Latest Cybersecurity News and Articles


Surge in Magniber Ransomware Attacks Impact Home Users Worldwide

05 August 2024
Unlike other ransomware groups targeting businesses, Magniber focuses on individuals. Victims report their devices getting infected after running software cracks. Ransom demands start at $1,000 and escalate to $5,000 if not paid within three days.

CrowdStrike Outage Renews Supply Chain Concerns, Federal Officials Say

05 August 2024
Federal officials have raised concerns about the software supply chain and memory safety vulnerabilities following a global IT outage caused by a faulty CrowdStrike software update.

Evasive Panda Compromises ISP to Distribute Malicious Software Updates

05 August 2024
The group used DNS poisoning to redirect software update queries to attacker-controlled servers, infecting victims with malware. Volexity detected one attack in Hong Kong, which ceased when the ISP took action.

White House Officials Meet with Allies, Industry on Connected Car Risks

05 August 2024
Representatives from various countries and the European Union participated in the meeting, addressing cybersecurity and data risks in connected vehicles. The meeting highlighted the importance of connected cars as a critical part of infrastructure.

Linux Kernel Impacted by New SLUBStick Cross-Cache Attack

05 August 2024
A new Linux Kernel attack called SLUBStick has a 99% success rate in turning a limited heap vulnerability into a powerful memory read-and-write capability, allowing for privilege escalation and container escape.

Mozilla Follows Google in Distrusting Entrust’s TLS Certificates

05 August 2024
Mozilla has joined Google in no longer trusting Entrust as a root certificate authority due to compliance failures and inadequate responses. Google was the first to make this decision, citing concerning behaviors from Entrust.

Cryptonator Seized for Laundering Ransom Payments, Stolen Crypto

05 August 2024
The U.S. and German law enforcement have seized the domain of the Cryptonator crypto wallet platform, indicting its operator, Roman Boss, for money laundering and running an unlicensed money service business.

Researchers Uncover Flaws in Windows Smart App Control and SmartScreen

05 August 2024
Cybersecurity researchers have uncovered design weaknesses in Microsoft's Windows Smart App Control and SmartScreen that could enable threat actors to gain initial access to target environments without raising any warnings. Smart App Control (SAC) is a cloud-powered security feature introduced by Microsoft in Windows 11 to block malicious, untrusted, and potentially unwanted apps from being run

Kazakh Organizations Targeted by 'Bloody Wolf' Cyber Attacks

05 August 2024
Organizations in Kazakhstan are the target of a threat activity cluster dubbed Bloody Wolf that delivers a commodity malware called STRRAT (aka Strigoi Master). "The program selling for as little as $80 on underground resources allows the adversaries to take control of corporate computers and hijack restricted data," cybersecurity vendor BI.ZONE said in a new analysis. The cyber attacks employ

Protect AI Raises $60M in Series B Financing

05 August 2024
Protect AI, a Seattle-based AI and ML security company, raised $60M in Series B funding led by Evolution Equity Partners, with participation from 01 Advisors, StepStone Group, Samsung, and existing investors.

Alex Stamos named Chief Information Security Officer at SentinelOne

05 August 2024
Alex Stamos has been hired as Chief Information Security Officer (CISO) at Sentinel One. 

Australian Companies Will Soon Need to Report Ransom Payments

05 August 2024
Australian companies will soon be required to report ransom payments, in line with the upcoming Cyber Security Act in the country. The legislation aims to enhance the response to cyber incidents, similar to CIRCIA in the US.

New BlankBot Android Malware Targets Users' Banking Data

05 August 2024
BlankBot, which is still in development, has advanced features like screen recording, keylogging, and remote control, posing a significant threat due to its evasion techniques.

The Loper Bright Decision: How it Impacts Cybersecurity Law

05 August 2024
The Loper Bright decision has yielded impactful results: the Supreme Court has overturned forty years of administrative law, leading to potential litigation over the interpretation of ambiguous laws previously decided by federal agencies. This article explores key questions for cybersecurity professionals and leaders as we enter a more contentious period of cybersecurity law. Background What is

US Releases Russian Hackers and Spies as Part of Prisoner Swap

05 August 2024
The United States, along with Germany and Slovenia, participated in a historic prisoner exchange with Russia, releasing hackers, spies, and an assassin. The swap took place at an airport in Ankara, Turkey.

Security Bypass Vulnerability Exposed in Rockwell Automation Logix Controllers

05 August 2024
A vulnerability in Rockwell Automation's Logix controllers, CVE-2024-6242, poses a security risk to industrial automation systems worldwide by allowing unauthorized access to PLCs.

Enhancing Incident Response Readiness with Wazuh

05 August 2024
Incident response is a structured approach to managing and addressing security breaches or cyber-attacks. Security teams must overcome challenges such as timely detection, comprehensive data collection, and coordinated actions to enhance readiness. Improving these areas ensures a swift and effective response, minimizing damage and restoring normal operations quickly. Challenges in incident

Tech Support Scam Ring Leader Gets Seven Years in Prison, $6M Fine

05 August 2024
A tech support fraud leader was sentenced to seven years in prison for scamming over 6,500 victims and making $6 million. The operation targeted elderly victims in the U.S. and Canada by showing fake malware infections on their computers.

Russian Threat Actors Hijacked Over 30,000 Domains in Sitting Ducks Attacks

05 August 2024
This attack method takes advantage of vulnerabilities at the registrar level and lax ownership verification at DNS providers. Research has shown that over a million domains could be vulnerable to this type of attack daily.

Cybersecurity Innovator Clutch Security Nets $8.5m in Funding Led by Lightspeed

05 August 2024
Tel Aviv-based cybersecurity firm, Clutch Security, has secured $8.5m in seed funding led by Lightspeed Venture Partners, Merlin Ventures, Cyber Club London, and other investors like Nir Polak, Shlomo Kramer, and Armon Dadgar.