiting Use of GenAI Over Privacy Risks

07 February 2024
Both consumers and businesses prioritize transparency in data usage, with businesses recognizing the importance of external privacy certifications in building consumer trust and loyalty.

Google Links Dozens of Zero-Day Vulnerabilities in Discovered Recent Years to Spyware Vendors

07 February 2024
Google has identified at least 40 companies involved in creating and selling spyware and hacking tools to governments for use against high-risk individuals such as journalists and human rights defenders.

Global Coalition and Tech Giants Unite Against Commercial Spyware Abuse

07 February 2024
A coalition of dozens of countries, including France, the U.K., and the U.S., along with tech companies such as Google, MDSec, Meta, and Microsoft, have signed a joint agreement to curb the abuse of commercial spyware to commit human rights abuses. The initiative, dubbed the Pall Mall Process, aims to tackle the proliferation and irresponsible use of commercial cyber intrusion tools by

Mortgage Industry Attack Spree Punctuates Common Errors

07 February 2024
Financial services organizations, including mortgage industry firms, are vulnerable to cyberattacks due to the critical functions they perform, the funding they handle, and the sensitive information they manage.

JetBrains Warns of New TeamCity Authentication Bypass Vulnerability

07 February 2024
The vulnerability, tracked as CVE-2024-23917, affects all versions of TeamCity On-Premises from 2017.1 through 2023.11.2 and can lead to remote code execution attacks without requiring user interaction.

Malicious Excel File Drops Python Info-stealer

07 February 2024
Fortinet's FortiGuard Labs uncovers a Python-based info-stealer distributed via malicious Excel documents, showcasing cybercriminals' innovative tactics. Exploiting legacy Excel 4.0 macros, the attack scans devices for sensitive data, employing sophisticated evasion techniques for stealthy data exfiltration. For safety, users are advised to disable macros in Office documents.

Chinese Hackers Exploited FortiGate Flaw to Breach Dutch Military Network

07 February 2024
Chinese state-backed hackers broke into a computer network that's used by the Dutch armed forces by targeting Fortinet FortiGate devices. "This [computer network] was used for unclassified research and development (R&D)," the Dutch Military Intelligence and Security Service (MIVD) said in a statement. "Because this system was self-contained, it did not lead to any damage to the

Critical JetBrains TeamCity On-Premises Flaw Exposes Servers to Takeover - Patch Now

07 February 2024
JetBrains is alerting customers of a critical security flaw in its TeamCity On-Premises continuous integration and continuous deployment (CI/CD) software that could be exploited by threat actors to take over susceptible instances. The vulnerability, tracked as CVE-2024-23917, carries a CVSS rating of 9.8 out of 10, indicative of its severity. "The vulnerability may enable an unauthenticated