Latest Cybersecurity News and Articles


Phone Phishing Gang Busted: Eight Arrested in Belgium and Netherlands

10 December 2024
Belgian and Dutch authorities have arrested eight suspects in connection with a "phone phishing" gang that primarily operated out of the Netherlands with an aim to steal victims' financial data and funds. As part of the international operation, law enforcement agencies carried out 17 searches in different locations in Belgium and the Netherlands, Europol said. In addition, large amounts of cash,

Hackers Weaponize Visual Studio Code Remote Tunnels for Cyber Espionage

10 December 2024
A suspected China-nexus cyber espionage group has been attributed to an attacks targeting large business-to-business IT service providers in Southern Europe as part of a campaign codenamed Operation Digital Eye. The intrusions took place from late June to mid-July 2024, cybersecurity companies SentinelOne SentinelLabs and Tinexta Cyber said in a joint report shared with The Hacker News, adding

82% of security leaders say AI may raise toxic combination challenges

10 December 2024
Research shows that AI and IT complexity may lead to greater toxic combination challenges.

Ongoing Phishing and Malware Campaigns in December 2024

10 December 2024
Cyber attackers never stop inventing new ways to compromise their targets. That's why organizations must stay updated on the latest threats.  Here's a quick rundown of the current malware and phishing attacks you need to know about to safeguard your infrastructure before they reach you. Zero-day Attack: Corrupted Malicious Files Evade Detection by Most Security Systems  The analyst

CERT-UA Warns of Phishing Attacks Targeting Ukraine’s Defense and Security Force

10 December 2024
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new set of cyber attacks that it said were aimed at defense companies in the country as well as its security and defense forces. The phishing attacks have been attributed to a Russia-linked threat actor called UAC-0185 (aka UNC4221), which has been active since at least 2022. "The phishing emails mimicked official messages

Black Basta Ransomware Evolves with Email Bombing, QR Codes, and Social Engineering

09 December 2024
The threat actors linked to the Black Basta ransomware have been observed switching up their social engineering tactics, distributing a different set of payloads such as Zbot and DarkGate since early October 2024. "Users within the target environment will be email bombed by the threat actor, which is often achieved by signing up the user's email to numerous mailing lists simultaneously," Rapid7

FCC Chair proposes action to protect nation’s communications systems

09 December 2024
A chairwoman for the FCC has made cybersecurity proposal for telecommunication organizations in light of recent hacking events.  

FTC orders Marriott to implement information security program

09 December 2024
The FTC will require Marriott and its subsidiary Starwood Hotels & Resorts to implement an information security program following three data breaches.

⚡ THN Recap: Top Cybersecurity Threats, Tools and Tips (Dec 2 - 8)

09 December 2024
This week’s cyber world is like a big spy movie. Hackers are breaking into other hackers’ setups, sneaky malware is hiding in popular software, and AI-powered scams are tricking even the smartest of us. On the other side, the good guys are busting secret online markets and kicking out shady chat rooms, while big companies rush to fix new security holes before attackers can jump in. Want to

Researchers Uncover Prompt Injection Vulnerabilities in DeepSeek and Claude AI

09 December 2024
Details have emerged about a now-patched security flaw in the DeepSeek artificial intelligence (AI) chatbot that, if successfully exploited, could permit a bad actor to take control of a victim's account by means of a prompt injection attack. Security researcher Johann Rehberger, who has chronicled many a prompt injection attack targeting various AI tools, found that providing the input "Print

Seven Bolt-Ons to Make Your Entra ID More Secure for Critical Sessions

09 December 2024
Identity security is all the rage right now, and rightfully so. Securing identities that access an organization’s resources is a sound security model. But IDs have their limits, and there are many use cases when a business should add other layers of security to a strong identity. And this is what we at SSH Communications Security want to talk about today. Let’s look at seven ways to add

Socks5Systemz Botnet Powers Illegal Proxy Service with 85,000+ Hacked Devices

09 December 2024
A malicious botnet called Socks5Systemz is powering a proxy service called PROXY.AM, according to new findings from Bitsight. "Proxy malware and services enable other types of criminal activity adding uncontrolled layers of anonymity to the threat actors, so they can perform all kinds of malicious activity using chains of victim systems," the company's security research team said in an analysis

Experts say Chinese hacking campaign underscores value of mobile data

09 December 2024
The recent Chinese hacking campaign against telecommunications companies underscores value of mobile data. 

Ultralytics AI Library Compromised: Cryptocurrency Miner Found in PyPI Versions

07 December 2024
In yet another software supply chain attack, it has come to light that two versions of a popular Python artificial intelligence (AI) library named ultralytics were compromised to deliver a cryptocurrency miner. The versions, 8.3.41 and 8.3.42, have since been removed from the Python Package Index (PyPI) repository. A subsequently released version has introduced a security fix that "ensures

Learn How Experts Secure Privileged Accounts—Proven PAS Strategies Webinar

07 December 2024
Cybercriminals know that privileged accounts are the keys to your kingdom. One compromised account can lead to stolen data, disrupted operations, and massive business losses. Even top organizations struggle to secure privileged accounts. Why? Traditional Privileged Access Management (PAM) solutions often fall short, leaving: Blind spots that limit full visibility. Complex deployment processes.

Hackers Using Fake Video Conferencing Apps to Steal Web3 Professionals' Data

07 December 2024
Cybersecurity researchers have warned of a new scam campaign that leverages fake video conferencing apps to deliver an information stealer called Realst targeting people working in Web3 under the guise of fake business meetings. "The threat actors behind the malware have set up fake companies using AI to make them increase legitimacy," Cado Security researcher Tara Gould said. "The company

Romania Cancels Presidential Election Results After Alleged Russian Meddling on TikTok

07 December 2024
In a historic decision, Romania's constitutional court has annulled the result of the first round of voting in the presidential election amid allegations of Russian interference. As a result, the second round vote, which was scheduled for December 8, 2024, will no longer take place. Călin Georgescu, who won the first round, denounced the verdict as an "officialized coup" and an attack on

U.S. Copyright Office states common AI research does not violate DMCA

06 December 2024
The U.S. Copyright Office has clarified legal rules for trustworthiness research and red teaming of artificial intelligence. 

FSB Uses Trojan App to Monitor Russian Programmer Accused of Supporting Ukraine

06 December 2024
A Russian programmer accused of donating money to Ukraine had his Android device secretly implanted with spyware by the Federal Security Service (FSB) after he was detained earlier this year. The findings come as part of a collaborative investigation by First Department and the University of Toronto's Citizen Lab. "The spyware placed on his device allows the operator to track a target device's

Researchers Uncover Flaws in Popular Open-Source Machine Learning Frameworks

06 December 2024
Cybersecurity researchers have disclosed multiple security flaws impacting open-source machine learning (ML) tools and frameworks such as MLflow, H2O, PyTorch, and MLeap that could pave the way for code execution. The vulnerabilities, discovered by JFrog, are part of a broader collection of 22 security shortcomings the supply chain security company first disclosed last month. Unlike the first