Latest Cybersecurity News and Articles
06 February 2024
Employment agencies and retail companies chiefly located in the Asia-Pacific (APAC) region have been targeted by a previously undocumented threat actor known as ResumeLooters since early 2023 with the goal of stealing sensitive data.
Singapore-headquartered Group-IB said the hacking crew's activities are geared towards job search platforms and the theft of resumes, with as many as 65
06 February 2024
The Commerce Department has sanctioned several European, Israeli, Russian, and Singaporean companies involved in the trafficking and development of spyware tools used for repression and human rights abuses.
06 February 2024
The leak compromised highly confidential documents exchanged between the Ministry of Foreign Affairs and its international diplomatic missions, prompting discussions between Tokyo and Washington on countermeasures.
06 February 2024
The court ruling allows the FTC to continue its enforcement action against data broker Kochava for selling non-anonymized, granular location data, setting the stage for potential limitations on data brokers' activities.
06 February 2024
The security research team at Escape scanned 189.5 million URLs and discovered over 18,000 exposed API secrets, with 41% of them being highly critical and posing financial risks.
06 February 2024
Collaboration between organizations and ethical hackers is essential as cyberattacks become more sophisticated, and bug bounty programs play a significant role in promoting online security.
06 February 2024
The Philippines repelled a cyberattack from hackers suspected to be based in China, targeting multiple government departments. The attackers used IP addresses located in China, prompting lawmakers to demand an urgent briefing on national security
06 February 2024
The cyberattacks targeted water systems in Pennsylvania and were carried out by an Iranian-backed militia group, exposing vulnerabilities in America's water infrastructure.
06 February 2024
The cyberattack led to disruption in Clorox's business operations, requiring expenses for IT recovery, forensic experts, and professional services to investigate and remediate the attack.
06 February 2024
The EUCC scheme is voluntary and aims to provide a common assessment process for ICT suppliers to certify products, based on the SOG-IS Common Criteria evaluation framework.
06 February 2024
A recently disclosed server-side request forgery (SSRF) vulnerability impacting Ivanti Connect Secure and Policy Secure products has come under mass exploitation.
The Shadowserver Foundation said it observed exploitation attempts originating from more than 170 unique IP addresses that aim to establish a reverse shell, among others.
The attacks exploit CVE-2024-21893 (CVSS
06 February 2024
The flaw allows attackers to bypass authentication and access restricted resources on vulnerable devices. The exploitation volume is high, with over 170 distinct IP addresses attempting to exploit the vulnerability.
06 February 2024
The U.S. State Department said it's implementing a new policy that imposes visa restrictions on individuals who are linked to the illegal use of commercial spyware to surveil civil society members.
"The misuse of commercial spyware threatens privacy and freedoms of expression, peaceful assembly, and association," Secretary of State Antony Blinken said. "Such targeting has been
05 February 2024
A 42-year-old Belarusian and Cypriot national with alleged connections to the now-defunct cryptocurrency exchange BTC-e is facing charges related to money laundering and operating an unlicensed money services business.
Aliaksandr Klimenka, who was arrested in Latvia on December 21, 2023, was extradited to the U.S. If convicted, he faces a maximum penalty of 25 years in prison.
BTC-e, which had
05 February 2024
Following Federal Trade Commission (FTC) charges, Blackbaud will be required to delete any unnecessary personal data to settle data privacy claims.
05 February 2024
The threat actor known as Patchwork likely used romance scam lures to trap victims in Pakistan and India, and infect their Android devices with a remote access trojan called VajraSpy.
Slovak cybersecurity firm ESET said it uncovered 12 espionage apps, six of which were available for download from the official Google Play Store and were collectively downloaded more than 1,400 times between
05 February 2024
The scammers digitally recreated the company's chief financial officer and other employees in a convincing video conference call to trick the victim into making money transfers.
05 February 2024
The Windows SmartScreen vulnerability CVE-2023-36025 allows threat actors to bypass warnings and execute malicious payloads using crafted .url files, posing a significant security risk to Windows users.
05 February 2024
The second half of 2023 saw a significant increase in the scale and sophistication of DDoS attacks, with the maximum attack power rising to 1.6 Tbps, according to data by Gcore.
05 February 2024
An investigation revealed widespread use of Pegasus spyware on the phones of journalists, human rights advocates, and lawyers in Jordan, suggesting a targeted surveillance campaign by Jordanian authorities.