Latest Cybersecurity News and Articles


Sellafield ordered to pay nearly £400,000 over cybersecurity failings

02 October 2024
Sellafield ordered to pay nearly £400,000 over cybersecurity failings Nuclear waste dump in Cumbria pleaded guilty to leaving data that could threaten national security exposed for four years, says regulatorSellafield will have to pay almost £400,000 after it pleaded guilty to criminal charges over years of cybersecurity failings at Britain’s most hazardous nuclear site.The vast nuclear waste dump in Cumbria left information that could threaten national security exposed for four years, according to the industry regulator, which brought the charges. It was also found that 75% of its computer servers were vulnerable to cyber-attack. Continue reading...

China-Linked CeranaKeeper Targeting Southeast Asia with Data Exfiltration

02 October 2024
A previously undocumented threat actor called CeranaKeeper has been linked to a string of data exfiltration attacks targeting Southeast Asia. Slovak cybersecurity firm ESET, which observed campaigns targeting governmental institutions in Thailand starting in 2023, attributed the activity cluster as aligned to China, leveraging tools previously identified as used by the Mustang Panda actor. "The

Fake Job Applications Deliver Dangerous More_eggs Malware to HR Professionals

02 October 2024
A spear-phishing email campaign has been observed targeting recruiters with a JavaScript backdoor called More_eggs, indicating persistent efforts to single out the sector under the guise of fake job applicant lures. "A sophisticated spear-phishing lure tricked a recruitment officer into downloading and executing a malicious file disguised as a resume, leading to a more_eggs backdoor infection,"

Alert: Over 700,000 DrayTek Routers Exposed to Hacking via 14 New Vulnerabilities

02 October 2024
A little over a dozen new security vulnerabilities have been discovered in residential and enterprise routers manufactured by DrayTek that could be exploited to take over susceptible devices. "These vulnerabilities could enable attackers to take control of a router by injecting malicious code, allowing them to persist on the device and use it as a gateway into enterprise networks," Forescout

Microsoft Alert: New INC Ransomware Targets US Healthcare

02 October 2024
As per a recent Microsoft alert, a threat actor with malicious financial motives has been observed leveraging a new INC ransomware strain to target the health sector in the United States (US).

Addressing Git Vulnerabilities in Ubuntu 18.04 and 16.04

02 October 2024
Canonical has released security updates for Ubuntu 16.04 ESM and Ubuntu 18.04 ESM to address multiple vulnerabilities in Git, a powerful and widely-used distributed version control system.

Alert: Adobe Commerce and Magento Stores Under Attack from CosmicSting Exploit

02 October 2024
Cybersecurity researchers have disclosed that 5% of all Adobe Commerce and Magento stores have been hacked by malicious actors by exploiting a security vulnerability dubbed CosmicSting. Tracked as CVE-2024-34102 (CVSS score: 9.8), the critical flaw relates to an improper restriction of XML external entity reference (XXE) vulnerability that could result in remote code execution. The shortcoming,

90% of U.S. companies admit to using AI in some capacity

02 October 2024
The use of artificial intelligence (AI) by information technology (IT) professionals in the U.S. was analyzed in a recent report by GetApp. 

5 Must-Have Tools for Effective Dynamic Malware Analysis

02 October 2024
Dynamic malware analysis is a key part of any threat investigation. It involves executing a sample of a malicious program in the isolated environment of a malware sandbox to monitor its behavior and gather actionable indicators. Effective analysis must be fast, in-depth, and precise. These five tools will help you achieve it with ease. 1. Interactivity Having the ability to interact with the

Andariel Hacking Group Shifts Focus to Financial Attacks on U.S. Organizations

02 October 2024
Three different organizations in the U.S. were targeted in August 2024 by a North Korean state-sponsored threat actor called Andariel as part of a likely financially motivated attack. "While the attackers didn't succeed in deploying ransomware on the networks of any of the organizations affected, it is likely that the attacks were financially motivated," Symantec, part of Broadcom, said in a

Community Clinic of Maui says 123,000 affected by May cyberattack

02 October 2024
The clinic said the hackers had access to personal data between May 4 and May 7, stealing information including Social Security numbers, passport numbers, financial account numbers with CVV numbers and expiration dates.

Evil Corp hit with new sanctions, BitPaymer ransomware charges

02 October 2024
The Evil Corp cybercrime syndicate has been hit with new sanctions by the United States, United Kingdom, and Australia. The US also indicted one of its members for conducting BitPaymer ransomware attacks.

AI-Powered Rhadamanthys Stealer Targets Crypto Wallets with Image Recognition

02 October 2024
The threat actors behind the Rhadamanthys information stealer have added new advanced features to the malware, including using AI for optical character recognition (OCR) as part of what's called "Seed Phrase Image Recognition.

Researchers Sound Alarm on Active Attacks Exploiting Critical Zimbra Postjournal Flaw

02 October 2024
Cybersecurity researchers are warning about active exploitation attempts targeting a newly disclosed security flaw in Synacor's Zimbra Collaboration. Enterprise security firm Proofpoint said it began observing the activity starting September 28, 2024. The attacks seek to exploit CVE-2024-45519, a severe security flaw in its postjournal service that could enable unauthenticated attackers to

PyPI Repository Found Hosting Fake Crypto Wallet Recovery Tools That Steal User Data

02 October 2024
A new set of malicious packages has been unearthed in the Python Package Index (PyPI) repository that masqueraded as cryptocurrency wallet recovery and management services, only to siphon sensitive data and facilitate the theft of valuable digital assets. "The attack targeted users of Atomic, Trust Wallet, Metamask, Ronin, TronLink, Exodus, and other prominent wallets in the crypto ecosystem,"

Iran-linked Threat Group Handala Actively Targets Israel

02 October 2024
Handala's most serious claims are unverified, but the Iranian threat group's actions have led to numerous account suspensions and website shutdowns due to its persistent activities.

Cyble Researchers Uncover Sophisticated Attack Using VSCode for Remote Access

02 October 2024
Cyble researchers have uncovered a sophisticated campaign that starts with a suspicious .LNK file and uses VSCode to establish persistence and remote access – and installs the VSCode CLI if VSCode isn’t found on the victim machine.

Zimbra RCE Vuln Under Attack Needs Immediate Patching

02 October 2024
Attackers are actively targeting a severe remote code execution vulnerability that Zimbra recently disclosed in its SMTP server, heightening the urgency for affected organizations to patch vulnerable instances right away.

Crook made millions by breaking into execs’ Office365 inboxes, feds say

02 October 2024
Federal prosecutors have charged a man for an alleged “hack-to-trade” scheme that earned him millions of dollars by breaking into the Office365 accounts of executives at publicly traded companies.

New PyPI Malware Poses as Crypto Wallet Tools to Steal Private Keys

02 October 2024
Checkmarx researchers discovered PyPI malware posing as crypto wallet tools. These malicious packages stole private keys and recovery phrases, targeting wallets like Metamask, Trust Wallet, and Exodus.