Latest Cybersecurity News and Articles


Data Insights on AgentTesla and OriginLogger Victims

15 January 2024
AgentTesla, also known as OriginLogger, is a prevalent commodity malware that steals sensitive information from Windows systems. It is commonly distributed via email attachments and has been a persistent threat since 2014.

US CISA Must Improve Water Sector Assistance, Says Watchdog

15 January 2024
Funding shortfalls and aging IT infrastructure contribute to poor cybersecurity in the water and wastewater sector, which is operated mainly by municipal and county governments.

Hacker Spins up One Million Virtual Servers to Illegally Mine Crypto

15 January 2024
A 29-year-old man in Ukraine was arrested for using hacked accounts to create 1 million virtual servers and mine $2 million in cryptocurrency, highlighting the growing threat of cryptojacking.

Cloud Security Predictions for 2024

15 January 2024
Businesses and cybersecurity professionals must prioritize understanding the intricacies of identity and access management (IAM) in a cloud-dominated era to ensure a robust security posture.

High-Severity Flaws Uncovered in Bosch Thermostats and Smart Nutrunners

15 January 2024
Multiple security vulnerabilities have been disclosed in Bosch BCC100 thermostats and Rexroth NXA015S-36V-B smart nutrunners that, if successfully exploited, could allow attackers to execute arbitrary code on affected systems. Romanian cybersecurity firm Bitdefender, which discovered the flaw in Bosch BCC100 thermostats last August, said the issue could be weaponized by an attacker to

Apple Fixed a Bug in Magic Keyboard That Allows to Monitor Bluetooth Traffic

15 January 2024
Apple has released a firmware update for its Magic Keyboard to address a recently discovered vulnerability that allows an attacker with physical access to the keyboard to extract its Bluetooth pairing key and spy on Bluetooth traffic.

Balada Injector Infects Over 7,100 WordPress Sites Using Plugin Vulnerability

15 January 2024
Thousands of WordPress sites using a vulnerable version of the Popup Builder plugin have been compromised with a malware called Balada Injector. First documented by Doctor Web in January 2023, the campaign takes place in a series of periodic attack waves, weaponizing security flaws WordPress plugins to inject backdoor designed to redirect visitors of infected sites to bogus tech

Critical RCE Vulnerability Uncovered in Juniper SRX Firewalls and EX Switches

15 January 2024
The vulnerability, rated 9.8 on the CVSS scoring system, could allow an unauthenticated attacker to cause a Denial-of-Service (DoS) or execute remote code with root privileges.

Vast Voter Data Leaks Cast Shadow Over Indonesia ’s 2024 Presidential Election

15 January 2024
Multiple breaches have resulted in the leak of millions of voter records, including personally identifiable information, which could be used for targeted information warfare campaigns during the election and beyond.

DDoS Attacks on the Environmental Services Industry Surge by 61,839% in 2023

15 January 2024
The environmental services industry witnessed an “unprecedented surge” in HTTP-based distributed denial-of-service (DDoS) attacks, accounting for half of all its HTTP traffic. This marks a 61,839% increase in DDoS attack traffic year-over-year, web infrastructure and security company Cloudflare said in its DDoS threat report for 2023 Q4 published last week. “This surge in cyber attacks coincided

New Findings Challenge Attribution in Denmark's Energy Sector Cyberattacks

14 January 2024
The cyber attacks targeting the energy sector in Denmark last year may not have had the involvement of the Russia-linked Sandworm hacking group, new findings from Forescout show. The intrusions, which targeted around 22 Danish energy organizations in May 2023, occurred in two distinct waves, one which exploited a security flaw in Zyxel firewall (CVE-2023-28771) and a

Critical RCE Vulnerability Uncovered in Juniper SRX Firewalls and EX Switches

13 January 2024
Juniper Networks has released updates to fix a critical remote code execution (RCE) vulnerability in its SRX Series firewalls and EX Series switches. The issue, tracked as CVE-2024-21591, is rated 9.8 on the CVSS scoring system. “An out-of-bounds write vulnerability in J-Web of Juniper Networks Junos OS SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a

29-Year-Old Ukrainian Cryptojacking Kingpin Arrested for Exploiting Cloud Services

13 January 2024
A 29-year-old Ukrainian national has been arrested in connection with running a “sophisticated cryptojacking scheme,” netting them over $2 million (€1.8 million) in illicit profits. The person was apprehended in Mykolaiv, Ukraine, on January 9 by the National Police of Ukraine with support from Europol and an unnamed cloud service provider following “months of intensive collaboration.” “A cloud

Fertility Test Lab Will Pay $1.25M to Settle Breach Lawsuit

13 January 2024
The settlement includes reimbursement for out-of-pocket losses, credit monitoring, identity theft insurance, and a cash settlement payment for affected individuals, with an additional payment for California residents.

British Cosmetics Firm Lush Confirms Cyberattack

13 January 2024
Lush has taken immediate steps to secure and screen all systems in order to contain the incident and limit its impact on their operations, while also informing relevant authorities about the incident.

Report: Elevated Ransomware Activity Hit Nearly 5,200 Organizations in 2023

13 January 2024
The most active ransomware groups in 2023 included AlphV, BianLian, Clop, LockBit 3.0, and Play, with AlphV being the most prolific and receiving substantial ransom payments.

Medusa Ransomware Gang Targets Nonprofit Providing Clean Water to World’s Poorest

13 January 2024
Water for People, a nonprofit focused on improving access to clean water, has been targeted by the Medusa ransomware group, highlighting the vulnerability of even non-profit organizations to cyberattacks.

APIs are Increasingly Becoming Attractive Targets

13 January 2024
APIs are being used more than ever by businesses to build and provide better sites, apps, and services to consumers. However, if APIs are not managed or secured properly, they can be exploited by hackers to steal sensitive information.

Volt Typhoon Ramps Up Malicious Activity Against Critical Infrastructure

13 January 2024
Volt Typhoon is using compromised routers as a command-and-control network and deploying a new web shell called "fy.sh" on targeted Cisco routers, indicating a highly active and sophisticated operation.

Vulnerability Affecting Smart Thermostats Patched by Bosch

13 January 2024
German technology manufacturer Bosch has fixed a vulnerability in its popular line of smart thermostats that allowed attackers to replace the device firmware with a rogue version.