Latest Cybersecurity News and Articles


Hands-On Review: SASE-based XDR from Cato Networks

05 February 2024
Companies are engaged in a seemingly endless cat-and-mouse game when it comes to cybersecurity and cyber threats. As organizations put up one defensive block after another, malicious actors kick their game up a notch to get around those blocks. Part of the challenge is to coordinate the defensive abilities of disparate security tools, even as organizations have limited resources and a dearth of

Combined Security Practices Changing the Game for Risk Management

05 February 2024
A significant challenge within cyber security at present is that there are a lot of risk management platforms available in the market, but only some deal with cyber risks in a very good way. The majority will shout alerts at the customer as and when they become apparent and cause great stress in the process. The issue being that by using a reactive, rather than proactive approach, many risks

More Ransomware Victims are Declining to Pay Extortionists

05 February 2024
The decline in the number of ransomware victims paying a ransom is attributed to better business resilience, assistance from the FBI, and the realization that paying for intangible promises is not effective.

China-Linked Hackers Primed to Attack US Critical Infrastructure, FBI Director Says

05 February 2024
The Cybersecurity and Infrastructure Security Agency (CISA) has observed an evolving threat from China-linked hackers infiltrating U.S. critical infrastructure, aiming to induce societal panic and chaos.

Lurie Children’s Hospital in Chicago Took Systems Offline After Cyberattack

05 February 2024
Some internal services at the hospital, such as internet, email, and access to medical platforms, have been affected, resulting in delays for scheduled procedures and test results.

Accenture and Tenchi Security Unite to Fortify Supply Chain Security

05 February 2024
This strategic partnership will involve integrating Tenchi's SaaS platform into Accenture's managed security services to enhance defenses against supply chain security threats.

Detecting and Mitigating the “Greatness” Phishing Kit Threat

05 February 2024
The "Greatness" phishing tool poses a significant threat to Microsoft 365 accounts and has the capability to outmaneuver multi-factor authentication, increasing the potential for cybercrime.

Oasis Security Leaves Stealth With $40M to Lock down the Wild West of Non-Human Identity Management

05 February 2024
Oasis Security, a startup from Israel, has developed a three-part system to address the challenges of non-human identity management, including discovery, resolution, and automation.

Update: DOJ Charges Trio in SIM-Swap Scheme Potentially Linked to $400 Million FTX Crypto Heist

05 February 2024
The trio obtained personal information from around 50 individuals and used it to access authentication codes for financial accounts, including those of FTX, resulting in the transfer of over $400 million in digital assets.

Pegasus Spyware Targeted iPhones of Journalists and Activists in Jordan

05 February 2024
The iPhones belonging to nearly three dozen journalists, activists, human rights lawyers, and civil society members in Jordan have been targeted with NSO Group's Pegasus spyware, according to joint findings from Access Now and the Citizen Lab. Nine of the 35 individuals have been publicly confirmed as targeted, out of whom had their devices compromised with the mercenary

Update: Secret Service Recovers Nearly $3 Million Stolen From North Carolina Housing Authority in BEC Scam

05 February 2024
The scam involved a request to update payment information for a private company contracting with the agency, resulting in the transfer of funds to an illegitimate account.

New Mispadu Banking Trojan Exploiting Windows SmartScreen Flaw

04 February 2024
The threat actors behind the Mispadu banking Trojan have become the latest to exploit a now-patched Windows SmartScreen security bypass flaw to compromise users in Mexico. The attacks entail a new variant of the malware that was first observed in 2019, Palo Alto Networks Unit 42 said in a report published last week. Propagated via phishing mails, Mispadu is a Delphi-based information stealer

Iran-Linked Hackers Claim Attack on Albania’s Institute of Statistics

03 February 2024
The hackers claimed to have accessed over 100 terabytes of Albania’s geographic information system and population data, although the institute denied that recent census data was compromised.

South African Railways Lost Over $1M in Phishing Scam

03 February 2024
The Passenger Rail Agency of South Africa (PRASA) reported a loss of 30.6 million rand due to a phishing scam, with only half of the stolen money recovered. Insider threats, such as ghost email accounts, are suspected.

U.S. Sanctions 6 Iranian Officials for Critical Infrastructure Cyber Attacks

03 February 2024
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) announced sanctions against six officials associated with the Iranian intelligence agency for attacking critical infrastructure entities in the U.S. and other countries. The officials include Hamid Reza Lashgarian, Mahdi Lashgarian, Hamid Homayunfal, Milad Mansuri, Mohammad Bagher Shirinkar, and Reza Mohammad Amin

Critical Vulnerability in Mastodon Sparks Patching Frenzy

03 February 2024
Mastodon users and administrators need to upgrade to the latest version to patch a critical vulnerability (CVE-2024-23832) that allows attackers to take over accounts remotely.

macOS Malware Campaign Showcases Novel Delivery Technique

03 February 2024
The backdoor, called Activator, employs a unique delivery method that backdoors the victim during the installation process, making it challenging to remove the infection even if the cracked software is removed.

Mastodon Vulnerability Allows Hackers to Hijack Any Decentralized Account

03 February 2024
The decentralized social network Mastodon has disclosed a critical security flaw that enables malicious actors to impersonate and take over any account. "Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account," the maintainers said in a terse advisory. The vulnerability, tracked as CVE-2024-23832, has a severity rating of 9.4 out of

AnyDesk Says Hackers Breached its Production Servers, Reset Passwords

03 February 2024
The attackers stole source code and code signing certificates. AnyDesk responded by revoking security certificates, replacing systems, and reassuring customers that it is safe to use the software.

Fake Voicemail as Credential Harvesting Lure

03 February 2024
The attackers disguise the email to appear as if it's from a legitimate brand, using social engineering techniques to lure recipients into clicking on what seems to be an embedded voicemail but is actually a credential harvesting page.