Latest Cybersecurity News and Articles


European Central Bank to Put Banks Through Cyber Stress Test

03 January 2024
The European Central Bank will conduct cyber stress tests on 109 banks in Europe to assess their resilience against cyberattacks. The tests will simulate disruptive cyberattacks and evaluate how the banks respond and recover.

Orbit Chain Loses $86 Million in the Last Fintech Hack of 2023

03 January 2024
The stolen funds are believed to be linked to North Korean hacking groups, such as Lazarus, who use cryptocurrency cyberattacks to bypass international sanctions and finance their weapons development program.

5 Ways to Reduce SaaS Security Risks

03 January 2024
As technology adoption has shifted to be employee-led, just in time, and from any location or device, IT and security teams have found themselves contending with an ever-sprawling SaaS attack surface, much of which is often unknown or unmanaged. This greatly increases the risk of identity-based threats, and according to a recent report from CrowdStrike, 80% of breaches today use compromised

SMTP Smuggling: New Flaw Lets Attackers Bypass Security and Spoof Emails

03 January 2024
A new exploitation technique called Simple Mail Transfer Protocol (SMTP) smuggling can be weaponized by threat actors to send spoofed emails with fake sender addresses while bypassing security measures. "Threat actors could abuse vulnerable SMTP servers worldwide to send malicious emails from arbitrary email addresses, allowing targeted phishing attacks," Timo Longin, a senior security

DOJ Slams XCast with $10 Million Fine Over Massive Illegal Robocall Operation

03 January 2024
XCast transmitted billions of illegal robocalls to American consumers, using false affiliations with government agencies and misleading information to deceive victims into making purchases.

New York State AG Hits Hospital With $300K Fine for Web Tracker Use

03 January 2024
NewYork-Presbyterian Hospital has been fined $300,000 by state regulators for privacy violations related to its use of tracking tools on its websites and patient portal. It violated HIPAA rules by sharing patient information with third parties.

Hacker Group Claims to Steal 3TB Data From Iranian Food Delivery Giant Snappfood

03 January 2024
The hacker group, known as "irleaks," publicly disclosed the breach and claimed to have acquired a vast amount of data, including customer details, vendor records, payment information, device data, product orders, and more.

BT Misses Deadline for Removing Huawei From Network Core

03 January 2024
BT has failed to meet the extended deadline to remove Huawei equipment from its core networks, with only 2G and 3G services still being served by non-compliant infrastructure.

Steam Drops Support for Windows 7 and 8.1 to Boost Security

03 January 2024
The end of support for these older Windows versions is due to the reliance on an embedded version of Google Chrome that no longer functions on them, as well as the need for Windows feature and security updates only available on Windows 10 and above.

Facts and Misconceptions About Cybersecurity Budgets

03 January 2024
Despite increased cybersecurity budgets, there is a need for a further rise in spending to effectively mitigate security risks. Economic volatility, a growing distributed workforce, and supply chain issues are key factors influencing spending.

DOJ Slams XCast with $10 Million Fine Over Massive Illegal Robocall Operation

03 January 2024
The U.S. Department of Justice (DoJ) on Tuesday said it reached a settlement with VoIP service provider XCast over allegations that it facilitated illegal telemarketing campaigns since at least January 2018, in contravention of the Telemarketing Sales Rule (TSR). In addition to prohibiting the company from violating the law, the stipulated order requires it to meet other compliance measures,

Update: After Ransomware Claims, Xerox Says Subsidiary Hit With Cyberattack

03 January 2024
Xerox stated that the incident had no impact on its corporate systems, operations, or data, but limited personal information in the XBS environment may have been affected.

Australian Court Service Hacked, Hearing Recordings at Risk

02 January 2024
The Court Services Victoria (CSV) took immediate action to isolate and disable the affected network, but recordings from November 1 to December 21, 2023, may have been accessed.

Android Game Developer’s Google Drive Misconfiguration Leaks Information on Nearly One Million Users

02 January 2024
A simple Google Drive configuration mistake by Japanese game developer Ateam resulted in the potential exposure of sensitive information for nearly one million individuals, highlighting the importance of properly securing cloud services.

New Black Basta Decryptor Exploits Ransomware Flaw to Recover Files

02 January 2024
While the decryptor only works on older versions of Black Basta and has been patched in newer attacks, it provides hope for victims who were affected between November 2022 and the recent bug fix.

Inc Ransom Ransomware Gang Claims to Have Breached Xerox Corp

02 January 2024
The Inc Ransom ransomware group has published several documents, including emails and an invoice, as proof of the hack. It is unclear how much data has been stolen from Xerox Corp.

New Variant of DLL Search Order Hijacking Bypasses Windows 10 and 11 Protections

02 January 2024
The technique leverages executables in the trusted WinSxS folder, making it possible to run nefarious code without elevated privileges and introduce potentially vulnerable binaries into the attack chain.

Bunker Hill Community College announces data breach

02 January 2024
Bunker Hill Community College (BHCC) in Boston, Massachusetts experienced a data breach in May 2023 that included Social Security Numbers.

Zeppelin2 Ransomware Builder for Sale on Dark Web

02 January 2024
A user on an underground forum is promoting the sale of Zeppelin2 ransomware, offering its source code and a cracked version of its builder tool. Zeppelin2 has been used since 2019, targeting various sectors including healthcare and technology.

Cactus Ransomware Gang Hit the Swedish Retail and Grocery Provider Coop

02 January 2024
The Cactus ransomware group has claimed to have hacked Coop, one of the largest retail and grocery providers in Sweden. They are threatening to release a large amount of personal information.