Latest Cybersecurity News and Articles


Beware: Scam-as-a-Service Aiding Cybercriminals in Crypto Wallet-Draining Attacks

30 December 2023
Cybersecurity researchers are warning about an increase in phishing attacks that are capable of draining cryptocurrency wallets. "These threats are unique in their approach, targeting a wide range of blockchain networks, from Ethereum and Binance Smart Chain to Polygon, Avalanche, and almost 20 other networks by using a crypto wallet-draining technique," Check Point researchers Oded Vanunu,

Info-Stealing Malware Now Includes Google Session Hijacking

30 December 2023
Multiple malware-as-a-service info stealers now have the ability to manipulate authentication tokens to gain persistent access to a victim's Google account, even after the user has reset their password.

Kimsuky Hackers Deploying AppleSeed, Meterpreter, and TinyNuke in Latest Attacks

29 December 2023
The North Korean Kimsuky APT has recently been observed using a new variant called AlphaSeed, written in Golang, which uses chromedp for communication with the command-and-control server.

Happy 14th Birthday, KrebsOnSecurity!

29 December 2023
KrebsOnSecurity celebrates its 14th year of existence today! I promised myself this post wouldn't devolve into yet another Cybersecurity Year in Review. Nor do I wish to hold forth about whatever cyber horrors may await us in 2024. But I do want to thank you all for your continued readership, encouragement and support, without which I could not do what I do.

DataNet Systems suffers data breach

29 December 2023
DataNet Systems gas announced that the company experienced a data breach affecting District of Columbia (D.C.) voters, including email addresses.

Albanian Parliament and One Albania Telecom Hit by Cyber Attacks

29 December 2023
The Assembly of the Republic of Albania and telecom company One Albania have been targeted by cyber attacks, the country’s National Authority for Electronic Certification and Cyber Security (AKCESK) revealed this week. “These infrastructures, under the legislation in force, are not currently classified as critical or important information infrastructure,” AKCESK said. One Albania, which has

Computer Systems at Massachusetts-Based Anna Jaques Hospital Compromised After Cyberattack

29 December 2023
Anna Jaques Hospital's health record system was shut down due to a cyberattack, causing delays in receiving services and diverting ambulance arrivals. The hospital is working with cybersecurity professionals to investigate the attack.

New data reveals the states at highest risk of cybercrime

29 December 2023
According to new data, residents of Nevada face a greater susceptibility to cyberattacks compared to those in all other states. 

With Car Privacy Concerns Rising, Automakers May Be on Road to Regulation

29 December 2023
Regulators, particularly the California Privacy Protection Agency and the Federal Trade Commission, are starting to investigate and potentially take action against connected vehicle manufacturers for privacy violations.

Russian Military Hackers Target Ukraine With New MASEPIE Malware

29 December 2023
The CERT-UA has issued a warning about a new phishing campaign orchestrated by Russian hackers known as APT28. The campaign targeted Ukraine between December 15 and 25, 2023, using phishing emails that tricked recipients into clicking on a link.

Google to Settle Class Action Lawsuit Alleging Incognito Mode Does Not Protect User Privacy

29 December 2023
Google has reached a preliminary settlement in a class-action lawsuit accusing the company of deceiving users about their privacy while using the Incognito mode. The settlement comes after a nearly four-year legal battle.

Game Mod on Steam Breached to Push Password-Stealing Malware

29 December 2023
The Downfall fan expansion for the game Slay the Spire was breached on Christmas Day, distributing the Epsilon information stealer malware through the Steam update system.

Eagers Automotive Halts Stock Trading in Response to Cyberattack

29 December 2023
The extent of the cyber incident is still being determined, but external experts have been engaged to investigate, raising concerns about a potential data breach and exposure of sensitive financial information.

CERT-UA Uncovers New Malware Wave Distributing OCEANMAP, MASEPIE, STEELHOOK

29 December 2023
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new phishing campaign orchestrated by the Russia-linked APT28 group to deploy previously undocumented malware such as OCEANMAP, MASEPIE, and STEELHOOK to harvest sensitive information. The activity, which was detected by the agency between December 15 and 25, 2023, targets government entities

Update: Operational Halt at First American Financial Corporation, Subsidiary After Cyberattack

29 December 2023
The company is working to restore its operations and has notified regulatory authorities. Despite the disruption, the company is still able to close loans and accept payments.

Kimsuky Hackers Deploying AppleSeed, Meterpreter, and TinyNuke in Latest Attacks

29 December 2023
Nation-state actors affiliated to North Korea have been observed using spear-phishing attacks to deliver an assortment of backdoors and tools such as AppleSeed, Meterpreter, and TinyNuke to seize control of compromised machines. South Korea-based cybersecurity company AhnLab attributed the activity to an advanced persistent threat group known as Kimsuky. “A notable point about attacks that

Microsoft Disables MSIX App Installer Protocol Widely Used in Malware Attacks

29 December 2023
Multiple financially motivated hacking groups have been observed using the App Installer service as an entry point for ransomware attacks, leveraging signed malicious MSIX app packages distributed via Microsoft Teams and malicious search engine ads.

Do the Casino Ransomware Attacks Make the Case to Pay?

29 December 2023
Experts caution that the decision to pay or not pay depends on various factors, including the type of data compromised, the availability of backups, the financial impact on the organization, and the sector in which the company operates.

Update: Kroll Reveals FTX Customer Info Exposed in August Data Breach

29 December 2023
The August data breach at Kroll exposed personal information of FTX bankruptcy claimants, including coin holdings and balances, making them potential targets for threat actors in the cryptocurrency market.

Microsoft Disables MSIX App Installer Protocol Widely Used in Malware Attacks

29 December 2023
Microsoft on Thursday said it’s once again disabling the ms-appinstaller protocol handler by default following its abuse by multiple threat actors to distribute malware. “The observed threat actor activity abuses the current implementation of the ms-appinstaller protocol handler as an access vector for malware that may lead to ransomware distribution,” the Microsoft Threat Intelligence