Latest Cybersecurity News and Articles


Mend.io Acquires Cyber Startup Atom Security

26 December 2023
The integration of Atom Security's technology into Mend.io's product line is expected to enhance coverage and reduce the number of irrelevant findings in code vulnerabilities.

Video Game Giant Ubisoft Investigates Reports of a Data Breach

26 December 2023
On December 20, an unknown threat actor had access to Ubisoft's infrastructure for 48 hours. The attackers attempted to steal user data from the game R6 Siege but were unsuccessful.

Update: GTA 5 Source Code Reportedly Leaked Online a Year After Rockstar Hack

26 December 2023
The source code for Grand Theft Auto 5 (GTA 5) has reportedly been leaked. This comes over a year after the Lapsus$ hacking group hacked Rockstar Games and stole company data.

Hackers steal customer data from Europe’s largest parking app operator

26 December 2023
Hackers steal customer data from Europe’s largest parking app operator Owner of RingGo and ParkMobile says data including parts of credit card numbers taken in cyber-attackEurope’s largest parking app operator has reported itself to information regulators in the EU and UK after hackers stole customer data.EasyPark Group, the owner of brands including RingGo and ParkMobile, said customer names, phone numbers, addresses, email addresses and parts of credit card numbers had been taken but said parking data had not been compromised in the cyber-attack. Continue reading...

Carbanak Banking Malware Resurfaces with New Ransomware Tactics

26 December 2023
The banking malware Carbanak has been observed in ransomware attacks with updated tactics. It has adapted to incorporate new attack vendors and techniques, making it more effective.

Stealth Android Backdoor Xamalicious Found Actively Infecting Devices

26 December 2023
The Xamalicious backdoor, implemented with Xamarin, targets Android devices by gaining accessibility privileges and communicating with a C2 server to download a second-stage payload, potentially enabling fraudulent actions without user consent.

Nim-based Malware Distributed Using Microsoft Word Docs Impersonating the Nepali Government

26 December 2023
The Nim-based backdoor communicates with command and control servers, evades analysis tools, and establishes persistence on the compromised machine through startup folders and scheduled tasks.

Operation RusticWeb Targets Indian Government Entities With Rust-Based Malware

26 December 2023
The phishing emails trick victims into interacting with malicious PDF files that drop Rust-based payloads or PowerShell scripts, enabling the collection of confidential documents and system information.

The Rising Threat of Phishing Attacks with Crypto Drainers

26 December 2023
The "Angel Drainer" phishing group is notorious for draining cryptocurrency wallets through sophisticated schemes, charging a percentage of the stolen amount from hackers.

Carbanak Banking Malware Resurfaces with New Ransomware Tactics

26 December 2023
The banking malware known as Carbanak has been observed being used in ransomware attacks with updated tactics. "The malware has adapted to incorporate attack vendors and techniques to diversify its effectiveness," cybersecurity firm NCC Group said in an analysis of ransomware attacks that took place in November 2023. "Carbanak returned last month through new

Cloud Atlas' Spear-Phishing Attacks Target Russian Agro and Research Companies

25 December 2023
The threat actor referred to as Cloud Atlas has been linked to a set of spear-phishing attacks on Russian enterprises. Targets included a Russian agro-industrial enterprise and a state-owned research company, according to a report from F.A.C.C.T., a standalone cybersecurity company formed after Group-IB's formal exit from Russia earlier this year. Cloud Atlas, active since at

British LAPSUS$ Teen Members Sentenced for High-Profile Attacks

24 December 2023
Two British teens part of the LAPSUS$ cyber crime and extortion gang have been sentenced for their roles in orchestrating a string of high-profile attacks against a number of companies. Arion Kurtaj, an 18-year-old from Oxford, has been sentenced to an indefinite hospital order due to his intent to get back to cybercrime "as soon as possible," BBC reported. Kurtaj, who is autistic, was

UAC-0099 Using WinRAR Exploit to Target Ukrainian Firms with LONEPAGE Malware

23 December 2023
The LONEPAGE malware, deployed through phishing messages and malicious attachments, can contact a command-and-control server to retrieve additional payloads and carry out activities like keylogging and stealing screenshots.

ESET Fixed a High-Severity Bug in the Secure Traffic Scanning Feature of Several Products

23 December 2023
The vulnerability was due to improper validation of server certificates, allowing browsers to trust sites with certificates signed with outdated algorithms. ESET has released security patches and is not aware of any attacks exploiting this flaw.

Real Estate Agency Exposes Details of 690K Customers in Dubai

23 December 2023
The leaked data included personal information such as names, emails, phone numbers, and scanned copies of receipts, checks, contracts, and IDs, increasing the likelihood of targeted scams and unauthorized access to sensitive accounts.

Bandook - A Persistent Threat That Keeps Evolving

23 December 2023
Bandook malware, a remote access trojan, has evolved with a new variant that uses a PDF file to distribute its payload and injects it into msinfo32.exe, allowing remote attackers to gain control of infected systems.

Experts Detail Multi-Million Dollar Licensing Model of Predator Spyware

23 December 2023
A new analysis of the Predator spyware reveals that it now has the ability to persist between reboots on infected Android systems. Predator, developed by the Intellexa Alliance, is a sophisticated commercial spyware sold on a licensing model.

Ukrainian Hackers Claim Attack on Popular Russian CRM Provider

23 December 2023
A group of Ukrainian hackers known as the IT Army claimed responsibility for disrupting the operations of Bitrix24, a Russian provider of customer relationship management (CRM) services.

Online Platform Carousell Violated Hong Kong Privacy Laws, Watchdog Finds

23 December 2023
The violation comes after the personal data of over 320,000 local users was discovered being sold on the dark web. Carousell reported the incident last year, attributing it to a loophole exploited by hackers in its system migration process.

Cyber-Espionage Group Cloud Atlas Targets Russian Companies With War-Related Phishing Attacks

23 December 2023
The hacker group known as Cloud Atlas has recently targeted a Russian agro-industrial enterprise and a state-owned research company in an espionage campaign. The group, believed to be state-backed, primarily attacks Russia and surrounding countries.