Latest Cybersecurity News and Articles


Online Ransomware Decryptor Helps Recover Partially Encrypted Files

31 January 2024
White Phoenix attempts to recover data through automated restoration methods and may help restore valuable files for ransomware victims, providing a potential option for those affected by certain ransomware strains.

Alpha Ransomware Group Launches Data Leak Site on the Dark Web

31 January 2024
The ransomware appends a random 8-character alphanumeric extension to encrypted files and its DLS, titled “MYDATA,” is considered unstable and frequently offline, indicating the group is still in the process of setting up operations.

New Glibc Flaw Grants Attackers Root Access on Major Linux Distros

31 January 2024
The __vsyslog_internal() function in glibc has also been found to contain two more flaws (CVE-2023-6779 and CVE-2023-6780) and a separate bug in the qsort() function, affecting all glibc versions since 1992.

Chinese Hackers Exploiting VPN Flaws to Deploy KrustyLoader Malware

31 January 2024
A pair of recently disclosed zero-day flaws in Ivanti Connect Secure (ICS) virtual private network (VPN) devices have been exploited to deliver a Rust-based payload called KrustyLoader that's used to drop the open-source Sliver adversary simulation tool. The security vulnerabilities, tracked as CVE-2023-46805 (CVSS score: 8.2) and CVE-2024-21887 (CVSS score: 9.1), could be abused

Critical Workspace Creation Flaw in GitLab Allows File Overwrite

31 January 2024
The latest update also addressed four medium-severity flaws, including issues related to regular expression denial-of-service, HTML injection, and disclosure of user's public email address via the tags RSS feed.

Israeli Government Says Smallest of SMBs Hit Hardest in Cyberattacks

31 January 2024
Businesses with five to 20 employees were the most impacted, especially those in the industrial sector. The field of commerce reported the fewest cyberattacks, with only 3% of businesses being affected.

China-Linked Hackers Target Myanmar's Top Ministries with Backdoor Blitz

31 January 2024
The Mustang Panda group utilized legitimate software and phishing emails to deploy malicious DLLs and backdoors, disguising command-and-control traffic as Microsoft update traffic.

New Glibc Flaw Grants Attackers Root Access on Major Linux Distros

31 January 2024
Malicious local attackers can obtain full root access on Linux machines by taking advantage of a newly disclosed security flaw in the GNU C library (aka glibc). Tracked as CVE-2023-6246, the heap-based buffer overflow vulnerability is rooted in glibc's __vsyslog_internal() function, which is used by syslog() and vsyslog() for system logging purposes. It's said to have been accidentally

OpenAI Says Mysterious Chat Histories Resulted From Account Takeover

31 January 2024
ChatGPT users' private conversations were leaked due to unauthorized logins from a different location, highlighting the need for better security measures such as 2FA and IP tracking.

Chloé Messdaghi appointed Head of Threat Intelligence at HiddenLayer

30 January 2024
Chloé Messdaghi has been appointed Head of Threat Intelligence at HiddenLayer. Messdaghi is focused on sharing the latest security for AI research.

Fla. Man Charged in SIM-Swapping Spree is Key Suspect in Hacker Groups Oktapus, Scattered Spider

30 January 2024
On Jan. 9, 2024, U.S. authorities arrested a 19-year-old Florida man charged with wire fraud, aggravated identity theft, and conspiring with others to use SIM-swapping to steal cryptocurrency. Sources close to the investigation tell KrebsOnSecurity the accused was a key member of a criminal hacking group blamed for a string of cyber intrusions at major U.S. technology companies during the summer of 2022.

2023 witnessed 68% more ransomware attacks than 2022

30 January 2024
According to a report, while Q4 ransomware attacks were down slightly from Q3 2023, ransomware activity for the year surpassed 2022 totals by 68%.

Brazilian Feds Dismantle Grandoreiro Banking Trojan, Arresting Top Operatives

30 January 2024
A Brazilian law enforcement operation has led to the arrest of several Brazilian operators in charge of the Grandoreiro malware. The Federal Police of Brazil said it served five temporary arrest warrants and 13 search and seizure warrants in the states of São Paulo, Santa Catarina, Pará, Goiás, and Mato Grosso. Slovak cybersecurity firm ESET, which provided additional

Threat Actors Selling 1.8TB Database of 750 Million Indian Mobile Users

30 January 2024
The compromised database is being sold on hacker forums, with two cybercrime groups offering the data for sale, highlighting the growing threat posed by emerging threat groups like CYBO CREW and its affiliates.

URGENT: Upgrade GitLab - Critical Workspace Creation Flaw Allows File Overwrite

30 January 2024
GitLab once again released fixes to address a critical security flaw in its Community Edition (CE) and Enterprise Edition (EE) that could be exploited to write arbitrary files while creating a workspace. Tracked as CVE-2024-0402, the vulnerability has a CVSS score of 9.9 out of a maximum of 10. "An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to

Hundreds of Network Operators’ Credentials Found Circulating in Dark Web

30 January 2024
A significant number of network administrators and IT personnel were found to have their credentials compromised, highlighting the vulnerability of staff involved in network engineering and IT management operations.

Dynatrace Acquires Runecast to Improve Cloud-Native Security

30 January 2024
Dynatrace's acquisition of Runecast will enhance its platform with AI-powered security posture management for proactive risk mitigation and real-time vulnerability assessments in hybrid and multicloud environments.

There was a 39% surge in data exfiltration cyberattacks in 2023

30 January 2024
According to a report, the number of organizations claiming to have been a victim of ransomware in the past 12 months more than doubled.

Ukraine’s Prisoners of War Agency Hit by Cyberattack

30 January 2024
Ukraine's Coordination Headquarters for Prisoners of War faced a DDoS attack, suspected to be linked to the recent crash of a Russian transport plane carrying Ukrainian prisoners and Russian servicemen.

Research shows cybercriminals’ motivation shifts to data exfiltration

30 January 2024
A new report shows ransomware attacks are increasing again and reveals a change in strategy among cybercriminals.