Latest Cybersecurity News and Articles


49% of organizations cite poor training as cause for privacy concerns

18 January 2024
According to a recent data privacy report, 43% say their privacy budget is underfunded and 51% of respondents expect a decrease in budget.

Report: 75% of Organizations Hit by Ransomware in 2023

18 January 2024
Cyberattacks are the leading cause of technology outages for 40% of organizations, emphasizing the need for comprehensive disaster preparation beyond just cybersecurity measures, according to Veeam.

Russian COLDRIVER Hackers Expand Beyond Phishing with Custom Malware

18 January 2024
The Russia-linked threat actor known as COLDRIVER has been observed evolving its tradecraft to go beyond credential harvesting to deliver its first-ever custom malware written in the Rust programming language. Google's Threat Analysis Group (TAG), which shared details of the latest activity, said the attack chains leverage PDFs as decoy documents to trigger the infection sequence. The lures are

Apple, AMD, Qualcomm, Imagination GPUs Open to Data Theft Using New LeftoverLocals Vulnerability

18 January 2024
The vulnerability affects various GPU products, with AMD and Apple planning mitigations, and Imagination and Qualcomm issuing fixes. Nvidia and Arm are reportedly unaffected.

OpenAI Combats Election Misinformation Amid Growing Concerns

18 January 2024
OpenAI is taking steps to prevent the use of ChatGPT in spreading election misinformation, including restricting its use for political campaigning and lobbying, and creating tools to empower voters to assess the authenticity of images.

Pro-Russia Group Hit Swiss Government Sites After Zelensky Visit in Davos

18 January 2024
Switzerland's National Cyber Security Centre promptly detected and responded to the DDoS attacks, restoring access to the targeted websites, including the Davos-Klosters ski resort and Swiss Ministry of the Interior.

As Hacks Worsen, SEC Turns up the Heat on CISOs

18 January 2024
The cybersecurity industry is facing increasing legal oversight and consequences, making it riskier to work in this field. Companies are now required to disclose "material" security incidents within four working days to the SEC.

Taiwanese Semiconductor Company Foxsemicon Suffers Ransomware Attack

18 January 2024
Foxsemicon, a major semiconductor manufacturer in Taiwan, was targeted by the LockBit ransomware gang, who threatened to leak customers' personal data if a ransom was not paid.

Attribute-Based Encryption Could Spell the End of Data Compromise

18 January 2024
Attribute-based encryption (ABE) offers fine-grained access to data, revolutionizing data protection and access control. ABE has diverse real-world applications, from privacy protection in surveillance videos to securing electronic medical records.

TensorFlow CI/CD Flaw Exposed Supply Chain to Poisoning Attacks

18 January 2024
Continuous integration and continuous delivery (CI/CD) misconfigurations discovered in the open-source TensorFlow machine learning framework could have been exploited to orchestrate supply chain attacks. The misconfigurations could be abused by an attacker to "conduct a supply chain compromise of TensorFlow releases on GitHub and PyPi by compromising TensorFlow's build agents via

Buggy API on Insurance Firm TTIBI's Website Leaked Over 650,000 Email Messages

18 January 2024
A security researcher Eaton Zveare discovered a misconfigured server belonging to Toyota Tsusho Insurance Broker India (TTIBI), which exposed over 650,000 Microsoft-hosted email messages.

Chinese Drones Pose Threat to US Infrastructure, CISA Warns

18 January 2024
The U.S. Cybersecurity and Infrastructure Security Agency and the FBI are warning critical infrastructure owners about the potential security risks posed by Chinese-manufactured unmanned aircraft systems (UAS).

iShutdown Method Allows to Discover Spyware Infections on iPhones

18 January 2024
The presence of spyware, such as Pegasus, Predator, and Reign, can be identified by examining the Shutdown.log file for anomalous log entries related to processes delaying the reboot.

MFA Spamming and Fatigue: When Security Measures Go Wrong

18 January 2024
In today's digital landscape, traditional password-only authentication systems have proven to be vulnerable to a wide range of cyberattacks. To safeguard critical business resources, organizations are increasingly turning to multi-factor authentication (MFA) as a more robust security measure. MFA requires users to provide multiple authentication factors to verify their identity, providing an

Researcher Uncovers Massive Password Dump Containing 71 Million Unique Credentials

18 January 2024
A massive data tranch containing nearly 71 million unique credentials, including 25 million previously unseen passwords, has been circulating on the internet for at least four months.

Bigpanzi Botnet Infects 170,000 Android TV Boxes With Malware

18 January 2024
The malware tools used by Bigpanzi, including 'pandoraspear' and 'pcdn,' enable the cybercriminals to hijack DNS settings, establish C2 communication, build a peer-to-peer CDN, and execute DDoS attacks on infected devices.

Cooper Aerobics Data Security Incident Raises Concerns of Personal Information Exposure

18 January 2024
The breach involved sensitive data such as financial details, SSNs, and health-related information. While there is no evidence of identity theft or financial fraud, the firm is taking precautionary measures and offering support to affected people.

FTC Joins Global Data Security and Privacy Investigative Consortium

18 January 2024
This nonbinding consortium aims to assist privacy investigators worldwide and facilitate seamless collaboration in law enforcement investigations and actions involving privacy and data security.

Iranian Hackers Masquerade as Journalists to Spy on Israel-Hamas War Experts

18 January 2024
The group's latest intrusion set involves using lures related to the Israel-Hamas war, sending malicious links disguised as innocuous emails, and utilizing breached accounts to build trust with targets.

PixieFail UEFI Flaws Expose Millions of Computers to RCE, DoS, and Data Theft

18 January 2024
Multiple security vulnerabilities have been disclosed in the TCP/IP network protocol stack of an open-source reference implementation of the Unified Extensible Firmware Interface (UEFI) specification used widely in modern computers. Collectively dubbed PixieFail by Quarkslab, the nine issues reside in the TianoCore EFI Development Kit II (EDK II) and could be exploited to