Latest Cybersecurity News and Articles


Tietoevry Ransomware Attack Causes Outages for Swedish Firms, Cities

22 January 2024
Finnish IT services and cloud hosting provider Tietoevry was hit by a ransomware attack, affecting a data center in Sweden and causing outages for multiple customers, including Filmstaden, Rusta, Moelven, and Grangnården.

New Guidance Urges US Water Sector to Boost Cyber Resilience

22 January 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), along with the Environmental Protection Agency (EPA) and the FBI, has issued a warning about increased cyberthreats targeting water and wastewater systems.

Cyberattack Hits Three English Councils at Once, as Outsourcer Civica Denies Blame

22 January 2024
The incident is suspected to be linked to the outsourcing of IT and HR services to Civica through the East Kent Services partnership, raising concerns about the potential impact on data and services.

CISA’s 1,200 Pre-Ransomware Alerts Saved Organizations Millions in Damages

22 January 2024
The agency's Joint Cyber Defense Collaborative gathers information to alert potential ransomware victims early on. CISA also assisted a Fortune 500 company and a mass transit operator in preventing significant ransomware attacks.

NS-STEALER Uses Discord Bots to Exfiltrate Your Secrets from Popular Browsers

22 January 2024
Cybersecurity researchers have discovered a new Java-based "sophisticated" information stealer that uses a Discord bot to exfiltrate sensitive data from compromised hosts. The malware, named NS-STEALER, is propagated via ZIP archives masquerading as cracked software, Trellix security researcher Gurumoorthi Ramanathan said in an analysis published last week. The ZIP file contains

52% of Serious Vulnerabilities We Find are Related to Windows 10

22 January 2024
We analyzed 2,5 million vulnerabilities we discovered in our customer’s assets. This is what we found. Digging into the data The dataset we analyze here is representative of a subset of clients that subscribe to our vulnerability scanning services. Assets scanned include those reachable across the Internet, as well as those present on internal networks. The data includes findings for network

LockBit Gang Claims New Attack on the Sandwich Chain Subway

22 January 2024
Subway's internal system, containing hundreds of gigabytes of data, has allegedly been compromised by the ransomware group. The group has given Subway a deadline to protect the stolen data, and it is currently unknown what ransom they have demanded.

Brave to End ‘Strict’ Fingerprinting Protection as it Breaks Websites

22 January 2024
The 'Standard' fingerprinting protection mode in Brave Browser will be enhanced to provide strong privacy protection while maintaining better compatibility with websites.

French CNIL Imposes Fine of $11 Million on Yahoo

22 January 2024
The French regulator found that Yahoo had deposited at least 20 advertising cookies without obtaining proper consent, affecting more than 5 million consumers over 21 months.

Admin of the BreachForums Hacking Forum Sentenced to 20 Years Supervised Release

22 January 2024
The hacking forum facilitated the exchange of illicit data and access devices, leading to the arrest of Pompompurin and the closure of RaidForums in a law enforcement operation.

Researchers Link 3AM Ransomware to Conti, Royal Cybercrime Gangs

22 January 2024
Researchers have found strong links between the 3AM ransomware and the Conti syndicate through analysis of their infrastructure, communication channels, and attack tactics.

Groups Urge FTC to Scrutinize Google Location Data Practices

22 January 2024
Two tech advocacy groups are urging the FTC to investigate Google for allegedly failing to delete sensitive location data as promised, potentially violating privacy and putting individuals at risk.

Apache ActiveMQ Flaw Exploited in New Godzilla Web Shell Attacks

22 January 2024
A critical vulnerability in Apache ActiveMQ (CVE-2023-46604) is being actively exploited by threat actors to deploy various malicious payloads, including ransomware and DDoS botnets.

FTC Settles Second Case With Geolocation Data Broker in Two Weeks

22 January 2024
The FTC has settled with a data broker, InMarket Media, for improperly collecting and selling consumers' location data without informed consent, signaling increased scrutiny of data brokers.

Experts Call for US Cyber Safety Review Board Rethink

22 January 2024
There are differing opinions on whether the CSRB should be granted subpoena powers, with concerns about potential conflicts of interest and adversarial relationships with the private sector.

Update: Ransomware Gang Claims Responsibility for Christmas Attack on Massachusetts Hospital

22 January 2024
The Money Message ransomware gang claimed responsibility for stealing 600GB of data from Anna Jaques Hospital, highlighting the ongoing threat to healthcare institutions.

IT Consultant in Germany Fined for Exposing Shoddy Security

22 January 2024
A security researcher in Germany was fined €3,000 ($3,300) for uncovering and reporting a serious e-commerce database vulnerability. The vulnerability exposed almost 700,000 customer records due to a plaintext password stored in the software.

FTC Bans InMarket for Selling Precise User Location Without Consent

22 January 2024
The U.S. Federal Trade Commission (FTC) is continuing to clamp down on data brokers by prohibiting InMarket Media from selling or licensing precise location data. The settlement is part of allegations that the Texas-based company did not inform or seek consent from consumers before using their location information for advertising and marketing purposes. "InMarket will also be prohibited from

Apache ActiveMQ Flaw Exploited in New Godzilla Web Shell Attacks

21 January 2024
Cybersecurity researchers are warning of a "notable increase" in threat actor activity actively exploiting a now-patched flaw in Apache ActiveMQ to deliver the Godzilla web shell on compromised hosts. "The web shells are concealed within an unknown binary format and are designed to evade security and signature-based scanners," Trustwave said. "Notably, despite the binary's unknown file

Digital afterlife – how to deal with social media accounts when someone dies

20 January 2024
Digital afterlife – how to deal with social media accounts when someone dies Deciding what to do with a dead friend or relative’s online presence is complicated and time-consuming but there are shortcutsFind more essential summer readingGet our morning and afternoon news emails,free app or daily news podcastGavin Blomeley was lucky his mother was incredibly organised before she died. She left a note that included the passcode to her phone and access to all her online passwords.“I can’t even begin to imagine how difficult this could have gotten not having these passwords or knowing this note with all of her passwords existed,” Blomeley says.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...