Latest Cybersecurity News and Articles


Major Cyber Attack Paralyzes Kyivstar - Ukraine's Largest Telecom Operator

13 December 2023
Ukraine's biggest telecom operator Kyivstar has become the victim of a cyber attack, disrupting customer access to mobile and internet services. "The cyberattack on Ukraine's #Kyivstar telecoms operator has impacted all regions of the country with high impact to the capital, metrics show, with knock-on impacts reported to air raid alert network and banking sector as work continues

OAuth Apps Used to Automate BEC and Cryptomining Attacks

13 December 2023
Attackers target user accounts without robust authentication measures, creating new OAuth apps with high privileges to ensure continued access and hide their malicious activities.

Update: Widespread Security Flaws Blamed for PSNI Data Breach

13 December 2023
An independent review found that the breach was a result of multiple factors and highlighted the organization's lack of a data protection strategy. It also noted that the PSNI had not fully implemented the 2018 Data Protection Act.

Cloud Engineer Wreaks Havoc on Bank’s Network After Firing

13 December 2023
The engineer deployed malware, deleted code repositories, and emailed himself proprietary bank code in retaliation for being fired, impersonating a coworker in the process.

Microsoft's Final 2023 Patch Tuesday Fixes 33 Flaws, Including Four Critical Ones

13 December 2023
Microsoft has released its final set of Patch Tuesday updates for 2023, addressing 33 flaws in its software. This release is considered one of the lightest in recent years, with four critical vulnerabilities and 29 important ones.

Microsoft's Final 2023 Patch Tuesday: 33 Flaws Fixed, Including 4 Critical

13 December 2023
Microsoft released its final set of Patch Tuesday updates for 2023, closing out 33 flaws in its software, making it one of the lightest releases in recent years. Of the 33 shortcomings, four are rated Critical and 29 are rated Important in severity. The fixes are in addition to 18 flaws Microsoft addressed in its Chromium-based Edge browser since the release of Patch

Microsoft Patch Tuesday, December 2023 Edition

12 December 2023
The final Patch Tuesday of 2023 is upon us, with Microsoft Corp. today releasing fixes for a relatively small number of security holes in its Windows operating systems and other software. Even more unusual, there are no known "zero-day" threats targeting any of the vulnerabilities in December's patch batch. Still, four of the updates pushed out today address "critical" vulnerabilities that Microsoft says can be exploited by malware or malcontents to seize complete control over a vulnerable Windows device with little or no help from users.

81% of companies had malware, phishing and password attacks in 2023

12 December 2023
According to a recent report, 81% of organizations faced malware, phishing and password attacks last year which were mainly targeted at users.

Unveiling the Cyber Threats to Healthcare: Beyond the Myths

12 December 2023
Let's begin with a thought-provoking question: among a credit card number, a social security number, and an Electronic Health Record (EHR), which commands the highest price on a dark web forum?  Surprisingly, it's the EHR, and the difference is stark: according to a study, EHRs can sell for up to $1,000 each, compared to a mere $5 for a credit card number and $1 for a social

Russian APT28 Hackers Targeting 13 Nations in Ongoing Cyber Espionage Campaign

12 December 2023
The Russian APT28 threat actor, also known as ITG05, is using authentic documents related to the Israel-Hamas war as lures to deliver a custom backdoor called HeadLace against targeted entities in 13 countries, primarily in Europe.

Over 1,450 pfSense Servers Exposed to RCE Attacks via Bug Chain

12 December 2023
Around 1,450 instances of pfSense, an open-source firewall and router software, are vulnerable to command injection and cross-site scripting flaws. These flaws, if exploited together, could allow attackers to execute remote code on the system.

Threat Actor TA4557 Targets Recruiters With Malware

12 December 2023
The threat actor uses techniques such as sending URLs to fake resume websites or attachments containing instructions to visit the website, leading to the download of malicious files.

Russian APT28 Hackers Targeting 13 Nations in Ongoing Cyber Espionage Campaign

12 December 2023
The Russian nation-state threat actor known as APT28 has been observed making use of lures related to the ongoing Israel-Hamas war to facilitate the delivery of a custom backdoor called HeadLace. IBM X-Force is tracking the adversary under the name ITG05, which is also known as BlueDelta, Fancy Bear, Forest Blizzard (formerly Strontium), FROZENLAKE, Iron Twilight, Sednit, Sofacy, and

Gamers Warned of Potential CS2 Exploit That can Reveal IP Addresses

12 December 2023
The exploit, which is an XSS vulnerability, allows players to display GIFs using HTML code blocks in-game. This poses a potential security threat to players, as the exploit can access player IP addresses and potentially execute code on their PCs.

Long-Running Clearview AI Class Action Biometric Privacy Case Settles

12 December 2023
Clearview AI has reached a settlement in a class-action privacy lawsuit, which alleged that the company violated Illinois' Biometric Information Privacy Act (BIPA) by using online images without consent for its facial recognition technology.

Fake LinkedIn Profiles Target Saudi Workers for Information Leakage and Financial Fraud

12 December 2023
Researchers have discovered nearly a thousand fake profiles created with the intention of reaching out to companies in the Middle East. These profiles, often difficult to distinguish from real ones, have been successful in their campaigns.

Security Automation Gains Traction, Prompting a “Shift Everywhere” Philosophy

12 December 2023
According to Synopsys, the use of automated security technology is on the rise, as organizations increasingly embrace the "shift everywhere" philosophy to improve the effectiveness and reduce the cost of security activities.

50K WordPress Sites Exposed to RCE Attacks by Critical Bug in Backup Plugin

12 December 2023
The vulnerability, tracked as CVE-2023-6553, can be exploited by unauthenticated attackers without user interaction. Although a patch has been released, almost 50,000 WordPress websites still remain vulnerable to this critical security flaw.

Cybercriminals Continue Targeting Open Remote Access Products

12 December 2023
According to WatchGuard, cybercriminals are still primarily targeting open remote access products and using legitimate remote access tools to hide their malicious activities.

Nearly 130,000 Affected by Ransomware Attack on Cold Storage Company Americold

12 December 2023
The cyberattack resulted in the leak of sensitive data, including names, addresses, Social Security numbers, financial account information, and employment-related health insurance and medical information.