Latest Cybersecurity News and Articles
02 January 2024
The Cactus ransomware group has claimed to have hacked Coop, one of the largest retail and grocery providers in Sweden. They are threatening to release a large amount of personal information.
02 January 2024
The United Kingdom's Radioactive Waste Management (RWM) company recently experienced a cyberattack attempt through LinkedIn. Although the attack was unsuccessful, concerns have been raised about the security of critical nuclear infrastructure.
02 January 2024
Multiple information-stealing malware families are exploiting an undocumented Google OAuth endpoint called "MultiLogin" to restore expired authentication cookies and gain unauthorized access to users' accounts.
02 January 2024
Pro-Palestinian hackers belonging to the group Cyber Toufan have successfully breached and leaked data from numerous Israeli entities, including foreign companies doing business with Israel.
02 January 2024
The Pentagon has provided new cost estimates for implementing its Cybersecurity Maturity Model Certification program, with projected costs totaling around $4 billion for contractors and other non-government entities over a 20-year period.
02 January 2024
TuneFab converter, a tool used to convert copyrighted music from streaming platforms, exposed over 151 million records of users' private data due to a misconfiguration on MongoDB.
02 January 2024
Google has agreed to settle a $5 billion privacy lawsuit that accused the company of collecting personal data from users even when they were in "private browsing mode" on its Chrome browser.
02 January 2024
This updated version of Meduza Stealer includes support for more software clients, an upgraded credit card grabber, and improved mechanisms for storing and extracting credentials and tokens.
02 January 2024
Security stakeholders have come to realize that the prominent role the browser has in the modern corporate environment requires a re-evaluation of how it is managed and protected. While not long-ago web-borne risks were still addressed by a patchwork of endpoint, network, and cloud solutions, it is now clear that the partial protection these solutions provided is no longer sufficient. Therefore,
02 January 2024
Google has agreed to settle a lawsuit filed in June 2020 that alleged that the company misled users by tracking their surfing activity who thought that their internet use remained private when using the “incognito” or “private” mode on web browsers.
The class-action lawsuit sought at least $5 billion in damages. The settlement terms were not disclosed.
The plaintiffs had
02 January 2024
The integration of Talon's Enterprise Browser with Prisma SASE will provide enhanced data protection for users across all applications and devices, addressing the security risks posed by web browsing on unmanaged devices.
02 January 2024
A third-party app called Clash Base Designer Easy Copy, which is used by Clash of Clans players to create custom base layouts, exposed its Firebase database and user-sensitive information. The app has over 100,000 downloads on the Google Play store.
02 January 2024
Two New York hospitals are seeking a court order to retrieve stolen data stored on a cloud storage company's servers after a ransomware attack. The stolen data includes sensitive information such as patients' personal and health information.
02 January 2024
On Christmas Eve, multiple threat actors released substantial data leaks, potentially causing significant financial damage and adverse effects such as identity theft and fraud globally.
02 January 2024
A dual privilege escalation chain in Google Kubernetes Engine (GKE) and Anthos Service Mesh (ASM) allowed attackers to gain complete control over Kubernetes clusters, highlighting the importance of regular updates and proactive security measures.
02 January 2024
The malware is distributed through phishing emails impersonating Abu Dhabi National Oil Company (ADNOC) and drops the JinxLoader executable upon opening password-protected RAR archive attachments.
01 January 2024

Court Service Victoria says it will notify those captured on recordings of hearings of the breachVictoria’s court system has been hit by a cyber-attack, with hackers accessing several weeks of recorded court and tribunal hearings.Court Services Victoria (CSV) was first made aware of the attack on 21 December but it is believed the audio-visual technology network was first compromised on 1 November. Continue reading...
01 January 2024
Security researchers have detailed a new variant of a dynamic link library (DLL) search order hijacking technique that could be used by threat actors to bypass security mechanisms and achieve execution of malicious code on systems running Microsoft Windows 10 and Windows 11.
The approach "leverages executables commonly found in the trusted WinSxS folder and exploits them via the classic DLL
01 January 2024
Security researchers from Ruhr University Bochum have discovered a vulnerability in the Secure Shell (SSH) cryptographic network protocol that could allow an attacker to downgrade the connection's security by breaking the integrity of the secure channel.
Called Terrapin (CVE-2023-48795, CVSS score: 5.9), the exploit has been described as the "first ever practically exploitable prefix
01 January 2024
A new Go-based malware loader called JinxLoader is being used by threat actors to deliver next-stage payloads such as Formbook and its successor XLoader.
The disclosure comes from cybersecurity firms Palo Alto Networks Unit 42 and Symantec, both of which highlighted multi-step attack sequences that led to the deployment of JinxLoader through phishing attacks.
"The