Latest Cybersecurity News and Articles
15 December 2023
The discovery of the new updated Pierogi++ malware suggests that the group is continuously refining its tactics and tools to maintain persistent access to targeted networks.
15 December 2023
Crypto hardware wallet maker Ledger published a new version of its "@ledgerhq/connect-kit" npm module after unidentified threat actors pushed malicious code that led to the theft of more than $600,000 in virtual assets.
The compromise was the result of a former employee falling victim to a phishing attack, the company said in a statement.
This allowed the attackers to gain
15 December 2023
Under the current proposals, datacenter providers would have a “duty to take appropriate and proportionate technical and organizational measures” to manage security and resilience risk.
15 December 2023
The global perma-crisis is set to continue to take its toll in 2024, as extreme weather events continue to impact organizations and global instability deepens.
15 December 2023
Kraft Heinz is investigating claims of a data breach by the Snatch ransomware gang, but currently sees no evidence of a broader attack or adverse effects on its internal systems.
15 December 2023
The settlement requires the company to implement data retention policies, use multifactor authentication, encrypt private information, and have a Chief Information Security Officer (CISO) reporting to the CEO regularly.
15 December 2023
The downloaders named ODAgent, OilCheck, and OilBooster, along with an updated version of SampleCheck5000, were used to blend with authentic network traffic and cover up the group's attack infrastructure.
15 December 2023
Approval phishing scams have been used to steal at least $1bn in crypto since May 2021, as per a new report by Chainalysis. This technique, frequently used by romance scammers, is estimated to have led to losses of at least $374m so far in 2023.
15 December 2023
Web Application Security consists of a myriad of security controls that ensure that a web application:
Functions as expected.
Cannot be exploited to operate out of bounds.
Cannot initiate operations that it is not supposed to do.
Web Applications have become ubiquitous after the expansion of Web 2.0, which Social Media Platforms, E-Commerce websites, and email clients saturating the internet
15 December 2023
Multiple security vulnerabilities have been discovered in the open-source Netgate pfSense firewall solution called pfSense that could be chained by an attacker to execute arbitrary commands on susceptible appliances.
The issues relate to two reflected cross-site scripting (XSS) bugs and one command injection flaw, according to new findings from Sonar.
"Security inside a local network is often
15 December 2023
The attackers have gained access to sensitive data, including employee records, law enforcement videos, emails, and confidential documents. The City of Defiance has not yet responded to the incident.
15 December 2023
Threat actors are increasingly using vulnerability exploitation instead of phishing emails to compromise victims with ransomware, according to insurance company Corvus Insurance.
15 December 2023
Despite increased monitoring, getting supply chain vendors to address security issues in a timely manner remains a challenge, with only 19% of respondents actively working with their suppliers to remediate issues, according to BlueVoyant.
15 December 2023
The Russia-based actor is targeting organisations and individuals in the UK and other geographical areas of interest.
15 December 2023
Despite a patch being issued, the exploitation of CitrixBleed has continued, highlighting the challenges of vendor security management and the need for organizations to take immediate action to mitigate the vulnerability.
15 December 2023
The IT network of New York-based health providers, including HealthAlliance Hospital, Margaretville Hospital, and Mountainside Residential Care Center, was breached for nearly two months, resulting in the compromise of patient data.
15 December 2023
The Federal Communications Commission (FCC) has updated its data breach rules for the first time in 16 years. The new rules expand the definition of a breach and specify who should be notified.
15 December 2023
Karakurt uses various tactics to steal data and extort victims for ransom. They contact victims' employees, business partners, and clients to pressure them into paying the ransom.
15 December 2023
Wyoming LLCs are being implicated in high-profile hacking activities, attracting cybercriminals due to the state's easy registration process for anonymous shell companies.
15 December 2023
MITRE has launched EMB3D, a new threat model framework to help defenders protect operational technology and industrial control systems by mapping cyber threats with vulnerabilities and flaws.