Latest Cybersecurity News and Articles


Newfound School District Still Working to Recover Data After Cyberattack

18 December 2023
Newfound Area School District in Bristol, New Hampshire, is recovering from a recent cyber breach that was described as a ransomware attack. The attack locked users out of the system, but no financial demand was made.

Employee Files Compromised After Ransomware Attack on Campbell County School District

18 December 2023
The Campbell County School District announced Thursday that it was recently the target of a ransomware incident that allowed an unauthorized person to gain access to employee files.

CISA Urges Manufacturers Eliminate Default Passwords to Thwart Cyber Threats

18 December 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is urging manufacturers to get rid of default passwords on internet-exposed systems altogether, citing severe risks that could be exploited by malicious actors to gain initial access to, and move laterally within, organizations. In an alert published last week, the agency called out Iranian threat actors affiliated with

MongoDB Suffers Security Breach, Exposing Customer Data

16 December 2023
MongoDB on Saturday disclosed it's actively investigating a security incident that has led to unauthorized access to "certain" corporate systems, resulting in the exposure of customer account metadata and contact information. The American database software company said it first detected anomalous activity on December 13, 2023, and that it immediately activated its incident response

Central Bank of Lesotho Facing Outages After Cyberattack

16 December 2023
The ongoing downtime of the National Payments System has made it impossible for local banks in Lesotho to honor inter-bank transactions, requiring alternative measures to facilitate payments.

China's MIIT Introduces Color-Coded Action Plan for Data Security Incidents

16 December 2023
China's Ministry of Industry and Information Technology (MIIT) on Friday unveiled draft proposals detailing its plans to tackle data security events in the country using a color-coded system. The effort is designed to "improve the comprehensive response capacity for data security incidents, to ensure timely and effective control, mitigation and elimination of hazards and losses caused

Ontario Public Library Shuts Down Most Services Due to Cyberattack

16 December 2023
The attack on the library, along with recent ransomware incidents at other major libraries, underscores the need for improved cybersecurity measures and data protection in the library sector.

Delta Dental of California Data Breach Exposed Info of Seven Million People

16 December 2023
Delta Dental of California and its affiliates have suffered a data breach, affecting almost seven million patients. The breach occurred through a vulnerability in the MOVEit Transfer software, allowing unauthorized access by threat actors.

PikaBot Distributed via Malicious Search Ads

16 December 2023
Threat actors are bypassing Google's security measures and using fingerprinting techniques to ensure successful execution of malicious downloads, pointing to a potential "malvertising as a service" model.

New NKAbuse Malware Exploits NKN Blockchain Tech for DDoS Attacks

16 December 2023
Researchers have discovered a new multi-platform threat called NKAbuse that uses a decentralized network connectivity protocol called NKN to communicate. NKAbuse leverages blockchain technology to conduct DDoS attacks and function as an implant.

Microsoft Warns of Storm-0539: The Rising Threat Behind Holiday Gift Card Frauds

16 December 2023
Microsoft is warning of an uptick in malicious activity from an emerging threat cluster it's tracking as Storm-0539 for orchestrating gift card fraud and theft via highly sophisticated email and SMS phishing attacks against retail entities during the holiday shopping season. The goal of the attacks is to propagate booby-trapped links that direct victims to adversary-in-the-middle (AiTM

UTSA names David Brown as next NSCC executive director

15 December 2023
The University of Texas at San Antonio has announced David Brown as the new executive director of its National Security Collaboration Center (NSCC) and professor of practice.

Researchers Detect Undocumented 8220 Gang Activities

15 December 2023
The 8220 gang, a Chinese-origin threat actor, continues to target Windows and Linux web servers with cryptojacking malware using evolving tactics and known vulnerabilities.

Ledger dApp Supply Chain Attack Steals $600K From Crypto Wallets

15 December 2023
Ledger users are advised to avoid using web3 dApps following a supply chain attack on the Ledger dApp Connect Kit library, which resulted in the theft of $600,000 worth of crypto and NFTs.

ALPHV Ransomware Gang Returns, Sorta

15 December 2023
The ALPHV ransomware gang is facing technical difficulties, with their leak site showing only one victim and negotiation links not working, potentially leaving them without payment.

Ten New Android Banking Trojans Targeted 985 Bank Apps in 2023

15 December 2023
The emergence of ten new Android banking malware families in 2023 highlights the increasing sophistication and capabilities of these trojans, including automated transfer systems, social engineering tactics, and live screen-sharing capabilities.

Data of Over a Million Users of the Crypto Exchange GokuMarket Exposed

15 December 2023
The centralized crypto exchange GokuMarket, owned by ByteX, left an open instance, exposing sensitive user data, including IP addresses, email addresses, encrypted passwords, and crypto wallet addresses.

New KV-Botnet Targeting Cisco, DrayTek, and Fortinet Devices for Stealthy Attacks

15 December 2023
A new botnet consisting of firewalls and routers from Cisco, DrayTek, Fortinet, and NETGEAR is being used as a covert data transfer network for advanced persistent threat actors, including the China-linked threat actor called Volt Typhoon. Dubbed KV-botnet by the Black Lotus Labs team at Lumen Technologies, the malicious network is an amalgamation of two complementary activity

BianLian, White Rabbit, and Mario Ransomware Gangs Spotted in a Joint Extortion Campaign

15 December 2023
The ransomware gangs utilized a "password spraying" attack and compromised email accounts through Business Email Compromise (BEC) to anonymously deliver ransom payment demands and complicate investigations.

Four Charged in Connection With $80m Pig Butchering Scheme

15 December 2023
The fraudsters used shell companies and bank accounts to launder the proceeds of pig butchering scams, where victims were lured into cryptocurrency investment schemes and deceived into transferring funds to the scammers.