Latest Cybersecurity News and Articles


Ivanti Releases Patch for Critical Vulnerability in Endpoint Manager Solution

05 January 2024
Ivanti has released security updates to address a critical vulnerability in its Endpoint Manager solution. The flaw, known as CVE-2023-39336, allows attackers to execute remote code on susceptible servers.

Alert: Ivanti Releases Patch for Critical Vulnerability in Endpoint Manager Solution

05 January 2024
Ivanti has released security updates to address a critical flaw impacting its Endpoint Manager (EPM) solution that, if successfully exploited, could result in remote code execution (RCE) on susceptible servers. Tracked as CVE-2023-39336, the vulnerability has been rated 9.6 out of 10 on the CVSS scoring system. The shortcoming impacts EPM 2021 and EPM 2022 prior to SU5. “If exploited, an

Russian Hackers Had Covert Access to Ukraine's Telecom Giant for Months

05 January 2024
Ukrainian cybersecurity authorities have disclosed that the Russian state-sponsored threat actor known as Sandworm was inside telecom operator Kyivstar's systems at least since May 2023. The development was first reported by Reuters. The incident, described as a "powerful hacker attack," first came to light last month, knocking out access to mobile and internet services

New Bandook RAT Variant Resurfaces, Targeting Windows Machines

05 January 2024
A new variant of remote access trojan called Bandook has been observed being propagated via phishing attacks with an aim to infiltrate Windows machines, underscoring the continuous evolution of the malware. Fortinet FortiGuard Labs, which identified the activity in October 2023, said the malware is distributed via a PDF file that embeds a link to a password-protected .7z archive. “

Victoria court records exposed following cyberattack

04 January 2024
In December 2023, Court Services Victoria was alerted to a cybersecurity incident impacting Victoria's courts and tribunals, including recordings.

Data Breach at Healthcare Tech Firm Hits 4.5 Million Patients

04 January 2024
The breach impacted 17 healthcare service providers and state-level health systems, including Corewell Health, HonorHealth, and the State of Tennessee's Division of TennCare.

SentinelOne Acquires PingSafe to Expand Cloud Security Capabilities

04 January 2024
By integrating PingSafe's capabilities into SentinelOne's Singularity Platform, companies will have access to a unified, best-of-breed security platform for their entire cloud footprint.

Threat Actor Demands $1M for Remote Command Injection Vulnerability in Cisco ASA

04 January 2024
The sale of this vulnerability poses significant risks, including network disruption, data compromise, and financial and reputational damage for organizations reliant on Cisco ASA.

Update: Estes Refuses to Pay Off Ransomware Crew, Says Data Stolen

04 January 2024
The company chose not to pay the ransom demanded by the hackers, aligning with the FBI's recommendation, but the specific details of the attack and the stolen data remain undisclosed.

Three Malicious PyPI Packages Found Targeting Linux Systems with Crypto Miners

04 January 2024
The packages were named modularseven, driftme, and catme and received a total of 431 downloads before being removed. The packages contained a CoinMiner executable that was deployed on the affected devices.

Cloud-Native Cybersecurity Startup Aqua Security Raises $60M and Remains a Unicorn

04 January 2024
The Series E funding round was led by Evolution Equity Partners, with participation from existing investors Lightspeed Venture Partners, Insight Partners, and StepStone Group.

Three Ways To Supercharge Your Software Supply Chain Security

04 January 2024
Section four of the "Executive Order on Improving the Nation’s Cybersecurity" introduced a lot of people in tech to the concept of a “Software Supply Chain” and securing it. If you make software and ever hope to sell it to one or more federal agencies, you have to pay attention to this. Even if you never plan to sell to a government, understanding your Software Supply Chain and

UAC-0050 Group Using New Phishing Tactics to Distribute Remcos RAT

04 January 2024
The malware is being distributed through LNK files that collect information about antivirus products and execute an HTML application. This leads to the download of two files from a remote server, which establish persistence and launch the Remcos RAT.

LastPass Now Requires 12-Character Master Passwords for Better Security

04 January 2024
LastPass, a popular password management solution, is now requiring customers to use complex master passwords with a minimum of 12 characters to enhance account security. Previously, users had the option to use weaker passwords.

Hacker Hijacks Orange Spain RIPE Account to Cause BGP Havoc

04 January 2024
The hacker changed the AS number associated with Orange Spain's IP addresses and enabled an invalid RPKI configuration, causing the IP addresses to no longer be announced properly.

Beware: 3 Malicious PyPI Packages Found Targeting Linux with Crypto Miners

04 January 2024
Three new malicious packages have been discovered in the Python Package Index (PyPI) open-source repository with capabilities to deploy a cryptocurrency miner on affected Linux devices. The three harmful packages, named modularseven, driftme, and catme, attracted a total of 431 downloads over the past month before they were taken down. “These packages, upon initial use, deploy a CoinMiner

FTC Soliciting Contest Submissions to Help Tackle Voice Cloning Technology

04 January 2024
The FTC is seeking multidisciplinary approaches to prevent unauthorized use of voice cloning, improve real-time detection, and provide consumers with tools to identify cloned voices in audio clips.

Consumers Prepared to Ditch Brands After Cybersecurity Issues

04 January 2024
In 2023, businesses have been hit with 800,000 cyberattacks, over 60,000 of which were DDoS attacks and 4,000 falling victim to ransomware, according to a report by Vercara.

Ukraine Says Russia Hacked Web Cameras to Spy on Targets in Kyiv

04 January 2024
Ukraine's security officers have discovered that Russian intelligence hacked into surveillance cameras in Kyiv to gain remote access and stream sensitive footage, potentially aiding in missile strikes against the city.

Nigerian Hacker Arrested for Stealing $7.5M From US Charities

04 January 2024
The fraud scheme involved unauthorized access to email accounts, impersonating employees, and tricking one charity into transferring funds to accounts controlled by the attacker.