Latest Cybersecurity News and Articles


Luxury Yacht Maker Lürssen Hit by Ransomware Attack Over Easter Weekend

13 April 2023
“In coordination with internal and external experts, we immediately initiated all necessary protective measures and informed the responsible authorities,” a spokesperson reportedly said in a brief statement.

Zelle Phishing Campaign Sends Spoofed Emails

13 April 2023
Zelle, the widely used and highly acclaimed money-transfer service, is now a prime target for cybercriminals. The simplicity of sending funds to friends or businesses through Zelle has made it appealing for hackers looking to cash in.

Pakistan-Aligned Transparent Tribe APT Expands Interest in Indian Education Sector

13 April 2023
SentinelLabs has been tracking a recently disclosed cluster of malicious Office documents that distribute Crimson RAT, used by the APT36 group (aka Transparent Tribe) targeting the education sector.

Sixty-three percent of CISOs predict hybrid or remote work to remain

13 April 2023
With the rise of hybrid and remote work environments, security leaders have wondered how best to protect their employees and their networks. 

Former TSB chief information officer fined £81,000 over IT meltdown in 2018

13 April 2023
Former TSB chief information officer fined £81,000 over IT meltdown in 2018 Regulator says Carlos Abarca ‘failed to take reasonable steps’ to ensure outsourcing firm was ready to migrate accounts en masseUK regulators have imposed an £81,000 fine on a former TSB information officer over the bank’s IT meltdown in 2018 that left millions of customers locked out of their accounts.The Prudential Regulation Authority (PRA) said Carlos Abarca, who was TSB’s chief information officer at the time of the meltdown, “failed to take reasonable steps” to ensure that an outsourcing firm owned by TSB’s parent company was ready to carry out the IT migration of customers en masse. Continue reading...

Sixty-six percent of security leaders admit staffing challenges

13 April 2023
Staffing concerns, including talent gaps and limited budgets, remain an obstacle for security leaders to ensure the security of their organizations.

Limit Login Attempts Vulnerability – Patch Now!

13 April 2023
On April 11th, 2023, a software update was released to patch a severe vulnerability within the Limit Login Attempts WordPress security plugin. With over 600,000 installations, it’s among the most popular WordPress plugins in use.

WhatsApp Introduces New Device Verification Feature to Prevent Account Takeover Attacks

13 April 2023
Popular instant messaging app WhatsApp on Thursday announced a new account verification feature that ensures that malware running on a user's mobile device doesn't impact their account. "Mobile device malware is one of the biggest threats to people's privacy and security today because it can take advantage of your phone without your permission and use your WhatsApp to send unwanted messages,"

Push to ban ransomware payments following Australia’s biggest cyberattack

13 April 2023
The Australian government is being pushed to ban the payment of cyber ransoms, usually demanded in cryptocurrency, following a local business suffering a mass data breach and subsequent ransom demand.

Over One Million Financial Records Exposed in Data Incident Involving Fintech Company

13 April 2023
Upon further research, it was identified that the database belonged to NorthOne Bank, a financial technology company that claims to be used by over 320,000 American businesses. It is worth noting that NorthOne is not a full-service bank.

Dan Elston promoted to VP of Risk Management at BayPort Credit Union

13 April 2023
BayPort Credit Union adds a new position to its executive team announcing the promotion of Dan Elston to Vice President of Risk Management.

Hackers Impersonate Ukrainian Nuclear Plant Managing Firm; Hides Malware in Doc

13 April 2023
FortiGuard Labs detected a malicious document masquerading as a communication from Energoatom, a state-run entity responsible for managing Ukraine's nuclear power stations. Threat actors were found using the Havoc Demon backdoor camouflaged as a legitimate component of Microsoft Office. It was even signed with an invalid portal[.]office[.]com certificate.

Threat hunting programs can save organizations from costly security breaches

13 April 2023
Proactive threat hunting helps organizations save money by preventing security breaches and reducing the impact of attacks. For example, a study by IBM found that the average total cost of a breach is $4.35 million.

Hyundai Suffered Data Breach That Impacted Customers in France and Italy

13 April 2023
According to the letter, financial data were not exposed. The number of impacted individuals is still unclear. In response to the incident, the company has taken the impacted systems offline.

New Python-Based "Legion" Hacking Tool Emerges on Telegram

13 April 2023
An emerging Python-based credential harvester and a hacking tool named Legion are being marketed via Telegram as a way for threat actors to break into various online services for further exploitation. Legion, according to Cado Labs, includes modules to enumerate vulnerable SMTP servers, conduct remote code execution (RCE) attacks, exploit unpatched versions of Apache, and brute-force cPanel and

Money Ransomware: The Latest Double Extortion Group

13 April 2023
Researchers warned that the Money ransomware actors employ a human-operated intrusion approach, evidenced by the method of data exfiltration and the execution of the malware sample.

Pakistan-based Transparent Tribe Hackers Targeting Indian Educational Institutions

13 April 2023
The Transparent Tribe threat actor has been linked to a set of weaponized Microsoft Office documents in attacks targeting the Indian education sector using a continuously maintained piece of malware called Crimson RAT. While the suspected Pakistan-based threat group is known to target military and government entities in the country, the activities have since expanded to include the education

Why Shadow APIs are More Dangerous than You Think

13 April 2023
Shadow APIs are a growing risk for organizations of all sizes as they can mask malicious behavior and induce substantial data loss. For those that aren't familiar with the term, shadow APIs are a type of application programming interface (API) that isn't officially documented or supported.  Contrary to popular belief, it's unfortunately all too common to have APIs in production that no one on

Banning TikTok could weaken personal cybersecurity

13 April 2023
TikTok is not the first app to be scrutinized over the potential exposure of U.S. user data, but it is the first widely used app that the U.S. government has proposed banning over privacy and security concerns.

Hacking Play-to-Earn Blockchain Games: The Case Of Manarium

13 April 2023
Manarium uses the architecture comprising a Client-Side (in Unity) and a Service (Firebase data store), and for the winner prize distribution, the Admin will do the process, fetching the data, and calling the Smart Contract to execute a pay function.