Latest Cybersecurity News and Articles


AI is responsible for 40% of business email compromise (BEC) emails

07 August 2024
According to a recent report, 40% of BEC emails are generated by AI. 

Abnormal Security Raises $250M on $5.1B Valuation to Enhance AI-Driven Cyber Protection

07 August 2024
Abnormal Security, an AI-driven cybersecurity company, has raised $250 million in funding, valuing the company at $5.1 billion. The funding will support their mission of using AI to protect against cybercrime by understanding human behavior.

Chameleon Malware Now Targeting Employees Masquerading as a CRM app

07 August 2024
Researchers have revealed a new tactic used by threat actors behind the Chameleon Android banking trojan, targeting Canadian users with a disguised Customer Relationship Management (CRM) app.

Replacement for Action Fraud, UK’s Cybercrime Reporting Service, Delayed Again Until 2025

07 August 2024
The new service, known as the Fraud and Cyber Crime Reporting and Analysis System (FCCRAS), will enhance the reporting process by allowing users to upload additional information like metadata, screenshots, and images.

The Role of AI in Cybersecurity Operations

07 August 2024
AI can analyze data quickly, detect patterns of malicious behavior, and automate routine tasks like alert triaging and log analysis. However, human oversight is still necessary to ensure the accuracy and relevance of AI-generated insights.

New Go-based Backdoor GoGra Targets South Asian Media Organization

07 August 2024
An unnamed media organization in South Asia was targeted in November 20233 using a previously undocumented Go-based backdoor called GoGra. "GoGra is written in Go and uses the Microsoft Graph API to interact with a command-and-control (C&C) server hosted on Microsoft mail services," Symantec, part of Broadcom, said in a report shared with The Hacker News. It's currently not clear how it's

The Prevalence of DarkComet in Dynamic DNS

07 August 2024
A recent analysis using HYAS Insight threat intelligence revealed a trend in dynamic DNS registrations originating from Turkey in 2024, with DarkComet malware representing over 50% of the malicious domains identified.

CrowdStrike Reveals Root Cause of Global System Outages

07 August 2024
Cybersecurity company CrowdStrike has published its root cause analysis detailing the Falcon Sensor software update crash that crippled millions of Windows devices globally. The "Channel File 291" incident, as originally highlighted in its Preliminary Post Incident Review (PIR), has been traced back to a content validation issue that arose after it introduced a new Template Type to enable

Police Recover Over $40m Headed to BEC Scammers

07 August 2024
A Singaporean commodity firm has had a narrow escape after police managed to intervene to recover nearly all of the $42.3m lost to fraudsters in a business email compromise (BEC) scam.

Florida Firm Sued Over Theft of 2.9B Personal Records

07 August 2024
A class-action lawsuit is brewing over the cyber-heist of 2.9 billion personal records that were stolen from a Florida data broker, Jerico Pictures, doing business as National Public Data, and sold on the dark web.

NCSC CEO shares insights into securing UK elections in cyber space at major international conference

07 August 2024
Felicity Oswald shares reflections on the UK approach to election security at Black Hat USA conference.

CISA Adds Microsoft COM for Windows Bug to its Known Exploited Vulnerabilities Catalog

07 August 2024
The vulnerability, tracked as CVE-2018-0824, arises from the deserialization of untrusted data. Microsoft warns that this flaw could lead to remote code execution if exploited by a specially crafted file or script.

Attackers Use Multiple Techniques to Bypass Reputation-Based Security

07 August 2024
Attackers have developed multiple techniques to bypass reputation-based security controls like Windows Smart App Control, allowing them initial access to environments without triggering alerts.

NHS IT firm faces £6m fine over medical records hack

07 August 2024
NHS IT firm faces £6m fine over medical records hack Watchdog says Advanced software firm failed to protect data of thousands affected by 2022 ransomware attack in EnglandA software provider faces being fined more than £6m over a 2022 ransomware attack that disrupted NHS and social care services in England, the data protection regulator has announced.The Information Commissioner’s Office (ICO) said it had provisionally found that Advanced Computer Software Group had failed to implement measures to protect the personal information of 82,946 people who were affected by the attack, which included some sensitive information. Continue reading...

Chameleon Android Banking Trojan Targets Users Through Fake CRM App

07 August 2024
Cybersecurity researchers have lifted the lid on a new technique adopted by threat actors behind the Chameleon Android banking trojan targeting users in Canada by masquerading as a Customer Relationship Management (CRM) app. "Chameleon was seen masquerading as a CRM app, targeting a Canadian restaurant chain operating internationally," Dutch security outfit ThreatFabric said in a technical

Apple’s New macOS Sequoia Tightens Gatekeeper Controls to Block Unauthorized Software

07 August 2024
Apple on Tuesday announced an update to its next-generation macOS version that makes it a little more difficult for users to override Gatekeeper protections. Gatekeeper is a crucial line of defense built into macOS designed to ensure that only trusted apps run on the operating system. When an app is downloaded from outside of the App Store and opened for the first time, it verifies that the

62% of phishing emails can bypass DMARC verification checks

07 August 2024
An analysis of 17.8 million phishing emails found 62% were able to pass verification checks for domain-based message authentication, reporting and conformance (DMARC).

INTERPOL Recovers $41 Million in Largest Ever BEC Scam in Singapore

06 August 2024
INTERPOL said it devised a "global stop-payment mechanism" that helped facilitate the largest-ever recovery of funds defrauded in a business email compromise (BEC) scam.  The development comes after an unnamed commodity firm based in Singapore fell victim to a BEC scam in mid-July 2024. It refers to a type of cybercrime where a malicious actor poses as a trusted figure and uses email to

86% of cyber professionals cite unknown cyber risks as a top concern

06 August 2024
Security leaders respond to a report that states 86% of cyber professionals consider unknown cyber risks to be a top concern.

Bloody Wolf Strikes Organizations in Kazakhstan with STRRAT Commercial Malware

06 August 2024
The STRRAT malware, sold for $80, allows attackers to take control of computers and steal data. Attackers use phishing emails pretending to be from government agencies to trick victims into downloading malicious files.