Latest Cybersecurity News and Articles


Number of Incidents Affecting GitHub, Bitbucket, GitLab, and Jira Continues to Rise

09 August 2024
The number of incidents affecting GitHub, Bitbucket, GitLab, and Jira is on the rise, leading to outages, human errors, cyberattacks, data breaches, ransomware, security vulnerabilities, and data loss for DevSecOps teams, according to GitProtect.io.

Report reveals 10% increase in the exploitation of old CVEs

09 August 2024
The exploitation of old common vulnerabilities and exposures (CVEs) rose by 10% from 2023 to 2024.

New Ransomware Groups Emerge Despite Crackdowns

09 August 2024
According to a report by Rapid7, a total of 21 new or rebranded groups have emerged since January 2024, alongside existing groups like LockBit, which has survived law enforcement crackdowns.

Consumer Reports Study Finds Data Removal Services are Often Ineffective

09 August 2024
Consumer Reports cautioned against relying too heavily on data removal services, as many fall short of expectations despite high costs. The study highlighted the need for better protection of consumer data and stricter regulations on data brokers.

Phishing Attack Exploits Google, WhatsApp to Steal Data

09 August 2024
The attack begins with a phishing email that directs recipients to what appears to be an Amazon account verification link. However, this link is a deceptive graphic hosted on Google Drawings, a component of the Google Workspace suite.

Sports Venues Must Vet Their Vendors to Maintain Security

09 August 2024
The sports and entertainment industries face unique cybersecurity challenges due to the rapid technological advancements being implemented. Cyber-physical systems like augmented reality and smart sensors increase security concerns.

Ransomware Drill Targets Healthcare in Operation 911

09 August 2024
A ransomware drill focused on healthcare called Operation 911 was conducted at Black Hat USA 2024 by Las Vegas law enforcement, the FBI, and Semperis. During the drill, a simulated ransomware attack targeted a fictitious hospital.

Russia's Kursk Region Suffers ‘Massive’ DDoS Attack Amid Ukraine Offensive

09 August 2024
Kursk region in Russia was hit by a large-scale DDoS attack during Ukraine's cross-border incursion, affecting government, business websites, and critical services. NetBlocks reported disruptions in internet connectivity linked to the attacks.

RustScan: Open-Source Port Scanner

09 August 2024
RustScan is a fast and versatile open-source port scanner with Adaptive Learning for optimal performance. It can scan all 65,000 ports in 3 seconds and supports a scripting engine for customization.

Ireland's DPC Takes Twitter to Court Over AI User Data Concerns

09 August 2024
Ireland's Data Protection Commission (DPC) has taken Twitter to court over concerns regarding the use of AI user data. The DPC is specifically worried about the personal data of millions of European users being used to train AI systems for Grok.

OpenWrt Dominates, but Vulnerabilities Persist in OT/IoT Router Firmware

09 August 2024
A Forescont study showed that outdated software components in OT/IoT cellular routers and SOHO routers are linked to known vulnerabilities, with an average of 20 exploitable n-days affecting the kernel in widely used firmware images.

Ransomware Attack Costs loanDepot Almost $27 Million

09 August 2024
The $27 million in costs included insurance recoveries, investigation and remediation costs, customer notifications, legal fees, and settlement costs for a class-action lawsuit.

Researchers Unveil AWS Vulnerabilities, New 'Shadow Resource' Attack Vector

09 August 2024
The vulnerabilities were promptly patched by AWS after being reported by Aqua Security researchers. These flaws in services like CloudFormation, CodeStar, and Service Catalog could potentially lead to a full account takeover if exploited.

CISA Releases Guide to Enhance Software Security Evaluations

09 August 2024
CISA has released a guide to enhance how organizations evaluate software manufacturers' security practices, emphasizing product security over enterprise security measures for defending against cyber threats.

DOJ Charges Nashville Man for Helping North Koreans Get U.S. Tech Jobs

09 August 2024
The U.S. Department of Justice (DoJ) on Thursday charged a 38-year-old individual from Nashville, Tennessee, for allegedly running a "laptop farm" to help get North Koreans remote jobs with American and British companies. Matthew Isaac Knoot is charged with conspiracy to cause damage to protected computers, conspiracy to launder monetary instruments, conspiracy to commit wire fraud, intentional

CISA Warns of Hackers Exploiting Legacy Cisco Smart Install Feature

09 August 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has disclosed that threat actors are abusing the legacy Cisco Smart Install (SMI) feature with the aim of accessing sensitive data. The agency said it has seen adversaries "acquire system configuration files by leveraging available protocols or software on devices, such as abusing the legacy Cisco Smart Install feature." It also

Security leaders respond to Olympic venue ransomware attack

08 August 2024
The Grand Palais exhibition hall in Paris experienced a ransomware attack, and security leaders are sharing their insights. 

University Professors Targeted by North Korean Cyber Espionage Group

08 August 2024
The North Korea-linked threat actor known as Kimsuky has been linked to a new set of attacks targeting university staff, researchers, and professors for intelligence gathering purposes. Cybersecurity firm Resilience said it identified the activity in late July 2024 after it observed an operation security (OPSEC) error made by the hackers. Kimsuky, also known by the names APT43, ARCHIPELAGO,

FTC approves lawsuit against TikTok for violating COPPA

08 August 2024
On behalf of the FTC, the Department of Justice sued video-sharing platform TikTok with violating the Children’s Online Privacy Protection Act.

Critical Progress WhatsUp Gold RCE Flaw Now Under Active Exploitation

08 August 2024
Threat actors are actively exploiting a critical remote code execution vulnerability in Progress WhatsUp Gold 23.1.2 and older versions, identified as CVE-2024-4885 with a CVSS v3 score of 9.8.