Latest Cybersecurity News and Articles
07 February 2024
Fortinet's FortiGuard Labs uncovers a Python-based info-stealer distributed via malicious Excel documents, showcasing cybercriminals' innovative tactics. Exploiting legacy Excel 4.0 macros, the attack scans devices for sensitive data, employing sophisticated evasion techniques for stealthy data exfiltration. For safety, users are advised to disable macros in Office documents.
07 February 2024
Chinese state-backed hackers broke into a computer network that's used by the Dutch armed forces by targeting Fortinet FortiGate devices.
"This [computer network] was used for unclassified research and development (R&D)," the Dutch Military Intelligence and Security Service (MIVD) said in a statement. "Because this system was self-contained, it did not lead to any damage to the
07 February 2024
JetBrains is alerting customers of a critical security flaw in its TeamCity On-Premises continuous integration and continuous deployment (CI/CD) software that could be exploited by threat actors to take over susceptible instances.
The vulnerability, tracked as CVE-2024-23917, carries a CVSS rating of 9.8 out of 10, indicative of its severity.
"The vulnerability may enable an unauthenticated
06 February 2024
What's next, malware-infected dental floss? But seriously: It's a reminder that even the smallest smart home devices can be a threat. Here's how to protect yourself.
06 February 2024
Verizon Communications has reported an insider data breach affecting nearly half of its workforce, exposing sensitive employee information such as names, addresses, Social Security numbers, and compensation details.
06 February 2024
Chinese state-sponsored hackers breached the internal computer network of the Dutch Ministry of Defence using a vulnerability in FortiGate devices. The breach was for espionage purposes and the malware was found in a compartmentalized network.
06 February 2024
The FortiSIEM product from Fortinet has been found to have two new critical vulnerabilities, CVE-2024-23108 and CVE-2024-23109, which allow for remote code execution by unauthenticated attackers.
06 February 2024
While it is unclear whether a ransom was paid, the company stated that client transaction data was not accessed during the attack. The attack occurred amidst a major business deal, but experts predicted minimal disruption to EquiLend's operations
06 February 2024
The threat actors behind the campaign utilized multiple stages and techniques, including obfuscation and leveraging open platforms, to carry out the attack and steal sensitive information.
06 February 2024
The malware is distributed through a multi-stage infection chain involving weaponized PDF files, internet shortcuts, and PowerShell loaders, with similarities to the previously disclosed Phemedrone Stealer.
06 February 2024
Airbus Navblue Flysmart+ Manager had a vulnerability that allowed attackers to tamper with engine performance calculations and intercept data, posing a serious risk to flight safety.
06 February 2024
Threat actors are leveraging bogus Facebook job advertisements as a lure to trick prospective targets into installing a new Windows-based stealer malware codenamed Ov3r_Stealer.
"This malware is designed to steal credentials and crypto wallets and send those to a Telegram channel that the threat actor monitors," Trustwave SpiderLabs said in a report shared with The Hacker News.
Ov3r_Stealer
06 February 2024
Three new security vulnerabilities have been discovered in Azure HDInsight's Apache Hadoop, Kafka, and Spark services that could be exploited to achieve privilege escalation and a regular expression denial-of-service (ReDoS) condition.
"The new vulnerabilities affect any authenticated user of Azure HDInsight services such as Apache Ambari and Apache Oozie," Orca security
06 February 2024
The Pennsylvania Courts system has been hit by a cyberattack, taking down parts of its website. The Administrative Office of Pennsylvania Courts revealed via social media that the service had suffered a denial of service (DoS) attack.
06 February 2024
The stolen data, including over two million unique email addresses, was put up for sale in Chinese-speaking hacking-themed Telegram groups, with the majority of the focus on India, Taiwan, Thailand, and Vietnam.
06 February 2024
Latio Application Security Tester simplifies code scanning with OpenAI, offering easy code change submission and GitHub Actions templates. The tool's future plans include support for non-OpenAI models, improved handling of large files, and more.
06 February 2024

The future of cybercrime resembles an arms race between an industry of hackers-for-hire and the UK’s weak defences It is not quite accurate to say that the cyber-attack against the British Library took place on 28 October 2023. Most probably, Rhysida, the hacker gang that orchestrated the attack and is thought to be Russian, had already been creeping undetected through the digital territories of the British Library for months, Enrico Mariconti, a lecturer in security and crime science at UCL, told me.Once it broke through to the library’s virtual private network (VPN) – the remote connection that allows employees to access its network from any location – it could in theory start making its way through locked door after locked door of the library’s many online systems, trawling until it discovered emails and documents containing details such as employees’ passport scans and work contracts. It hoped these documents might tempt a single bidder to pay 20 bitcoins (about £600,000) for privileged access to all that personal information.Lamorna Ash is the author of Dark, Salt, Clear: Life in a Cornish Fishing Town Continue reading...
06 February 2024
Hewlett Packard Enterprise (HPE) is investigating a potential breach after a threat actor claimed to have stolen HPE credentials and sensitive data and put it up for sale on a hacking forum.
06 February 2024
SaaS applications are the darlings of the software world. They enable work from anywhere, facilitate collaboration, and offer a cost-effective alternative to owning the software outright. At the same time, the very features that make SaaS apps so embraced – access from anywhere and collaboration – can also be exploited by threat actors.
Recently, Adaptive Shield commissioned a Total Economic
06 February 2024
A cyberattack over the weekend targeted the computer servers of Northern Light Health, a major Maine healthcare provider. As a precaution, it temporarily took all patient records offline, although the records were not on the affected servers.