Latest Cybersecurity News and Articles


Chinese Hackers Silently Weaponized VMware Zero-Day Flaw for 2 Years

20 January 2024
An advanced China-nexus cyber espionage group previously linked to the exploitation of security flaws in VMware and Fortinet appliances has been linked to the abuse of a critical vulnerability in VMware vCenter Server as a zero-day since late 2021. "UNC3886 has a track record of utilizing zero-day vulnerabilities to complete their mission without being detected, and this latest example further

Russian Hackers Stole Microsoft Corporate Emails in Month-Long Breach

20 January 2024
The breach was facilitated by a password spray attack on a non-production test tenant account lacking two-factor authentication, highlighting the importance of robust account security measures.

Payoneer Accounts in Argentina Hacked in 2FA Bypass Attacks

20 January 2024
Suspicions have been raised about a potential data leak from mobile service providers or a breach in the SMS provider used for OTP code delivery as the possible cause of the hacks.

CISA Issues Emergency Directive to Federal Agencies on Ivanti Zero-Day Exploits

20 January 2024
The vulnerabilities allow threat actors to execute arbitrary commands, move laterally, perform data exfiltration, and establish persistent system access, potentially compromising target information systems.

China-linked APT UNC3886 Exploits VMware Zero-Day Since 2021

20 January 2024
Mandiant researchers observed UNC3886 exploiting a VMware ESXi zero-day vulnerability in June 2023, using novel malware persistence techniques to achieve administrative access within VMware ESXi Hypervisors.

CISA Issues Emergency Directive to Federal Agencies on Ivanti Zero-Day Exploits

19 January 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday issued an emergency directive urging Federal Civilian Executive Branch (FCEB) agencies to implement mitigations against two actively exploited zero-day flaws in Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS) products. The development came after the vulnerabilities – an authentication bypass

Microsoft's Top Execs' Emails Breached in Sophisticated Russia-Linked APT Attack

19 January 2024
Microsoft on Friday revealed that it was the target of a nation-state attack on its corporate systems that resulted in the theft of emails and attachments from senior executives and other individuals in the company's cybersecurity and legal departments. The Windows maker attributed the attack to a Russian advanced persistent threat (APT) group it tracks as Midnight Blizzard (formerly

Invoice Phishing Alert: TA866 Deploys WasabiSeed & Screenshotter Malware

19 January 2024
The threat actor tracked as TA866 has resurfaced after a nine-month hiatus with a new large-volume phishing campaign to deliver known malware families such as WasabiSeed and Screenshotter. The campaign, observed earlier this month and blocked by Proofpoint on January 11, 2024, involved sending thousands of invoice-themed emails targeting North America bearing decoy PDF files. "The PDFs

Update: VMware Confirms Critical vCenter Flaw Now Exploited in Attacks

19 January 2024
A critical vCenter Server vulnerability (CVE-2023-34048) is actively being exploited, allowing attackers to execute remote code with high impact and without requiring authentication.

FTC bans Texas media company from sharing location data

19 January 2024
The Federal Trade Commission (FTC) has banned Texas company InMarket Media from selling precise location data for advertising purposes.

Update: LoanDepot Outage Drags Into Second Week After Ransomware Attack

19 January 2024
The mortgage and loan company LoanDepot experienced a suspected ransomware attack, leading to difficulties for customers in making mortgage payments and accessing their online accounts.

PolyCrypt Runtime Crypter Being Sold on Cybercrime Forums

19 January 2024
The underground market for crypters, exemplified by PolyCrypt, facilitates the sale and use of these tools for malicious purposes, highlighting the ongoing challenge of cybercrime.

Canadian Man Stuck in Triangle of E-Commerce Fraud

19 January 2024
A Canadian man who says he's been falsely charged with orchestrating a complex e-commerce scam is seeking to clear his name. His case appears to involve "triangulation fraud," which occurs when a consumer purchases something online -- from a seller on Amazon or eBay, for example -- but the seller doesn't actually own the item for sale. Instead, the seller purchases the item from an online retailer using stolen payment card data. In this scam, the unwitting buyer pays the scammer and receives what they ordered, and very often the only party left to dispute the transaction is the owner of the stolen payment card.

Update: Vans, Supreme Owner VF Corp Says Hackers Stole 35 Million Customers’ Personal Data

19 January 2024
The clothing company has not specified the type of data stolen but assured that Social Security numbers, bank account information, and payment card details were not retained.

Report: Illicit Cryptocurrency Flows Drop 39% in 2023

19 January 2024
In 2023, the flow of cryptocurrency into illicit addresses decreased by nearly 39% compared to the previous year, with sanctioned entities accounting for the majority of activity, according to Chainalysis.

Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software

19 January 2024
These applications are found on Chinese pirating websites and contain modified disk image files that download and execute multiple payloads to compromise the victim's machine.

Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software

19 January 2024
Pirated applications targeting Apple macOS users have been observed containing a backdoor capable of granting attackers remote control to infected machines. "These applications are being hosted on Chinese pirating websites in order to gain victims," Jamf Threat Labs researchers Ferdous Saljooki and Jaron Bradley said. "Once detonated, the malware will download and execute multiple payloads

Adversaries Exploit Trends, Target Popular GenAI Apps

19 January 2024
Enterprise employees are increasingly accessing generative AI applications, posing a risk of exposing sensitive data, making it crucial for organizations to implement advanced data security measures.

Cybercriminals Leverage TeamViewer to Breach Networks in New Ransomware Attacks

19 January 2024
Ransomware actors are exploiting TeamViewer to gain access to organization endpoints and attempt to deploy ransomware, highlighting the importance of maintaining strong security practices and using the latest software versions.

AHA Warns of Rise in Scams Targeting IT Help Desks for Payment Fraud

19 January 2024
The AHA recommends strict IT help desk security protocols and immediate notification to financial institutions and the FBI to mitigate the risk of falling victim to these schemes.