Latest Cybersecurity News and Articles


Healthcare Software Provider Suffers Data Breach Impacting 2.7 Million Patients

21 December 2023
The attack occurred on September 28 and resulted in data being stolen before the hackers encrypted company systems. The breach impacted patients associated with ESO's customers, including hospitals and clinics in the US.

Data Leak at Real Estate Wealth Network Exposes 1.5 Billion Ownership Records

21 December 2023
The leaked data, which included information on property history, tax records, and mortgage details, could be exploited by threat actors for social engineering and financial fraud.

Cost of a Data Breach Report 2023: Insights, Mitigators and Best Practices

21 December 2023
John Hanley of IBM Security shares 4 key findings from the highly acclaimed annual Cost of a Data Breach Report 2023 What is the IBM Cost of a Data Breach Report? The IBM Cost of a Data Breach Report is an annual report that provides organizations with quantifiable information about the financial impacts of breaches. With this data, they can make data driven decisions about how they implement

German Authorities Dismantle Dark Web Hub 'Kingdom Market' in Global Operation

21 December 2023
German law enforcement has announced the disruption of a dark web platform called Kingdom Market that specialized in the sales of narcotics and malware to "tens of thousands of users." The exercise, which involved collaboration from authorities from the U.S., Switzerland, Moldova, and Ukraine, began on December 16, 2023, the Federal Criminal Police Office (BKA) said. Kingdom

Indian Banking Customers Targeted by Phishing Campaign Distributing Trojan as Fake Verification Tool

21 December 2023
The trojan is distributed through WhatsApp messages, prompting users to download an APK for a mandatory verification procedure. Once installed, it collects personal and financial information and intercepts SMS messages to steal verification codes.

German Police Seized the Dark Web Marketplace Kingdom Market

21 December 2023
The German police, along with international law enforcement agencies, have seized the dark web marketplace Kingdom Market, which offered drugs, malware, stolen data, and forged documents.

Crypto Scammers Abuse Twitter ‘Feature’ to Impersonate High-Profile Accounts

21 December 2023
The scam tweets often appear to be from well-known crypto accounts like Binance and Ethereum, but they lead to unrelated users promoting fake giveaways, wallet-draining websites, and pump-and-dump schemes.

The Impact of Prompt Injection in LLM Agents

21 December 2023
Prompt injection poses a significant threat to LLM integrity, especially when LLM-powered agents interact with external systems, and safeguarding their operations requires meticulous attention to confidentiality levels and access controls.

Mozilla Patches Firefox Vulnerability Allowing Remote Code Execution, Sandbox Escape

21 December 2023
The security updates for Firefox 121 include patches for critical vulnerabilities like a heap buffer overflow bug in WebGL and a side-channel attack vulnerability in Network Security Services (NSS) NIST curves.

SimSpace raises $45M to simulate tech stacks for cyber training

21 December 2023
Cybersecurity training startup SimSpace has raised $45 million in a funding round led by L2 Point Management, bringing its total raised to $70 million. It creates digital replicas of organizations' tech and networking stacks for training purposes.

Hackers Exploiting Old MS Excel Vulnerability to Spread Agent Tesla Malware

21 December 2023
Attackers are weaponizing an old Microsoft Office vulnerability as part of phishing campaigns to distribute a strain of malware called Agent Tesla. The infection chains leverage decoy Excel documents attached in invoice-themed messages to trick potential targets into opening them and activate the exploitation of CVE-2017-11882 (CVSS score: 7.8), a memory corruption vulnerability in Office's

Behind the Scenes of Matveev's Ransomware Empire: Tactics and Team

21 December 2023
Matveev and his team demonstrate a significant disregard for ethical values in their cyber operations, engaging in tactics such as threatening to leak sensitive files and retaining files even after the ransom is paid.

Urgent: New Chrome Zero-Day Vulnerability Exploited in the Wild - Update ASAP

20 December 2023
Google has rolled out security updates for the Chrome web browser to address a high-severity zero-day flaw that it said has been exploited in the wild. The vulnerability, assigned the CVE identifier CVE-2023-7024, has been described as a heap-based buffer overflow bug in the WebRTC framework that could be exploited to result in program crashes or arbitrary code execution. Clément

FTC bans Rite Aid from using AI facial recognition

20 December 2023
The Federal Trade Commission (FTC) banned Rite Aid from using facial recognition technology for surveillance purposes for the next five years.

Malware Leveraging Public Infrastructure Like GitGub on the Rise

20 December 2023
Public services like GitHub provide a convenient and less suspicious platform for malware authors to operate their C2 infrastructure, eliminating the need for maintaining their own servers.

Decrypting the Sidewinder Cyber Intrusion Tactics

20 December 2023
The Sidewinder group, a sophisticated APT group originating from South Asia, is behind a highly targeted cyber threat campaign involving a malicious Word document with an embedded macro, potentially targeting Nepalese government officials.

Update: Israel Blames Iran for Hospital Data Breach

20 December 2023
Israel has identified Iran and Hezbollah as the perpetrators of a cyberattack on the Ziv Medical Center. The attack, which occurred last month, resulted in the theft of 500GB of medical data.

Top cybersecurity predictions of 2024

20 December 2023
As another year comes to a close, cybersecurity leaders are not only looking back and reviewing the top trends of 2023, but considering what the future holds for 2024.

Global Law Enforcement Seizes $300 Million, Arrests 3,500 Involved in Transnational Cybercrime Operation

20 December 2023
The operation targeted various online scams, including voice phishing, romance scams, investment fraud, and e-commerce fraud, highlighting the significant financial incentives driving the growth of organized cybercrime.

Global Malspam Targets Hotels, Spreading Redline and Vidar Stealers

20 December 2023
The hospitality industry is being targeted by a sophisticated malspam campaign that uses social engineering tactics to trick hotel representatives into opening password-protected archives containing malware.