Latest Cybersecurity News and Articles


ALPHV Ransomware Site Outage Rumored to be Caused by Law Enforcement

11 December 2023
Law enforcement is suspected to be behind the recent outage of ALPHV ransomware gang's websites. The negotiation and data leak sites, as well as the Tor negotiation URLs, have been down for over 30 hours.

CISA Adds Qlik Bugs to Exploited Vulnerabilities Catalog

11 December 2023
Both bugs were found this summer in Qlik Sense — a data analytics tool used widely among government organizations and large businesses. The vulnerabilities provide hackers with an entry point into systems and allow them to elevate their privileges.

North Korea's Kimsuky Targeting South Korean Research Institutes with Backdoor Attacks

11 December 2023
The North Korean threat group uses a backdoor to steal information and execute commands on compromised systems. Kimsuky has expanded its attacks to include Europe, Russia, and the US.

Mobile Password Managers Might Be Exposing Credentials Due to New ‘Autospill’ Vulnerability

11 December 2023
The vulnerability occurs when password managers get disoriented and mistakenly autofill credentials into the native fields of the underlying app instead of the intended login page.

Akira Ransomware Strikes Again: Compass Group Italia and Aqualectra Utility Hit by Data Breach

11 December 2023
The Akira ransomware group has targeted two more victims, one in Italy and another in Curaçao, compromising sensitive data and posing a threat to the integrity and security of the affected companies.

HHS Announces Next Steps in Ongoing Work to Enhance Cybersecurity for Health Care and Public Health Sectors

11 December 2023
The U.S. Department of Health and Human Services (HHS) has released a concept paper outlining a cybersecurity strategy for the healthcare sector, focusing on strengthening resilience against cyber-attacks.

SpyLoan Scandal: 18 Malicious Loan Apps Defraud Millions of Android Users

11 December 2023
Cybersecurity researchers have discovered 18 malicious loan apps for Android on the Google Play Store that have been collectively downloaded over 12 million times. "Despite their attractive appearance, these services are in fact designed to defraud users by offering them high-interest-rate loans endorsed with deceitful descriptions, all while collecting their victims' personal and

New PoolParty Process Injection Techniques Outsmart Top EDR Solutions

11 December 2023
A new collection of eight process injection techniques, collectively dubbed PoolParty, could be exploited to achieve code execution in Windows systems while evading endpoint detection and response (EDR) systems. SafeBreach researcher Alon Leviev said the methods are "capable of working across all processes without any limitations, making them more flexible than existing process

The threat landscape in H1 2023

11 December 2023
Ransomware, AI and malware featured in top threat actors in H1 2023.

SLAM Attack: New Spectre-based Vulnerability Impacts Intel, AMD, and Arm CPUs

09 December 2023
Researchers from the Vrije Universiteit Amsterdam have disclosed a new side-channel attack called SLAM that could be exploited to leak sensitive information from kernel memory on current and upcoming CPUs from Intel, AMD, and Arm. The attack is an end-to-end exploit for Spectre based on a new feature in Intel CPUs called Linear Address Masking (LAM) as well as its analogous

Researchers Automated Jailbreaking of LLMs With Other LLMs

09 December 2023
Researchers have developed an automated machine learning technique, called TAP, that can quickly exploit vulnerabilities in large language models (LLMs) and make them produce harmful and toxic responses.

Bypassing Major EDRs Using Pool Party Process Injection Techniques

09 December 2023
The technique utilizes Windows thread pools and includes a chain of three primitives for memory allocation, writing malicious code, and executing it, making it more flexible than existing process injection techniques.

Central Virginia Transit System Affected by Cyber Incident

09 December 2023
The Greater Richmond Transit Company (GRTC) experienced a cyberattack over the Thanksgiving holiday, resulting in a temporary disruption to their computer network. The Play ransomware gang has claimed responsibility for the attack.

Researchers Unveal GuLoader Malware's Latest Anti-Analysis Techniques

09 December 2023
Threat hunters have unmasked the latest tricks adopted by a malware strain called GuLoader in an effort to make analysis more challenging. "While GuLoader's core functionality hasn't changed drastically over the past few years, these constant updates in their obfuscation techniques make analyzing GuLoader a time-consuming and resource-intensive process," Elastic Security Labs

Hackers Hit Erris Water in Stance Over Israel

09 December 2023
Cybercriminals targeted a private group water scheme in the Erris area, causing disruption to 180 homeowners and highlighting the vulnerability of critical infrastructure to politically motivated cyber-attacks.

New 5G Modem Flaws Affect iOS Devices and Android Models from Major Brands

09 December 2023
The set of vulnerabilities, collectively known as 5Ghoul, impacts USB and IoT modems as well as smartphones running Android and iOS, affecting 714 smartphones from 24 brands.

Android Barcode Scanner App Exposes User Passwords

09 December 2023
The Android app Barcode to Sheet, with over 100k downloads, has left sensitive user data exposed due to an open instance, including plaintext enterprise data and weakly hashed passwords.

Employee burnout is on the rise

08 December 2023
According to a recent report, 80% of surveyed global risk leaders believe burnout will have a significant impact on businesses in the next year.

New 5G Modems Flaws Affect iOS Devices and Android Models from Major Brands

08 December 2023
A collection of security flaws in the firmware implementation of 5G mobile network modems from major chipset vendors such as MediaTek and Qualcomm impact USB and IoT modems as well as hundreds of smartphone models running Android and iOS. Of the 14 flaws – collectively called 5Ghoul (a combination of "5G" and "Ghoul") – 10 affect 5G modems from the two companies, out of which three

FCC Partners With Four States on Privacy and Data Protection Enforcement

08 December 2023
By collaborating with state enforcers, the FCC can enhance its investigative efforts, share information, and leverage tools to address consumer harms more effectively in the realm of privacy and cybersecurity.