Latest Cybersecurity News and Articles
09 January 2024
Olugbenga Lawal, 33, of Indianapolis, Indiana, was convicted in August last year of conspiring to commit money laundering, after three co-conspirators had already pleaded guilty to the same crime.
09 January 2024
While there is no evidence that the flaws have been exploited in the wild, it's recommended that users take steps to update their installations to the latest version to mitigate potential risks.
09 January 2024
The cyberattack has forced the affected Chambers to disconnect from the network and take their systems offline, causing disruption to vocational training and other online services.
09 January 2024
According to a recent report, 87% of organizations indicate plans to enhance vulnerability and exposure remediation efforts within the next year.
09 January 2024
The Saudi Ministry of Industry and Mineral Resources (MIM) had a sensitive environment file exposed for 15 months, potentially allowing attackers to gain unauthorized access and launch ransomware attacks.
09 January 2024
The Refuah Health Center in New York has been fined up to $450,000 and required to invest over $1 million in improving its data security following a ransomware attack in 2021.
09 January 2024
Poorly secured Microsoft SQL (MS SQL) servers are being targeted in the U.S., European Union, and Latin American (LATAM) regions as part of an ongoing financially motivated campaign to gain initial access.
“The analyzed threat campaign appears to end in one of two ways, either the selling of ‘access’ to the compromised host, or the ultimate delivery of ransomware payloads,” Securonix researchers
09 January 2024
The authentication bypass flaw in OFBiz allows attackers to remotely execute arbitrary code and access sensitive information. Upgrading to OFBiz version 18.12.11 is crucial to patch both this zero-day vulnerability and another equally serious hole.
09 January 2024
The attack was carried out by the Rhysida ransomware gang, who also claimed responsibility for attacking the Lutheran World Federation, a member of the WCC. The WCC's systems went down on December 26, 2023.
09 January 2024
The attack caused network outages and disrupted patient care, resulting in canceled appointments and rescheduled surgeries. The LockBit ransomware gang has now threatened to leak 7TB of stolen data from the hospital.
09 January 2024
FortiGuard Labs researchers discovered an attack campaign involving the Lumma Stealer malware spreading through hijacked YouTube channels. Threat actors compromise accounts, upload videos disguised as legitimate cracked software sharing, and redirect users to malicious URLs via installation guides. It is recommended to download apps/software from trusted sources.
09 January 2024
The breach, carried out by the BlackCat ransomware gang, resulted in the theft of around 30 gigabytes of sensitive data, including a contract between the Swiss Department of Defence and Ultra Intelligence & Communications for nearly $5 million.
09 January 2024
Collaboration is a powerful selling point for SaaS applications. Microsoft, Github, Miro, and others promote the collaborative nature of their software applications that allows users to do more.
Links to files, repositories, and boards can be shared with anyone, anywhere. This encourages teamwork that helps create stronger campaigns and projects by encouraging collaboration among employees
09 January 2024
Hackers are increasingly targeting verified Twitter accounts of businesses and government organizations to promote cryptocurrency scams and steal assets from unsuspecting users.
09 January 2024
A security flaw has been disclosed in Kyocera’s Device Manager product that could be exploited by bad actors to carry out malicious activities on affected systems.
"This vulnerability allows attackers to coerce authentication attempts to their own resources, such as a malicious SMB share, to capture or relay Active Directory hashed credentials if the ‘Restrict NTLM: Outgoing NTLM
09 January 2024
The Toronto Zoo's operations and animal well-being were not impacted by a recent ransomware attack on its systems. The zoo does not store credit card information but is investigating if the attack affected guest and donor records.
09 January 2024
The cyberattack may have been a distributed denial of service (DDoS) attack. Prior to the election, both political parties accused foreign states of attempting to influence the vote.
09 January 2024
A threat group is using YouTube channels to distribute a variant of Lumma Stealer, a malware that targets sensitive information, by uploading videos with malicious URLs disguised as cracked software installation guides.
09 January 2024
Threat actors are resorting to YouTube videos featuring content related to cracked software in order to entice users into downloading an information stealer malware called Lumma.
“These YouTube videos typically feature content related to cracked applications, presenting users with similar installation guides and incorporating malicious URLs often shortened using services like TinyURL and Cuttly,
08 January 2024
In July of 2023, Welltok was alerted to a data breach affected by MOVEit Transfer software, affecting health data and Social Security Numbers.