Latest Cybersecurity News and Articles


Vulnerability Affecting Smart Thermostats Patched by Bosch

13 January 2024
German technology manufacturer Bosch has fixed a vulnerability in its popular line of smart thermostats that allowed attackers to replace the device firmware with a rogue version.

Purple Teaming and the Role of Threat Categorization

13 January 2024
Purple team assessments, where red and blue teams collaborate, can provide a more comprehensive approach to security assessments, but they need to evolve to account for the multitude of attack technique variants.

Update: Ransomware Attack on US Navy Shipbuilder Leaked Information of Nearly 17,000 People

13 January 2024
Nearly 17,000 people had their personal information exposed in a ransomware attack on Fincantieri Marine Group. The attack, which occurred in April 2023, caused production issues and disrupted the company's computer systems.

Saudi Foreign Affairs Ministry Allegedly Hit by Major Data Breach, Impacting Over 1.4 Million Employees

13 January 2024
The Ministry of Foreign Affairs for Saudi Arabia reportedly experienced a major data breach, exposing the personal information of over 1.4 million employees, including names, contact details, and job titles.

New Financial Fraud APK Campaign Discovered

13 January 2024
A new family of malicious Android Package Kit (APK) files has been discovered targeting Chinese users. The attackers pose as law enforcement officials and claim the victim's phone number or bank account is involved in financial fraud.

Update: Nation-State Actors Weaponize Ivanti VPN Zero-Days, Deploying Five Malware Families

13 January 2024
Suspected nation-state threat actors have been exploiting two zero-day vulnerabilities in Ivanti Connect Secure VPN appliances to gain backdoor access to targeted devices.

Medusa Ransomware Turning Your Files into Stone

12 January 2024
The Medusa ransomware group has escalated its activities by introducing a dedicated leak site called the Medusa Blog, where they disclose sensitive data from non-compliant victims.

Alabama law firm issues data breach notification

12 January 2024
An Alabama-based law firm announced that the company experienced a data breach affecting client information, including insurance information.

GitLab Releases Patch for Critical Vulnerabilities

12 January 2024
The vulnerability (CVE-2023-7028) allows attackers to reset passwords through unverified email addresses, affecting all self-managed instances of GitLab Community Edition and Enterprise Edition.

CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign

12 January 2024
The Phemedrone Stealer campaign exploits the Windows Defender SmartScreen Bypass vulnerability (CVE-2023-36025) to infect users and steal data from web browsers, cryptocurrency wallets, and messaging apps.

FTC blocks data broker from selling information

12 January 2024
The FTC has prohibited X-Mode Social and Outlogic from selling or sharing sensitive data to settle allegations regarding precise location data.

Bitwarden Adds Passkey Support to Log Into Web Password Vaults

12 January 2024
Passkeys in Bitwarden are generated using the PRF WebAuthn extension, which derives a unique encryption key from the passkey and enhances security. The passkey feature is currently in beta and available in Chromium-based browsers.

Nation-State Actors Weaponize Ivanti VPN Zero-Days, Deploying 5 Malware Families

12 January 2024
As many as five different malware families were deployed by suspected nation-state actors as part of post-exploitation activities leveraging two zero-day vulnerabilities in Ivanti Connect Secure (ICS) VPN appliances since early December 2023. "These families allow the threat actors to circumvent authentication and provide backdoor access to these devices," Mandiant said in an

Fake Recruiters Defraud Facebook Users via Remote Work Offers

12 January 2024
Researchers from Qualys have warned of a new wave of job scams on Facebook's Meta platform. Scammers are using Facebook ads to lure users with offers of remote work and then stealing their personal data and banking credentials.

Medusa Ransomware on the Rise: From Data Leaks to Multi-Extortion

12 January 2024
The threat actors associated with the Medusa ransomware have ramped up their activities following the debut of a dedicated data leak site on the dark web in February 2023 to publish sensitive data of victims who are unwilling to agree to their demands. “As part of their multi-extortion strategy, this group will provide victims with multiple options when their data is posted on their

Further Analysis of Denmark Attacks Leads to Warning About Unpatched Network Gear

12 January 2024
Cybersecurity researchers warn that the recent attacks on Denmark's energy sector highlight the need for critical infrastructure organizations across Europe to remain vigilant against exploits targeting unpatched network infrastructure devices.

Urgent: GitLab Releases Patch for Critical Vulnerabilities - Update ASAP

12 January 2024
GitLab has released security updates to address two critical vulnerabilities, including one that could be exploited to take over accounts without requiring any user interaction. Tracked as CVE-2023-7028, the flaw has been awarded the maximum severity of 10.0 on the CVSS scoring system and could facilitate account takeover by sending password reset emails to an unverified email address. The

Halara Probes Breach After Hacker Leaks Data for 950,000 People

12 January 2024
The leaked data, containing names, phone numbers, and addresses, appears to be accurate according to users listed in the file. Customers should be cautious of potential smishing attacks and the misuse of their information for fraudulent purposes.

How the Merck Case Shapes the Future of Cyber Insurance

12 January 2024
The complexity of attributing cyber incidents to specific entities, such as nation-states or criminal groups, poses challenges when applying exclusions in insurance policies.

Cyber Insecurity and Misinformation Top WEF Global Risk List

12 January 2024
The World Economic Forum's Global Risks Report 2024 highlights the increasing threat of cyber threats, with misinformation and disinformation being identified as the most severe risk globally.