Latest Cybersecurity News and Articles


To Improve Your Cybersecurity Posture, Focus on the Data

20 August 2024
To bolster cybersecurity, focus on managing and utilizing enterprise data efficiently. Companies possess significant data reserves, yet these are often scattered across different systems, necessitating manual efforts to extract value.

2 out of 3 Americans cannot distinguish AI voices from real voices

20 August 2024
A survey has revealed that 2 out of 3 Americans cannot distinguish AI voices from real voices. 

Hackers Linked to $14M Holograph Crypto Heist Arrested in Italy

20 August 2024
Suspected hackers who stole $14 million worth of cryptocurrency from Holograph, a blockchain tech firm, have been arrested in Italy after living a lavish lifestyle for weeks in luxury villas.

36% of global internet traffic originated from bots

20 August 2024
A recent report report found that 91% of cyberattacks – up from 69% in 2023 – targeted multiple customers using mass scanning techniques.

UK: NCSC Opens Cyber Resilience Audit Scheme to Applicants

20 August 2024
The NCSC has launched the Cyber Resilience Audit (CRA) scheme to find auditors for a new cyber-resilience initiative. It focuses on conducting independent audits based on the Cyber Assessment Framework (CAF) to support nationally critical sectors.

Russia-linked Vermin Hackers Target Ukraine With new Malware Strain

20 August 2024
CERT-UA has identified the deployment of two malicious tools by Vermin: Spectr spyware, which can capture screenshots and steal data, and a new malware strain called Firmachagent, which is used to upload stolen data.

OpenAI Kills Iranian Accounts Spreading Us Election Disinformation

20 August 2024
The operation was linked to Iran's Storm-2035, also flagged by Microsoft for election interference. Google has also reported Iranian cyber influence activity. OpenAI identified 12 X accounts and one Instagram account involved in the operation.

Common API Security Issues: From Exposed Secrets To Unauthorized Access

20 August 2024
API security is a major concern due to issues like exposed secrets and unauthorized access, leading to serious vulnerabilities for many organizations. A recent report shoed 35% of exposed API keys are still active, posing significant security risks.

Cybercriminals Exploit Popular Software Searches to Spread FakeBat Malware

20 August 2024
Cybercriminals are using popular software searches to spread FakeBat malware, a loader linked to threat actor Eugenfest and identified by Google's threat intelligence team as NUMOZYLOD.

Ransomware Resilience Drives Down Cyber Insurance Claims

20 August 2024
Ransomware resilience is leading to a decrease in cyber insurance claims, as reported by UK backup solutions provider Databarracks. While more organizations are investing in cyber insurance, the number of claims has dropped significantly.

Digital Wallets can Allow Purchases With Stolen Credit Cards

20 August 2024
Once a stolen card is added to the attacker's wallet, they can use it to make purchases without being detected, even after the original card has been canceled. Recurring transactions are also vulnerable to abuse, allowing payments with locked cards.

x64dbg: Open-Source Binary Debugger for Windows

20 August 2024
x64dbg is an open-source binary debugger for Windows, perfect for malware analysis and reverse engineering executables. It has a user-friendly UI that simplifies navigation and provides context on the process.

Xeon Sender Enables Large-Scale SMS Spam Attacks Using Legitimate SaaS Providers

20 August 2024
Xeon Senderallows attackers to conduct large-scale SMS spam and phishing campaigns using legitimate SaaS providers. Distributed through Telegram and hacking forums, it requires API credentials from popular providers like Amazon SNS and Twilio.

Chrome Will Redact Credit Cards, Passwords When You Share Android Screen

20 August 2024
Google is testing a feature in Chrome on Android to redact credit card details, passwords, and sensitive information when sharing your screen. Google aims to prevent leaks of sensitive data while recording or sharing screens.

RansomHub threat actors observed using EDR-killing tool

20 August 2024
Security leaders weigh in on a recent ransomware encounter deploying an EDR-killing tool. 

New UULoader Malware Distributes Gh0st RAT and Mimikatz in East Asia

20 August 2024
The Cyberint Research Team discovered that the malware, believed to be the work of a Chinese speaker, contains core files in a Microsoft Cabinet archive, with executables vulnerable to DLL side-loading.

US Bipartisan Committee Urges Investigation Into Chinese Wi-Fi Routers

20 August 2024
House members John Moolenaar and Raja Krishnamoorthi expressed worries about TP-Link Technologies, the world's top Wi-Fi product provider, being vulnerable to compromised by state-sponsored hackers from China.

Multiple Microsoft Apps for macOS Vulnerable to Library Injection Attacks

20 August 2024
Microsoft has classified the issue as low-severity and has not issued any fixes, except for Teams and OneNote apps. Excel, Outlook, PowerPoint, and Word apps remain vulnerable.

Authentik: Open-Source Identity Provider

20 August 2024
Authentik is known for its adaptability and flexibility. It seamlessly integrates into existing environments, offering support for various protocols. It simplifies tasks like sign-up and account recovery in applications.

Update: Ransomware Attack on Indian Payment System Traced Back to Jenkins Bug

20 August 2024
A recent ransomware attack on Indian payment systems has been traced back to a vulnerability in the widely used Jenkins automation system. The attack targeted a digital payment system used by many Indian banks.