Latest Cybersecurity News and Articles


New Pierogi++ Malware by Gaza Cyber Gang Targeting Palestinian Entities

15 December 2023
The discovery of the new updated Pierogi++ malware suggests that the group is continuously refining its tactics and tools to maintain persistent access to targeted networks.

Crypto Hardware Wallet Ledger's Supply Chain Breach Results in $600,000 Theft

15 December 2023
Crypto hardware wallet maker Ledger published a new version of its "@ledgerhq/connect-kit" npm module after unidentified threat actors pushed malicious code that led to the theft of more than $600,000 in virtual assets. The compromise was the result of a former employee falling victim to a phishing attack, the company said in a statement. This allowed the attackers to gain

UK Plans Tough New Security Rules for Datacenters

15 December 2023
Under the current proposals, datacenter providers would have a “duty to take appropriate and proportionate technical and organizational measures” to manage security and resilience risk.

80% predict burnout will have significant effect on businesses

15 December 2023
The global perma-crisis is set to continue to take its toll in 2024, as extreme weather events continue to impact organizations and global instability deepens. 

Kraft Heinz Reviewing Claims of Cyberattack but Internal Systems ‘Operating Normally’

15 December 2023
Kraft Heinz is investigating claims of a data breach by the Snatch ransomware gang, but currently sees no evidence of a broader attack or adverse effects on its internal systems.

Dental Plan Administrator Fined $400K for Phishing Breach

15 December 2023
The settlement requires the company to implement data retention policies, use multifactor authentication, encrypt private information, and have a Chief Information Security Officer (CISO) reporting to the CEO regularly.

Iranian State-Sponsored OilRig Group Deploys Three New Malware Downloaders

15 December 2023
The downloaders named ODAgent, OilCheck, and OilBooster, along with an updated version of SampleCheck5000, were used to blend with authentic network traffic and cover up the group's attack infrastructure.

Report: Approval Phishing Scams Drain $1bn of Cryptocurrency from Victims

15 December 2023
Approval phishing scams have been used to steal at least $1bn in crypto since May 2021, as per a new report by Chainalysis. This technique, frequently used by romance scammers, is estimated to have led to losses of at least $374m so far in 2023.

Bug or Feature? Hidden Web Application Vulnerabilities Uncovered

15 December 2023
Web Application Security consists of a myriad of security controls that ensure that a web application: Functions as expected. Cannot be exploited to operate out of bounds. Cannot initiate operations that it is not supposed to do. Web Applications have become ubiquitous after the expansion of Web 2.0, which Social Media Platforms, E-Commerce websites, and email clients saturating the internet

New Security Vulnerabilities Uncovered in pfSense Firewall Software - Patch Now

15 December 2023
Multiple security vulnerabilities have been discovered in the open-source Netgate pfSense firewall solution called pfSense that could be chained by an attacker to execute arbitrary commands on susceptible appliances. The issues relate to two reflected cross-site scripting (XSS) bugs and one command injection flaw, according to new findings from Sonar. "Security inside a local network is often

Knight Ransomware Group Strikes Ohio City of Defiance to Exfiltrate Data

15 December 2023
The attackers have gained access to sensitive data, including employee records, law enforcement videos, emails, and confidential documents. The City of Defiance has not yet responded to the incident.

Report: Vulnerabilities Now Top Initial Access Route For Ransomware

15 December 2023
Threat actors are increasingly using vulnerability exploitation instead of phishing emails to compromise victims with ransomware, according to insurance company Corvus Insurance.

Organizations Prefer a Combination of AI and Human Analysts to Monitor Their Digital Supply Chain

15 December 2023
Despite increased monitoring, getting supply chain vendors to address security issues in a timely manner remains a challenge, with only 19% of respondents actively working with their suppliers to remediate issues, according to BlueVoyant.

Russian FSB cyber actor Star Blizzard continues worldwide spear-phishing campaigns

15 December 2023
The Russia-based actor is targeting organisations and individuals in the UK and other geographical areas of interest.

CitrixBleed Isn’t Going Away: Security Experts Struggle to Control Critical Vulnerability

15 December 2023
Despite a patch being issued, the exploitation of CitrixBleed has continued, highlighting the challenges of vendor security management and the need for organizations to take immediate action to mitigate the vulnerability.

New York Hospitals’ Patient Data Impacted by Cyberattack

15 December 2023
The IT network of New York-based health providers, including HealthAlliance Hospital, Margaretville Hospital, and Mountainside Residential Care Center, was breached for nearly two months, resulting in the compromise of patient data.

FCC Updates Data Breach Rules, With Consumers in Mind

15 December 2023
The Federal Communications Commission (FCC) has updated its data breach rules for the first time in 16 years. The new rules expand the definition of a breach and specify who should be notified.

FBI, CISA, Treasury, and FinCEN Released Joint Advisory on Karakurt Data Extortion Group

15 December 2023
Karakurt uses various tactics to steal data and extort victims for ransom. They contact victims' employees, business partners, and clients to pressure them into paying the ransom.

'Virtual Wild, Wild West': Cybercriminals use Wyoming shell companies for global hacks

15 December 2023
Wyoming LLCs are being implicated in high-profile hacking activities, attracting cybercriminals due to the state's easy registration process for anonymous shell companies.

MITRE Launches Critical Infrastructure Threat Model Framework

15 December 2023
MITRE has launched EMB3D, a new threat model framework to help defenders protect operational technology and industrial control systems by mapping cyber threats with vulnerabilities and flaws.