Latest Cybersecurity News and Articles


New PoC Exploit for Apache OfBiz Vulnerability Poses Risk to ERP Systems

11 January 2024
Cybersecurity researchers have developed a proof-of-concept (PoC) code that exploits a recently disclosed critical flaw in the Apache OfBiz open-source Enterprise Resource Planning (ERP) system to execute a memory-resident payload. The vulnerability in question is CVE-2023-51467 (CVSS score: 9.8), a bypass for another severe shortcoming in the same software (

New Python-based FBot Hacking Toolkit Aims at Cloud and SaaS Platforms

11 January 2024
A new Python-based hacking tool called FBot has been uncovered targeting web servers, cloud services, content management systems (CMS), and SaaS platforms such as Amazon Web Services (AWS), Microsoft 365, PayPal, Sendgrid, and Twilio. “Key features include credential harvesting for spamming attacks, AWS account hijacking tools, and functions to enable attacks against PayPal and various

UK: NCSC Publishes Practical Security Guidance for SMBs

11 January 2024
Smaller organizations are increasingly reliant on cloud and online services, making them vulnerable to cyber threats. The guide provides practical advice on choosing the right service, securing user accounts, and recovering from a cyberattack.

Black Basta-Affiliate Spreads Pikabot

11 January 2024
Threat group Water Curupira, known for its Cobalt Strike backdoors, recently transitioned to using Pikabot malware in phishing campaigns. Pikabot witnessed a surge in activity in Q4 2023, potentially serving as a replacement for Qakbot after its takedown. Users must exercise caution with email attachments and verify sender authenticity.

HMG Healthcare Discloses Data Breach Affecting 40 Affiliated Nursing Facilities

11 January 2024
The breach occurred in August 2023 when threat actors gained unauthorized access to a company server and stole unencrypted files containing medical records, personal information, and employment records.

French Hacker From ‘ShinyHunters’ Group Sentenced to Three Years in US Prison

11 January 2024
A 22-year-old French hacker has been sentenced to three years in U.S. federal prison for his involvement in the ShinyHunters hacking group and must pay $5 million in restitution.

Thousands of WordPress Sites with Popup Builder Plugin Compromised by Balada Injector

11 January 2024
A stored XSS flaw in the Popup Builder WordPress plugin has been exploited by the Balada Injector campaign. The campaign injects malicious code into websites using older versions of the plugin, with over 6,200 sites currently affected.

There is a Ransomware Armageddon Coming for Us All

11 January 2024
Generative AI will enable anyone to launch sophisticated phishing attacks that only Next-generation MFA devices can stop The least surprising headline from 2023 is that ransomware again set new records for a number of incidents and the damage inflicted. We saw new headlines every week, which included a who’s-who of big-name organizations. If MGM, Johnson Controls, Chlorox, Hanes Brands, Caesars

Atomic Stealer Gets an Upgrade - Targeting Mac Users with Encrypted Payload

11 January 2024
Cybersecurity researchers have identified an updated version of a macOS information stealer called Atomic (or AMOS), indicating that the threat actors behind the malware are actively enhancing its capabilities. "It looks like Atomic Stealer was updated around mid to late December 2023, where its developers introduced payload encryption in an effort to bypass detection rules,"

ExtraHop Raises $100M in Growth Capital

11 January 2024
Seattle-based company ExtraHop has raised $100 million in growth capital for its cloud-native network detection and response platform. The funding will be used to expand operations and business reach.

New NoaBot Botnet Spreads an Illicit Cryptominer on Linux Systems

11 January 2024
The malware's obfuscation and custom code suggest mature threat actors, but the inclusion of childish elements complicates attribution, making it difficult to determine the exact nature of the operation.

Top LLM Vulnerabilities and How to Mitigate the Associated Risk

11 January 2024
Enterprises must implement robust security measures throughout the AI application development lifecycle to mitigate vulnerabilities such as prompt and data leakage, including sandboxing, whitelisting, and careful vetting of plug-ins.

Actively Exploited Zero-Days in Ivanti VPN are Letting Hackers Backdoor Networks

11 January 2024
The vulnerabilities, tracked as CVE-2023-846805 and CVE-2024-21887, were used in an attack last month to steal configuration data, modify files, and gain unauthorized access to systems.

Beware of Phishing Scams Disguised as Annual HR Tasks

11 January 2024
Threat actors are increasingly using annual responsibilities like open enrollment, 401k updates, and salary adjustments as lures to steal employee credentials through phishing emails.

Atomic Stealer Rings in the New Year With Updated Version

11 January 2024
Atomic Stealer, a popular malware among criminals, has recently been updated with payload encryption to evade detection and has been distributed through malvertising campaigns and cracked software.

Cisco Says Critical Unity Connection Bug Lets Attackers Get Root

11 January 2024
The vulnerability, found in the software's web-based management interface, allows attackers to execute commands on the underlying operating system by uploading arbitrary files.

Mandiant's X Account Was Hacked Using Brute-Force Attack

11 January 2024
The compromise of Mandiant's X (formerly Twitter) account last week was likely the result of a "brute-force password attack," attributing the hack to a drainer-as-a-service (DaaS) group. "Normally, [two-factor authentication] would have mitigated this, but due to some team transitions and a change in X's 2FA policy, we were not adequately protected," the threat intelligence firm said 

Chinese Hackers Exploit Zero-Day Flaws in Ivanti Connect Secure and Policy Secure

11 January 2024
A pair of zero-day flaws identified in Ivanti Connect Secure (ICS) and Policy Secure have been chained by suspected China-linked nation-state actors to breach less than 10 customers. Cybersecurity firm Volexity, which identified the activity on the network of one of its customers in the second week of December 2023, attributed it to a hacking group it tracks under the name UTA0178

Cisco Fixes High-Risk Vulnerability Impacting Unity Connection Software

10 January 2024
Cisco has released software updates to address a critical security flaw impacting Unity Connection that could permit an adversary to execute arbitrary commands on the underlying system. Tracked as CVE-2024-20272 (CVSS score: 7.3), the vulnerability is an arbitrary file upload bug residing in the web-based management interface and is the result of a lack of authentication in a specific

Cybersecurity Deals Boom as Investment Dips, Pinpoint Reports

10 January 2024
The cybersecurity sector recorded 346 funding rounds and 91 mergers and acquisition (M&A) transactions in 2023, according to cyber recruitment firm Pinpoint Search Group.