Latest Cybersecurity News and Articles
27 December 2023
The cybercrime group, DragonForce, has claimed responsibility for the attack and has leaked 95 GB of data belonging to the company. Yakult Australia is currently investigating the incident with the help of cybersecurity experts.
27 December 2023
A new zero-day security flaw has been discovered in the Apache OfBiz, an open-source Enterprise Resource Planning (ERP) system that could be exploited to bypass authentication protections.
The vulnerability, tracked as CVE-2023-51467, resides in the login functionality and is the result of an incomplete patch for another critical vulnerability (CVE-2023-49070, CVSS score: 9.8) that was
27 December 2023
The hacker group CyberAv3ngers claims to have obtained and is selling 1TB of data from Israel's electricity infrastructure. They posted a message on a platform offering the data for sale. The Israel Electric Corporation (IEC) has not yet responded.
27 December 2023
The cyberattack on Fidelity National Financial was claimed by the AlphV/Blackcat ransomware gang, causing disruption to hundreds of home purchases and leading to the seizure of the gang's leak site by law enforcement agencies.
27 December 2023
A Russian man accused by the United States of trafficking in a hacked database of online credentials will apparently evade American courts after the Russian government said it had succeeded in extraditing him.
27 December 2023
Barracuda Networks has discovered two zero-day vulnerabilities, known as CVE-2023-7102 and CVE-2023-7101, in its Barracuda Email Security Gateway Appliance (ESG) devices.
27 December 2023
GitHub is warning users that they must enable 2FA on their accounts or face limited functionality on the site. This requirement applies to users contributing code on GitHub and is aimed at protecting accounts from breaches and code alterations.
27 December 2023
The Rhysida ransomware group has claimed responsibility for hacking Abdali Hospital in Jordan. The group has published proof of the hack, including stolen documents, and is now auctioning off the sensitive data for 10 BTC.
27 December 2023
Barracuda has revealed that Chinese threat actors exploited a new zero-day in its Email Security Gateway (ESG) appliances to deploy backdoor on a "limited number" of devices.
Tracked as CVE-2023-7102, the issue relates to a case of arbitrary code execution that resides within a third-party and open-source library Spreadsheet::ParseExcel that's used by the Amavis scanner within the
27 December 2023
National Amusements, the parent company of Paramount and CBS, has confirmed a data breach in which hackers stole personal information from 82,128 people. The breach occurred in December 2022 but was only discovered in August 2023.
27 December 2023
EasyPark Group, the owner of brands including RingGo and ParkMobile, said customer names, phone numbers, addresses, email addresses, and parts of credit card numbers had been taken but said parking data had not been compromised in the cyberattack.
27 December 2023
Europol, along with law enforcement authorities from 17 countries and the European Union Agency for Cybersecurity (ENISA), has partnered with private sector companies to combat digital skimming attacks.
27 December 2023
Linux SSH servers with poor security are being targeted by cybercriminals to install port scanners and dictionary attack tools. The attackers aim to compromise other vulnerable servers and use them for cryptocurrency mining and DDoS attacks.
27 December 2023
A new Android backdoor has been discovered with potent capabilities to carry out a range of malicious actions on infected devices.
Dubbed Xamalicious by the McAfee Mobile Research Team, the malware is so named for the fact that it's developed using an open-source mobile app framework called Xamarin and abuses the operating system's accessibility permissions to fulfill its objectives.
27 December 2023
The LockBit ransomware group has targeted Xeinadin, an accountancy firm with over 60,000 clients, and threatens to leak 1.5 terabytes of stolen customer data if not contacted by the company.
27 December 2023
President Joe Biden has signed a short-term extension of surveillance efforts authorized under Section 702 of the FISA. The extension, which will keep digital snooping programs running until April 19, was included in the $886 billion NDAA.
27 December 2023
Nissan is still investigating the cyberattack and working to restore affected systems in Australia and New Zealand, while also notifying authorities and warning customers to be vigilant for suspicious online activity.
27 December 2023
Poorly secured Linux SSH servers are being targeted by bad actors to install port scanners and dictionary attack tools with the goal of targeting other vulnerable servers and co-opting them into a network to carry out cryptocurrency mining and distributed denial-of-service (DDoS) attacks.
"Threat actors can also choose to install only scanners and sell the breached IP and account credentials on
26 December 2023
The vulnerabilities range from denial of service risks to arbitrary code execution possibilities. It emphasizes the importance of regularly updating Vim and applying security patches to mitigate these risks.
26 December 2023
The breach exposed customers' names, phone numbers, email addresses, SIM serial numbers, IMEI numbers, and service plan information. Importantly, financial data and passwords were not exposed in the breach.