Latest Cybersecurity News and Articles


SeleniumGreed Cryptomining Campaign Exploiting Publicly Exposed Grid Services

26 July 2024
Researchers at Wiz have identified an ongoing campaign targeting exposed Selenium Grid services for illicit cryptocurrency mining. The campaign, known as SeleniumGreed, is exploiting older versions of Selenium to run a modified XMRig miner.

US Indicts Alleged North Korean State Hacker for Ransomware Attacks on Hospitals

26 July 2024
The US has indicted a North Korean state hacker for ransomware attacks on hospitals and healthcare companies. The hacker, Rim Jong Hyok, is a member of the Andariel Unit within North Korea's intelligence agency.

ISC Releases Security Advisories for BIND 9

26 July 2024
The Internet Systems Consortium (ISC) has released patches to fix multiple security vulnerabilities in the BIND 9 DNS software suite that could lead to denial-of-service attacks.

Senator: Top Banks Only Reimburse 38% of Unauthorized Claims

26 July 2024
US Senator Richard Blumenthal revealed that Bank of America, JPMorgan Chase, and Wells Fargo only reimbursed 38% of customers for unauthorized payments, resulting in $100 million in fraud losses.

Thread Name-Calling: Using Thread Name for Offense

26 July 2024
Process Injection is a vital technique used by attackers to evade detection and escalate privileges. Thread Name-Calling has emerged as a new injection technique that abuses Windows APIs for thread descriptions to bypass endpoint protection products.

CrowdStrike Disruption Direct Losses to Reach $5.4B for Fortune 500, Study Finds

26 July 2024
A recent study by Parametrix has found that the global IT outage linked to CrowdStrike will result in at least $5.4 billion in direct financial losses for Fortune 500 companies, excluding Microsoft.

Critical ServiceNow RCE Flaws Actively Exploited to Steal Credentials

26 July 2024
ServiceNow RCE vulnerabilities are being actively exploited to steal credentials. Threat actors are using publicly available exploits to target government agencies and private firms for data theft.

Offensive AI: The Sine Qua Non of Cybersecurity

26 July 2024
"Peace is the virtue of civilization. War is its crime. Yet it is often in the furnace of war that the sharpest tools of peace are forged." - Victor Hugo. In 1971, an unsettling message started appearing on several computers that comprised ARPANET, the precursor to what we now know as the Internet. The message, which read "I'm the Creeper: catch me if you can." was the output of a program named

North Korean Hackers Targeted KnowBe4 with Fake IT Worker

26 July 2024
KnowBe4, a cybersecurity training company, was tricked into hiring a fake IT worker from North Korea, highlighting the threat of insider activities. Despite this, no data breach occurred.

Google Chrome Now Asks for Passwords To Scan Protected Archives

26 July 2024
The new warning messages help users understand the danger posed by each downloaded file from the Internet. Google has implemented a two-tier download warning system using AI-powered malware verdicts from its Safe Browsing service.

Progress Software Fixed Critical Flaw in Telerik Report Server

26 July 2024
The vulnerability, tracked as CVE-2024-6327, allows attackers to execute code on unpatched servers through deserialization of untrusted data. The issue affects Report Server 2024 Q2 (10.1.24.514) and earlier versions.

SocGholish: Fake Update Puts Visitors at Risk

26 July 2024
The recent developments in SocGholish infection tactics target WordPress-based websites. The attack sequence involves initial access through compromised websites with vulnerable WordPress plugins.

Mimecast Acquires Veteran Data Security Firm Code42

26 July 2024
Mimecast has acquired veteran data security firm Code42, adding 175 employees to its team. Code42, founded in 2001, focuses on expanding its data protection platform, Incydr, with recent enhancements for source code exfiltration detection.

U.S. DoJ Indicts North Korean Hacker for Ransomware Attacks on Hospitals

26 July 2024
The U.S. Department of Justice (DoJ) on Thursday unsealed an indictment against a North Korean military intelligence operative for allegedly carrying out ransomware attacks against healthcare facilities in the country and funneling the payments to orchestrate additional intrusions into defense, technology, and government entities across the world. "Rim Jong Hyok and his co-conspirators deployed

Patchwork Group Found Using Brute Ratel C4 and an Enhanced Version of PGoShell Backdoor

26 July 2024
Patchwork hackers targeted Bhutan using the advanced Brute Ratel C4 tool, along with an updated backdoor called PGoShell. This marks the first time Patchwork has been observed using the red teaming software.

Email Gateway Security Gaps Enable New Malware Tactics

26 July 2024
Email security gaps in gateway defenses have allowed phishing hackers to sneak malware past static scanning functions. Hackers hid malicious attachments by using a decoy file extension in a compressed archive.

Ongoing Cyberattack Targets Exposed Selenium Grid Services for Crypto Mining

26 July 2024
Cybersecurity researchers are sounding the alarm over an ongoing campaign that's leveraging internet-exposed Selenium Grid services for illicit cryptocurrency mining. Cloud security firm Wiz is tracking the activity under the name SeleniumGreed. The campaign, which is targeting older versions of Selenium (3.141.59 and prior), is believed to be underway since at least April 2023. "Unbeknownst to

CrowdStrike Warns of New Phishing Scam Targeting German Customers

26 July 2024
CrowdStrike is alerting about an unfamiliar threat actor attempting to capitalize on the Falcon Sensor update fiasco to distribute dubious installers targeting German customers as part of a highly targeted campaign. The cybersecurity company said it identified what it described as an unattributed spear-phishing attempt on July 24, 2024, distributing an inauthentic CrowdStrike Crash Reporter

Critical Flaw in Telerik Report Server Poses Remote Code Execution Risk

26 July 2024
Progress Software is urging users to update their Telerik Report Server instances following the discovery of a critical security flaw that could result in remote code execution. The vulnerability, tracked as CVE-2024-6327 (CVSS score: 9.9), impacts Report Server version 2024 Q2 (10.1.24.514) and earlier. "In Progress Telerik Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code

One year after SEC cyber disclosure ruling, security leaders weigh in

26 July 2024
With a year in the rearview mirror, security professionals are reflecting on the SEC cyber disclosure ruling.