Latest Cybersecurity News and Articles


WordPress Fixes POP Chain Exposing Websites to RCE Attacks

08 December 2023
This vulnerability could allow attackers to run arbitrary PHP code on a target website. The vulnerability is a Property Oriented Programming (POP) chain that requires an attacker to control all the properties of a deserialized object.

Founder of Bitzlato Cryptocurrency Exchange Pleads Guilty in Money-Laundering Scheme

08 December 2023
The Russian founder of the now-defunct Bitzlato cryptocurrency exchange has pleaded guilty, nearly 11 months after he was arrested in Miami earlier this year. Anatoly Legkodymov (aka Anatolii Legkodymov, Gandalf, and Tolik), according to the U.S. Justice Department, admitted to operating an unlicensed money-transmitting business that enabled other criminal actors to launder their

John Denning joins FS-ISAC as Chief Information Security Officer

07 December 2023
FS-ISAC has announced the appointment of John Denning as Chief Information Security Officer (CISO) effective as of January 1, 2024.

Google Pushes Yet Another Security Update to Its Chrome Browser

07 December 2023
Chrome version 120 includes 10 bug fixes, with two of them being highly critical security patches. The high-ranked security vulnerabilities include "Use after free" exploits in Media Stream and Side Panel Search.

UK: Cambridge Hospitals Admit Two Excel-Based Data Breaches

07 December 2023
A Cambridge NHS trust has admitted to two historic data breaches, involving the accidental disclosure of patient data while responding to Freedom of Information requests.

Dangerous Vulnerability in Fleet Management Software Seemingly Ignored by Vendor

07 December 2023
The vulnerability, which impacts the Syrus4 IoT gateway made by Digital Communications Technologies (DCT), gives hackers access to the software and commands used to manage thousands of vehicles.

Groveport Madison School District Servers Hacked by Ransomware Group

07 December 2023
The BlackSuit ransomware group was able to hack into two servers belonging to the school district, impacting Windows devices, file services, printers, and copiers. Phones were not impacted.

New SLAM Attack Steals Sensitive Data From AMD, Future Intel CPUs

07 December 2023
The SLAM attack exploits hardware features in upcoming CPUs from Intel, AMD, and Arm to obtain the root password hash from kernel memory, highlighting potential security vulnerabilities.

47% of organizations monitored supply chain risks monthly or more

07 December 2023
According to a report, there was a 26% increase in supply chain breaches in 2022 and 9% of organizations are working with suppliers to fix them.

Millions of Patient Scans and Health Records Spilling Online Thanks to Decades-Old DICOM Bug

07 December 2023
Over 3,800 PACS servers across 110 countries are unintentionally exposing the private data of 16 million patients, including names, addresses, and even Social Security numbers.

Apple and Some Linux Distros are Open to Bluetooth Attack

07 December 2023
A Bluetooth authentication bypass vulnerability, tracked as CVE-2023-45866, allows attackers to connect to Apple, Android, and Linux devices and inject keystrokes to run arbitrary commands.

Microsoft Warns of COLDRIVER's Evolving Evading and Credential-Stealing Tactics

07 December 2023
The threat actor known as COLDRIVER has continued to engage in credential theft activities against entities that are of strategic interests to Russia while simultaneously improving its detection evasion capabilities. The Microsoft Threat Intelligence team is tracking under the cluster as Star Blizzard (formerly SEABORGIUM). It's also called Blue Callisto, BlueCharlie (or TAG-53),

TA422’s Dedicated Exploitation Loop—the Same Week After Week

07 December 2023
Russian APT group TA422 has been actively exploiting patched vulnerabilities to target government, aerospace, education, finance, manufacturing, and technology sectors in Europe and North America.

Report: LockBit Remains Top Global Ransomware Threat

07 December 2023
Researchers at ZeroFox found that LockBit was leveraged in more than a quarter of global ransomware and digital extortion (R&DE) attacks in the seven quarters analyzed from January 2022 to September 2023.

Schools in Maine, Indiana and Georgia Contend Ransomware Attacks

07 December 2023
The Henry County Schools district in Georgia and the Hermon School Department in Maine are among the latest victims, with the former experiencing a ransomware attack and the latter having outdated software vulnerabilities exploited.

Microsoft Will Offer Extended Security Updates for Windows 10

07 December 2023
Microsoft will offer Extended Security Updates (ESU) for Windows 10 users after the end of support, but they will have to pay for them. ESUs will provide critical security updates but not new features or design changes.

Nissan Investigates Cyberattack Involving its Systems in Australia and New Zealand

07 December 2023
Nissan's warning to customers to remain vigilant suggests a potential data breach may have occurred, highlighting the ongoing threat to personal information in the automotive industry.

Report shows rise in threat actors exploiting remote access software

07 December 2023
A new report shows increasing instances of remote access software abuse and the rise of cyber adversaries using password-stealers.

CISA Performance Goals Program Trims Exploited CVEs

07 December 2023
Since the release of the CPG program, organizations enrolled in CISA's vulnerability scanning service have reduced their average number of known exploited vulnerabilities by about 20%.

Threat Actors can Leverage AWS STS to Infiltrate Cloud Accounts

07 December 2023
According to the experts, to mitigate AWS token abuse, organizations should log CloudTrail event data, detect role-chaining events and MFA abuse, and rotate long-term IAM user access keys.