Latest Cybersecurity News and Articles
28 December 2023
The scam involved the developer downloading npm packages from a GitHub repository, which potentially allowed the attackers to gain access to his machine and drain his wallet.
28 December 2023
The malware is sold as a service and can be obtained through malvertising, fake browser updates, and cracked software installations. It has also been found that the malware is being spread through Discord's content delivery network.
28 December 2023
Google Cloud has addressed a medium-severity security flaw in its platform that could be abused by an attacker who already has access to a Kubernetes cluster to escalate their privileges.
"An attacker who has compromised the Fluent Bit logging container could combine that access with high privileges required by Anthos Service Mesh (on clusters that have enabled it) to
28 December 2023
The National Insurance Board in Trinidad and Tobago has been hit by a ransomware attack, leading to the closure of its offices and limiting its operations for an extended period.
28 December 2023
The attack occurred on December 24, 2023, and caused severe disruptions to the hospitals' IT systems. Investigations are underway to determine the extent of the damage and whether any data was stolen.
28 December 2023
The Albanian parliament and a telecom company were targeted by cyberattacks originating from outside Albania. The attacks, which attempted to interfere with infrastructure and delete data, have not been attributed to a specific threat actor.
28 December 2023
The Operation Triangulation spyware attacks targeting Apple iOS devices leveraged never-before-seen exploits that made it possible to even bypass pivotal hardware-based security protections erected by the company.
Russian cybersecurity firm Kaspersky, which discovered the campaign at the beginning of 2023 after becoming one of the targets, described it as
28 December 2023
The newly surfaced DragonForce ransomware gang has claimed responsibility for the attack, stating that they have encrypted devices and stolen data, including personal information of Ohio Lottery customers and employees.
28 December 2023
The secret hardware function targeted by the attackers allowed them to bypass advanced memory protections, enabling post-exploitation techniques and compromising system integrity.
28 December 2023
SE Labs has warned that multi-factor authentication (MFA) is not foolproof and can be bypassed by attackers using old-school methods such as social engineering, malware, and phishing.
28 December 2023
The breached information includes names, contact details, dates of birth, medical and health insurance information, financial account numbers, employment status, and government identifiers.
28 December 2023
Companies need to shift their focus from solely addressing threats to proactively mitigating risks by analyzing behaviors and implementing insider risk management solutions.
28 December 2023
DDoS attacks have significant consequences, including financial losses, compromised data, and erosion of customer trust. Global events like the Russia-Ukraine war and NATO bids have fueled recent DDoS attack growth.
28 December 2023
The flaw, tracked as CVE-2023-51467, is a result of an incomplete patch for another critical vulnerability (CVE-2023-49070) and allows attackers to achieve a simple Server-Side Request Forgery (SSRF) to access unauthorized internal resources.
28 December 2023
The breach was confirmed by the Iranian Leakage Tracking System, and the targeted company, Fanavaran, has since blocked access to its website in the aftermath of the incident.
28 December 2023
A new malware loader is being used by threat actors to deliver a wide range of information stealers such as Lumma Stealer (aka LummaC2), Vidar, RecordBreaker (aka Raccoon Stealer V2), and Rescoms.
Cybersecurity firm ESET is tracking the trojan under the name Win/TrojanDownloader.Rugmi.
"This malware is a loader with three types of components: a downloader that downloads an
27 December 2023
Integris Health, Oklahoma's largest healthcare network, suffered a cyberattack resulting in the theft of patient data, and now patients are receiving blackmail emails threatening to sell their data if they don't pay an extortion demand.
27 December 2023
HealthEC, a population health management platform that provides services to Corewell Health, is the company involved in the breach, which may have compromised sensitive data such as names, addresses, SSNs, and medical records.
27 December 2023
The PowerShell script uses a technique developed by a researcher in 2022, which involves patching the Windows Defender registered DLL for AMSI with a shellcode to overwrite the function that scans PowerShell scripts.
27 December 2023
The cybercrime group, DragonForce, has claimed responsibility for the attack and has leaked 95 GB of data belonging to the company. Yakult Australia is currently investigating the incident with the help of cybersecurity experts.