Latest Cybersecurity News and Articles


Non-Human Access is the Path of Least Resistance: A 2023 Recap

12 December 2023
2023 has seen its fair share of cyber attacks, however there’s one attack vector that proves to be more prominent than others - non-human access. With 11 high-profile attacks in 13 months and an ever-growing ungoverned attack surface, non-human identities are the new perimeter, and 2023 is only the beginning.  Why non-human access is a cybercriminal’s paradise  People always

Leader of Russian Hacktivist Group Killnet ‘Retires,’ Appoints New Head

12 December 2023
Killmilk, the leader of the pro-Russia hacktivist group Killnet, has announced his retirement. Killmilk, whose alleged identity was recently uncovered as Nikolai Serafimov, cited the toll of Russia's war in Ukraine as the reason for his departure.

Toyota Financial Services Discloses Data Breach Affecting German Customers

12 December 2023
Toyota Financial Services (TFS) has suffered a data breach, exposing sensitive personal and financial data. The breach affected German customers, with threat actors gaining access to names, addresses, contract information, and bank account details.

UK Police Return $10 Million in Bitcoin Stolen by Chronically-Ill Bed-Bound Thief

12 December 2023
Police in Lancashire, UK have returned around £8 million ($10 million) worth of bitcoin to a man whose cryptocurrency was stolen in 2017. Four people involved in the hack were sentenced earlier this year.

TV Service in UAE Hacked to Show Alleged Atrocities in Palestine

12 December 2023
Viewers saw a message from the hackers and then a fake news broadcast featuring AI-generated news anchor showing alleged atrocities committed by Israel. The incident is still being investigated, and it is unclear who is responsible.

New MrAnon Stealer Malware Targeting German Users via Booking-Themed Scam

12 December 2023
A phishing campaign has been observed delivering an information stealer malware called MrAnon Stealer to unsuspecting victims via seemingly benign booking-themed PDF lures. "This malware is a Python-based information stealer compressed with cx-Freeze to evade detection," Fortinet FortiGuard Labs researcher Cara Lin said. "MrAnon Stealer steals its victims' credentials, system

White House Wants to Set Minimum Cyber Standards for Hospitals, Healthcare

12 December 2023
The White House plans to collaborate with the Department of Health and Human Services to establish minimum cybersecurity standards to protect the healthcare sector from ransomware and other cyber threats.

Update: Henry Schein Says 29K People Affected in September Cyberattack

12 December 2023
Henry Schein has notified Maine's attorney general that the personal information of over 29,000 people may have been accessed in a cyber incident in September. The hackers obtained names, financial account information, and security codes.

Amazon Sues REKK Fraud Gang That Stole Millions in Illicit Refunds

12 December 2023
Amazon has taken legal action against an underground refund scheme called REKK, involving an international fraudulent organization and former Amazon employees, resulting in the theft of millions of dollars worth of products.

Greece Plans National Cybersecurity Authority to Combat Rising Hacker Threats

12 December 2023
The National Cybersecurity Authority will coordinate and implement policies and measures to enhance Greece's cybersecurity ecosystem and effectively prevent and manage cyberattacks.

Apple Releases Security Updates to Patch Critical iOS and macOS Security Flaws

12 December 2023
Apple has released security patches for various devices and software, including iOS, iPadOS, macOS, tvOS, watchOS, and Safari. These patches address multiple security flaws, including two recently disclosed zero-day vulnerabilities.

Kubescape Open-Source Project Adds Vulnerability Exploitability eXchange (VEX) Support

12 December 2023
Kubescape, an open-source project, has become the first to generate Vulnerability Exploitability eXchange (VEX) documents. VEX is a standard that helps share information about vulnerabilities and their potential for exploitation.

HHS Agrees to $480,000 Settlement With Louisiana Medical Group Over Data Breach

12 December 2023
This settlement marks the first resolution by HHS involving a phishing attack that violated the Health Insurance Portability and Accountability Act (HIPAA), highlighting the need for healthcare organizations to prioritize cybersecurity measures.

LockBit Ransomware Group Alleges LivaNova PLC Data Breach

12 December 2023
LivaNova has not yet issued an official statement or response regarding the breach, and cybersecurity experts are closely monitoring the situation for further developments.

Apple Releases Security Updates to Patch Critical iOS and macOS Security Flaws

12 December 2023
Apple on Monday released security patches for iOS, iPadOS, macOS, tvOS, watchOS, and Safari web browser to address multiple security flaws, in addition to backporting fixes for two recently disclosed zero-days to older devices. This includes updates for 12 security vulnerabilities in iOS and iPadOS spanning AVEVideoEncoder, ExtensionKit, Find My, ImageIO, Kernel, Safari

New Critical RCE Vulnerability Discovered in Apache Struts 2 - Patch Now

12 December 2023
Apache has released a security advisory warning of a critical security flaw in the Struts 2 open-source web application framework that could result in remote code execution. Tracked as CVE-2023-50164, the vulnerability is rooted in a flawed "file upload logic" that could enable unauthorized path traversal and could be exploited under the circumstances to upload a malicious file

September 2023 saw more ransomware attacks than all of 2022

11 December 2023
According to a recent report by Apple, the total number of data breaches more than tripled between 2013 and 2022, and rose further in 2023.

Researchers Unmask Sandman APT's Hidden Link to China-Based KEYPLUG Backdoor

11 December 2023
The APT group known as Sandman and a China-based threat cluster using the backdoor KEYPLUG share infrastructure control and management practices, indicating potential overlap in their operations.

Kelvin Security Hacking Group Leader Arrested in Spain

11 December 2023
Kelvin Security has been active since 2013, targeting public-facing systems to obtain user credentials and steal confidential data, which they would sell or leak on hacking forums.

Australia: University of Wollongong Confirms Data Breach, Notifies Authorities

11 December 2023
The University of Wollongong has experienced a data breach, with potentially both staff and students affected. The breach has been detected and contained, and investigations are underway to determine the scope of the breach.