Latest Cybersecurity News and Articles


88% of organizations use passwords as primary authentication method

23 January 2024
According to a recent password report by Specops Software, passwords remain the primary authentication method for 88% of organizations.

Black Basta Gang Claims the Hack of the UK Water Utility Southern Water

23 January 2024
The Black Basta ransomware gang targeted the UK water utility Southern Water, threatening to leak 750 gigabytes of stolen sensitive data, including personal and corporate documents.

Slug Ransomware Attacked AerCap, Claims to Have Stolen 1TB Data

23 January 2024
AerCap, the world's largest aircraft leasing company, reported a ransomware infection. However, it claims to have not suffered financial losses and has control over its systems.

Threat Assessment of BianLian Ransomware

23 January 2024
The BianLian ransomware group has shifted from a double extortion scheme to a focus on extortion without encryption, posing a significant threat to organizations, particularly in the healthcare and manufacturing sectors in the US and Europe.

Update: LoanDepot Says 16.6 Million Customers had ‘Sensitive Personal’ Information Stolen in Cyberattack

23 January 2024
The company is working to restore normal business operations, but many online services remain inaccessible even after two weeks. It is still uncertain whether the cyber incident will have a significant impact on LoanDepot's financial condition.

VexTrio: The Uber of Cybercrime - Brokering Malware for 60+ Affiliates

23 January 2024
The threat actors behind ClearFake, SocGholish, and dozens of other actors have established partnerships with another entity known as VexTrio as part of a massive "criminal affiliate program," new findings from Infoblox reveal. The latest development demonstrates the "breadth of their activities and depth of their connections within the cybercrime industry," the company said,

Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub

23 January 2024
Two malicious packages discovered on the npm package registry have been found to leverage GitHub to store Base64-encrypted SSH keys stolen from developer systems on which they were installed. The modules named warbeast2000 and kodiak2k were published at the start of the month, attracting 412 and 1,281 downloads before they were taken down by the npm

Global ransomware threat expected to rise with AI, NCSC warns

23 January 2024
New assessment focuses on how AI will impact the efficacy of cyber operations and the implications for the cyber threat over the next two years.

Apple Issues Patch for Critical Zero-Day in iPhones, Macs - Update Now

23 January 2024
The vulnerability, tracked as CVE-2024-23222, is a type confusion bug in the WebKit browser engine that could lead to arbitrary code execution when processing malicious web content.

North Korean ScarCruft Attackers Gear Up to Target Cybersecurity Professionals

23 January 2024
The group is testing innovative infection routines that use technical threat research on another North Korean APT group, Kimsuky, as a lure, indicating a new approach to their cyberattacks.

New Method To Safeguard Against Mobile Account Takeovers

23 January 2024
The method involves modeling how account access changes as devices, SIM cards, or apps are disconnected from the account ecosystem, providing insights into complex hacking attacks.

Historic Data Leak Reveals 26 Billion Records From Tencent, Weibo, Twitter, Adobe, and Others

23 January 2024
The leaked information spans across various companies, organizations, and government agencies globally. The potential impact on consumers is significant, as the leaked data could be used for credential-stuffing attacks and spear-phishing.

"Activator" Alert: MacOS Malware Hides in Cracked Apps, Targeting Crypto Wallets

23 January 2024
Cracked software have been observed infecting Apple macOS users with a previously undocumented stealer malware capable of harvesting system information and cryptocurrency wallet data. Kaspersky, which identified the artifacts in the wild, said they are designed to target machines running macOS Ventura 13.6 and later, indicating the malware's ability to infect Macs on both Intel and

Lack of Understanding, Underfunding Threaten Data Privacy & Compliance

23 January 2024
A lack of understanding combined with budgetary squeezes are significant obstacles for organization's navigating data privacy and compliance with data protection laws, according to industry body ISACA.

NS-STEALER Uses Discord Bots to Exfiltrate Your Secrets from Popular Browsers

23 January 2024
The malware exfiltrates sensitive information including screenshots, cookies, autofill credentials, system info, installed programs, tokens, and sessions, and uploads the collected data to a Discord bot channel.

From Megabits to Terabits: Gcore Radar Warns of a New Era of DDoS Attacks

23 January 2024
As we enter 2024, Gcore has released its latest Gcore Radar report, a twice-annual publication in which the company releases internal analytics to track DDoS attacks. Gcore’s broad, internationally distributed network of scrubbing centers allows them to follow attack trends over time. Read on to learn about DDoS attack trends for Q3–Q4 of 2023, and what they mean for developing a robust

Israel, Czech Republic Reinforce Cyber Partnership Amid Hamas War

23 January 2024
The agreement will facilitate the sharing of information and experience between the Israel National Cyber Directorate and the Czech National Cyber and Information Security Agency, including the possibility of internships.

Trezor Support Site Breach Exposes Personal Data of 66,000 Customers

23 January 2024
While no evidence of compromised digital assets has been found, 66,000 users' names, usernames, and email addresses may have been exposed. Unfortunately, attackers have exploited this data to trick some users into giving away their recovery seeds.

Finland: Prosecutors Add to Evidence Against Alleged Vastaamo Hacker

23 January 2024
Prosecutors have traced the cryptocurrency wallet used for extortion to the bank account of Aleksanteri Kivimäki, the accused in the psychotherapy clinic data breach case.

BreachForums Founder Sentenced to 20 Years of Supervised Release, No Jail Time

23 January 2024
Conor Brian Fitzpatrick has been sentenced to time served and 20 years of supervised release for his role as the creator and administrator of BreachForums. Fitzpatrick, who went by the online alias "pompompurin," was arrested in March 2023 in New York and was subsequently charged with conspiracy to commit access device fraud and possession of child pornography. He was later released on a $