Latest Cybersecurity News and Articles


FTC proposes new restrictions on the use of children's data

05 January 2024
The Federal Trade Commission (FTC) announced proposed changes to the Children’s Online Privacy Protection Rule (COPPA Rule), including ed tech.

New SpectralBlur macOS Backdoor Threat From North Korean Hackers

05 January 2024
The backdoor, SpectralBlur, shares similarities with the KANDYKORN malware family attributed to North Korean threat actors and showcases their evolving tactics to infiltrate industries like cryptocurrency and blockchain.

SpectralBlur: New macOS Backdoor Threat from North Korean Hackers

05 January 2024
Cybersecurity researchers have discovered a new Apple macOS backdoor called SpectralBlur that overlaps with a known malware family that has been attributed to North Korean threat actors. “SpectralBlur is a moderately capable backdoor that can upload/download files, run a shell, update its configuration, delete files, hibernate, or sleep, based on commands issued from the [

The FBI Is Adding More Cyber-Focused Agents to US Embassies

05 January 2024
The expansion of the FBI's cyber program reflects a shift towards a proactive approach, focusing on disrupting cybercriminal operations rather than just investigating after the fact.

Crypto Wallet Founder Loses $125,000 to Fake Airdrop Website

05 January 2024
Bill Lou, co-founder of Nest Wallet, a cryptocurrency wallet startup, lost $125,000 to a crypto scam. He fell victim to a phishing attack after visiting a fraudulent website that appeared to be a legitimate crypto airdrop platform.

DOE Announces Up to $70 Million to Strengthen Energy Sector Against Physical and Cyber Hazards

05 January 2024
The funding opportunity is open to public and private stakeholders, universities, and DOE's National Laboratories, and will focus on developing innovative solutions to strengthen the resilience of America's energy systems.

AsyncRAT Distributed Using Phishing Emails and Malicious JavaScript Files

05 January 2024
AT&T Alien Labs discovered an ongoing campaign that delivers the AsyncRAT to targeted victims. The threat actor behind the campaign has been active for at least 11 months, using phishing emails and malicious JavaScript files to distribute the RAT.

23andMe Blames User “Negligence” for Data Breach

05 January 2024
The company claims that users negligently recycled and failed to update their passwords, allowing attackers to launch a credential stuffing campaign. Nearly 7 million customers' information was accessed, including genealogy data.

US Military’s Cyber National Mission Force Gets a New Chief

05 January 2024
The CNMF, composed of 39 joint cyber teams with over 2,000 military and civilian personnel, is a vital component of Cyber Command's operations and has been authorized to become a permanent organization.

MyEstatePoint Property Search Android App Leaks User Passwords, Email Addresses, and Phone Numbers

05 January 2024
The MyEstatePoint Property Search app, developed by NJ Technologies in India, left a publicly accessible MongoDB server containing sensitive information such as names, plain-text passwords, email addresses, phone numbers, and more.

San Bernardino Housing Authority Cyberattack Affected Nearly 19,000 People

05 January 2024
This incident highlights the ongoing vulnerability of housing authorities to cyberattacks, as seen in previous attacks on housing authorities in North Carolina, Los Angeles, Indianapolis, and Cleveland.

Orrick, Herrington & Sutcliffe Data Breach Exposes Information of Over 600,000 Individuals

05 January 2024
The stolen data included a wide range of information such as names, dates of birth, addresses, government-issued identification numbers, medical treatment details, insurance claims information, and credit/debit card numbers.

Exposed Secrets are Everywhere. Here's How to Tackle Them

05 January 2024
Picture this: you stumble upon a concealed secret within your company's source code. Instantly, a wave of panic hits as you grasp the possible consequences. This one hidden secret has the power to pave the way for unauthorized entry, data breaches, and a damaged reputation. Understanding the secret is just the beginning; swift and resolute action becomes imperative. However, lacking the

Orange Spain Faces BGP Traffic Hijack After RIPE Account Hacked by Malware

05 January 2024
Mobile network operator Orange Spain suffered an internet outage for several hours on January 3 after a threat actor used administrator credentials captured by means of stealer malware to hijack the border gateway protocol (BGP) traffic. "The Orange account in the IP network coordination center (RIPE) has suffered improper access that has affected the browsing of some of our customers," the

Security Vulnerabilities Addressed in Firefox 121

05 January 2024
Mozilla's latest release of Firefox 121 addresses critical vulnerabilities, including a heap buffer overflow bug and a vulnerability in rendering Network Security Services (NSS) NIST curves.

BreachForums Administrator Detained After Violating Parole

05 January 2024
The administrator of BreachForums, a notorious cybercrime haven, has been arrested for violating his parole by using a computer and VPN services without the required monitoring software.

Update: Russian Hackers Had Covert Access to Ukraine's Telecom Giant for Months

05 January 2024
A Russian hacking group called Solntsepyok claimed responsibility for the breach. Sandworm, known for orchestrating disruptive cyber attacks, has been linked to Solntsepyok.

Mimecast Acquires Human Risk Management Specialist Elevate Security

05 January 2024
The deal aims to enhance digital work environment protection by gaining insights into human behavior. Mimecast plans to integrate Elevate Security's technology into its own security offerings by midyear.

In Airtags Stalking Lawsuit, Federal Judge Says Apple Likely Negligent

05 January 2024
A federal judge in San Francisco has indicated that he is leaning towards denying Apple's motion to dismiss a class action lawsuit brought by stalking victims who claim that the company's AirTags tracking product enabled their abusers.

Ivanti Releases Patch for Critical Vulnerability in Endpoint Manager Solution

05 January 2024
Ivanti has released security updates to address a critical vulnerability in its Endpoint Manager solution. The flaw, known as CVE-2023-39336, allows attackers to execute remote code on susceptible servers.