Latest Cybersecurity News and Articles


Hackers Exploit Job Boards in APAC, Steal Data of Millions of Job Seekers

06 February 2024
Employment agencies and retail companies chiefly located in the Asia-Pacific (APAC) region have been targeted by a previously undocumented threat actor known as ResumeLooters since early 2023 with the goal of stealing sensitive data. Singapore-headquartered Group-IB said the hacking crew's activities are geared towards job search platforms and the theft of resumes, with as many as 65

US announces visa ban on those linked to commercial spyware

06 February 2024
The Commerce Department has sanctioned several European, Israeli, Russian, and Singaporean companies involved in the trafficking and development of spyware tools used for repression and human rights abuses.

Update: Classified Japanese Diplomatic Documents Leaked in Chinese Cyberattacks

06 February 2024
The leak compromised highly confidential documents exchanged between the Ministry of Foreign Affairs and its international diplomatic missions, prompting discussions between Tokyo and Washington on countermeasures.

Judge Allows Case Against Geolocation Data Broker Kochava To Proceed

06 February 2024
The court ruling allows the FTC to continue its enforcement action against data broker Kochava for selling non-anonymized, granular location data, setting the stage for potential limitations on data brokers' activities.

Researchers Discover Exposed API Secrets, Impacting Major Tech Tokens

06 February 2024
The security research team at Escape scanned 189.5 million URLs and discovered over 18,000 exposed API secrets, with 41% of them being highly critical and posing financial risks.

Report: Ethical Hackers Reported 835 Vulnerabilities, Earned $450K in 2023

06 February 2024
Collaboration between organizations and ethical hackers is essential as cyberattacks become more sophisticated, and bug bounty programs play a significant role in promoting online security.

Philippine Lawmakers Demand Briefing Following China-Linked Cyberattack

06 February 2024
The Philippines repelled a cyberattack from hackers suspected to be based in China, targeting multiple government departments. The attackers used IP addresses located in China, prompting lawmakers to demand an urgent briefing on national security

US Sanctions Iranian Officials Over Cyberattacks on Water Plants

06 February 2024
The cyberattacks targeted water systems in Pennsylvania and were carried out by an Iranian-backed militia group, exposing vulnerabilities in America's water infrastructure.

Update: Clorox Says Cyberattack Caused $49 Million in Expenses

06 February 2024
The cyberattack led to disruption in Clorox's business operations, requiring expenses for IT recovery, forensic experts, and professional services to investigate and remediate the attack.

EU Adopts First Cybersecurity Certification Scheme for Safer Tech

06 February 2024
The EUCC scheme is voluntary and aims to provide a common assessment process for ICT suppliers to certify products, based on the SOG-IS Common Criteria evaluation framework.

Recent SSRF Flaw in Ivanti VPN Products Undergoes Mass Exploitation

06 February 2024
A recently disclosed server-side request forgery (SSRF) vulnerability impacting Ivanti Connect Secure and Policy Secure products has come under mass exploitation. The Shadowserver Foundation said it observed exploitation attempts originating from more than 170 unique IP addresses that aim to establish a reverse shell, among others. The attacks exploit CVE-2024-21893 (CVSS

Newest Ivanti SSRF Zero-Day Now Under Mass Exploitation

06 February 2024
The flaw allows attackers to bypass authentication and access restricted resources on vulnerable devices. The exploitation volume is high, with over 170 distinct IP addresses attempting to exploit the vulnerability.

U.S. Imposes Visa Restrictions on those Involved in Illegal Spyware Surveillance

06 February 2024
The U.S. State Department said it's implementing a new policy that imposes visa restrictions on individuals who are linked to the illegal use of commercial spyware to surveil civil society members. "The misuse of commercial spyware threatens privacy and freedoms of expression, peaceful assembly, and association," Secretary of State Antony Blinken said. "Such targeting has been

Belarusian National Linked to BTC-e Faces 25 Years for $4 Billion Crypto Money Laundering

05 February 2024
A 42-year-old Belarusian and Cypriot national with alleged connections to the now-defunct cryptocurrency exchange BTC-e is facing charges related to money laundering and operating an unlicensed money services business. Aliaksandr Klimenka, who was arrested in Latvia on December 21, 2023, was extradited to the U.S. If convicted, he faces a maximum penalty of 25 years in prison. BTC-e, which had

FTC requires Blackbaud to delete personal data following charges

05 February 2024
Following Federal Trade Commission (FTC) charges, Blackbaud will be required to delete any unnecessary personal data to settle data privacy claims.

Patchwork Using Romance Scam Lures to Infect Android Devices with VajraSpy Malware

05 February 2024
The threat actor known as Patchwork likely used romance scam lures to trap victims in Pakistan and India, and infect their Android devices with a remote access trojan called VajraSpy. Slovak cybersecurity firm ESET said it uncovered 12 espionage apps, six of which were available for download from the official Google Play Store and were collectively downloaded more than 1,400 times between

Over 25$ Million Lost in Deepfake Conference Call Scam at Hong Kong Office of Multinational Firm

05 February 2024
The scammers digitally recreated the company's chief financial officer and other employees in a convincing video conference call to trick the victim into making money transfers.

New Mispadu Banking Trojan Exploits Windows SmartScreen Flaw

05 February 2024
The Windows SmartScreen vulnerability CVE-2023-36025 allows threat actors to bypass warnings and execute malicious payloads using crafted .url files, posing a significant security risk to Windows users.

DDoS Attack Power Skyrockets to 1.6 Tbps

05 February 2024
The second half of 2023 saw a significant increase in the scale and sophistication of DDoS attacks, with the maximum attack power rising to 1.6 Tbps, according to data by Gcore.

Report: Civil Society in Jordan Under Assault by NSO's Pegasus Spyware

05 February 2024
An investigation revealed widespread use of Pegasus spyware on the phones of journalists, human rights advocates, and lawyers in Jordan, suggesting a targeted surveillance campaign by Jordanian authorities.