Latest Cybersecurity News and Articles


Vendor Email Attacks Surged by 137% in Financial Sector in 2023

18 January 2024
The financial services industry has seen a significant increase in Vendor Email Compromise (VEC) and Business Email Compromise (BEC) attacks, with VEC attacks causing millions of dollars in losses.

Indian Air Force Potentially Targeted With Info-Stealing Malware

18 January 2024
The malware used in the campaign, a variant of Go Stealer, targets browsers like Firefox, Chrome, Edge, and Brave, and uses Slack for data exfiltration to blend in with regular business traffic.

National Bank of Angola Says it Mitigated Cyberattack

18 January 2024
The National Bank of Angola is trying to reassure the country that its financial system is secure following a cyberattack on January 6. No hacking group has taken credit for the incident.

Clearview Resources Ltd Hit by Cyberattack, Suffers $1.5 Million in Damages

18 January 2024
A cyberattack on the Canadian energy producer Clearview Resources Ltd resulted in a US$1.5 million financial loss. The attack involved the compromise of an internal email address, leading to the redirection of company funds to a third-party account.

Iranian Hackers Masquerade as Journalists to Spy on Israel-Hamas War Experts

17 January 2024
High-profile individuals working on Middle Eastern affairs at universities and research organizations in Belgium, France, Gaza, Israel, the U.K., and the U.S. have been targeted by an Iranian cyber espionage group called Mind Sandstorm since November 2023. The threat actor "used bespoke phishing lures in an attempt to socially engineer targets into downloading malicious files," the

Vulnerabilities Discovered in Android-based POS Terminals From PAX Technology

17 January 2024
The PoS terminals from PAX Technology, based on Android, are found to have several vulnerabilities that can be exploited to execute arbitrary code or commands, according to a report by STM Cyber.

E-Crime Rapper ‘Punchmade Dev’ Debuts Card Shop

17 January 2024
The rapper and social media personality Punchmade Dev is perhaps best known for his flashy videos singing the praises of a cybercrime lifestyle. With memorable hits such as "Internet Swiping" and "Million Dollar Criminal" earning millions of views, Punchmade has leveraged his considerable following to peddle tutorials on how to commit financial crimes online. But until recently, there wasn't much to support a conclusion that Punchmade was actually doing the cybercrime things he promotes in his songs.

Detained Russian Student Allegedly Helped Ukrainian Hackers With Cyberattacks

17 January 2024
A Russian tech student faces treason charges for allegedly helping Ukrainian hackers carry out cyberattacks against Russia, revealing the ongoing cyberwar between the two countries.

Cyber Startup Vicarius Raises $30 Million Series B for Vulnerability Remediation Platform

17 January 2024
The Israeli startup has secured a $30 million Series B funding led by Bright Pixel Capital. The company's total funding now exceeds $56 million, with participation from other investors such as JVP, AllegisCyber Capital, AlleyCorp, and Strait Capital.

Cheap .cloud Domains and Shark Tank Impersonation Fuels Unhealthy Scams

17 January 2024
Scammers are using fake news campaigns and cheaply acquired domain names to sell dubious health products, often claiming endorsements from popular entrepreneurial reality shows like Shark Tank and Dragons' Den.

Progress Software’s MOVEit Meltdown: Uncovering the Fallout

17 January 2024
The data breach involving Progress Software’s MOVEit file-transfer service exposed millions of individuals and thousands of organizations, highlighting the far-reaching impact of supply chain cyberattacks.

MacOS Info-Stealers Quickly Evolve to Evade XProtect Detection

17 January 2024
XProtect, macOS's built-in anti-malware system, struggles to detect evolving info-stealers like KeySteal and Atomic Stealer, highlighting the need for more robust security measures.

Snyk Acquires Helios for Runtime Visibility

17 January 2024
Snyk's acquisition of Helios marks its second move in developer-led application security posture management, following the previous acquisition of Enso Security, further strengthening its platform with prioritization and remediation capabilities.

Crypto Trading Firm Closes Shop After $8 Million NY State Fine Over Security Issues

17 January 2024
Genesis Global Trading violated its BitLicense terms, with late and inadequate cybersecurity risk assessments, and appeared deficient in filing suspicious activity reports for potential money laundering.

Citrix Warns Admins to Immediately Patch NetScaler for Actively Exploited Zero-Days

17 January 2024
The vulnerabilities, tracked as CVE-2023-6548 and CVE-2023-6549, can lead to remote code execution or denial-of-service attacks, and specific recommendations for mitigating the risks are provided.

PAX PoS Terminal Flaw Could Allow Attackers to Tamper with Transactions

17 January 2024
The point-of-sale (PoS) terminals from PAX Technology are impacted by a collection of high-severity vulnerabilities that can be weaponized by threat actors to execute arbitrary code. The STM Cyber R&D team, which reverse engineered the Android-based devices manufactured by the Chinese firm owing to their rapid deployment in Poland, said it unearthed half a dozen flaws that allow for

Combating IP Leaks into AI Applications with Free Discovery and Risk Reduction Automation

17 January 2024
Wing Security announced today that it now offers free discovery and a paid tier for automated control over thousands of AI and AI-powered SaaS applications. This will allow companies to better protect their intellectual property (IP) and data against the growing and evolving risks of AI usage. SaaS applications seem to be multiplying by the day, and so does their integration of AI

Adalanche: Open-Source Active Directory ACL Visualizer, Explorer

17 January 2024
The tool offers a visual attack graph representation of Active Directory in the browser, along with the ability to collect data from Windows machines and perform in-depth analysis.

PixieFail Vulnerabilities Impact PXE Network Boot in Enterprise Systems

17 January 2024
The flaws affect Tianocore's EDK II UEFI implementation and other major tech companies and BIOS providers, prompting a coordinated disclosure effort by CERT/CC and CERT-FR.

Report: 94% of Firms Hit by Phishing Attacks in 2023

17 January 2024
Phishing attacks continue to pose a significant threat, with 94% of cyber decision-makers having to deal with such attacks in 2023, marking a 2% increase from the previous year, according to Egress.