Latest Cybersecurity News and Articles


Crypto Drainer Steals $59 Million From 63K People in Twitter Ad Push

23 December 2023
The MS Drainer operates through phishing websites, tricking users into approving malicious contracts and transferring their money to the attacker's wallet address without their consent.

Rogue WordPress Plugin Exposes E-Commerce Sites to Credit Card Theft

22 December 2023
Threat hunters have discovered a rogue WordPress plugin that's capable of creating bogus administrator users and injecting malicious JavaScript code to steal credit card information. The skimming activity is part of a Magecart campaign targeting e-commerce websites, according to Sucuri. "As with many other malicious or fake WordPress plugins it contains some deceptive information at

Android Banking Trojan Chameleon can Now Bypass Any Biometric Authentication

22 December 2023
The Chameleon banking trojan has evolved with new advanced features, including the ability to bypass biometric prompts and display HTML pages for enabling Accessibility Services on Android 13, making it a potent threat to mobile banking security.

Operation RusticWeb: Rust-Based Malware Targets Indian Government Entities

22 December 2023
Indian government entities and the defense sector have been targeted by a phishing campaign that's engineered to drop Rust-based malware for intelligence gathering. The activity, first detected in October 2023, has been codenamed Operation RusticWeb by enterprise security firm SEQRITE. "New Rust-based payloads and encrypted PowerShell commands have been utilized to exfiltrate

BidenCash Dark Web Marketplace Leaks 1.6 Million Credit Card Details

22 December 2023
Unlike a previous leak, this one does not include names or emails of cardholders. While the absence of names reduces the risk of identity theft, the leaked financial details still pose a significant risk for unauthorized transactions.

Decoy Microsoft Word Documents Used to Deliver Nim-Based Malware

22 December 2023
A new phishing campaign is leveraging decoy Microsoft Word documents as bait to deliver a backdoor written in the Nim programming language. "Malware written in uncommon programming languages puts the security community at a disadvantage as researchers and reverse engineers' unfamiliarity can hamper their investigation," Netskope researchers Ghanashyam Satpathy and Jan Michael Alcantara 

Iran’s Peach Sandstorm Group Deploys FalseFont Backdoor Against Defense Sector

22 December 2023
FalseFont is a custom backdoor with various capabilities that allow operators to remotely access compromised systems, execute files, and transmit information to Command and Control servers.

New Rules in UK Could Reimburse Fraud Victims up to £415,000 ($525,000)

22 December 2023
The UK's Payment Systems Regulator (PSR) announced that victims could be repaid up to £415,000 ($525,000) unless the bank can prove "gross negligence" on the part of the individual.

BattleRoyal Threat Cluster Spread DarkGate RAT via Email and Fake Browser Updates

22 December 2023
The BattleRoyal cluster, using DarkGate and NetSupport malware, demonstrates the use of multiple attack chains and social engineering techniques to deliver payloads via email and fake update lures.

Analysis: The Various Ways Malicious JavaScript can Steal Your Secrets

22 December 2023
Researchers from Unit 42 have discovered that threat actors are using malicious JavaScript to steal sensitive information by exploiting popular survey sites, low-quality hosting, and web chat APIs.

First American Takes IT Systems Offline After Cyberattack

22 December 2023
First American Financial Corporation, the second-largest title insurance company in the US, has experienced a cyberattack and has taken some systems offline to contain the impact.

CISA Seeks Comment on Secure by Design Principles to Boost Global Software Security

22 December 2023
The Biden administration is pushing for secure-by-design principles to be embraced by the tech industry, aiming to make security a core feature of software development to prevent attacks exploiting vulnerabilities.

MageCart WordPress Plugin Injects Malicious User & Credit Card Skimmer

22 December 2023
A recent analysis discovered a malicious plugin injected into a WordPress/WooCommerce website that creates a fake administrator user and injects credit card skimming JavaScript into the checkout page.

Cisco to Acquire Cloud-Native Networking and Security Startup Isovalent

22 December 2023
Isovalent has developed eBPF, an open-source technology that provides insight into the operating system layer, and Cilium, which offers visibility into cloud-native applications.

St Vincent’s Health Australia Says Data Stolen in Cyberattack

22 December 2023
St Vincent's, Australia's largest not-for-profit health and aged care provider, has confirmed that it has experienced a cyberattack and that hackers have stolen some of its data.

FTC Proposes Tougher Children’s Data Privacy Rules for First Time in a Decade

22 December 2023
The proposed changes to the Children's Online Privacy Protection Rule (COPPA) would hold service providers responsible for ensuring the safety of digital experiences for children, rather than relying solely on parents.

Kansas City-Area Hospital Transfers Patients, Reschedules Appointments After Cyberattack

22 December 2023
A hospital near Kansas City, Missouri, is facing disruptions in patient care due to a cyberattack on its IT systems. Some patients had to be transferred to other hospitals, and the hospital is actively investigating the source of the disruption.

These aren’t the Android phones you should be looking for

22 December 2023
Users should exercise caution when using third-party app stores or purchasing cheap devices from unknown brands, as they may be at a higher risk of malware and other security threats.

NIST Report Identifies Significant Privacy Gaps in Genomic Data Handling

22 December 2023
Breaches of genomic data not only pose risks to individuals but also have implications for their families, while sharing such data is crucial for research and development in the biotechnology field.

UAC-0099 Using WinRAR Exploit to Target Ukrainian Firms with LONEPAGE Malware

22 December 2023
The threat actor known as UAC-0099 has been linked to continued attacks aimed at Ukraine, some of which leverage a high-severity flaw in the WinRAR software to deliver a malware strain called LONEPAGE. "The threat actor targets Ukrainian employees working for companies outside of Ukraine," cybersecurity firm Deep Instinct said in a Thursday analysis. UAC-0099 was first