Latest Cybersecurity News and Articles


Report: Hackers Use PoC Exploits in Attacks 22 Minutes After Release

16 July 2024
Threat actors rapidly weaponize proof-of-concept exploits in real attacks, often within 22 minutes of their public release, as per Cloudflare's 2024 Application Security report covering May 2023 to March 2024.

New BugSleep Backdoor Deployed in Recent MuddyWater Campaigns

16 July 2024
The deployment of BugSleep is a significant development in MuddyWater's tactics, targeting various sectors with phishing emails leading to the distribution of Remote Management Tools and the BugSleep malware.

Kaspersky Exits U.S. Market Following Commerce Department Ban

16 July 2024
Russian security vendor Kaspersky has said it's exiting the U.S. market nearly a month after the Commerce Department announced a ban on the sale of its software in the country citing a national security risk. News of the closure was first reported by journalist Kim Zetter. The company is expected to wind down its U.S. operations on July 20, 2024, the same day the ban comes into effect. It's also

CISA Warns of Actively Exploited RCE Flaw in GeoServer GeoTools Software

16 July 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical security flaw impacting OSGeo GeoServer GeoTools to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. GeoServer is an open-source software server written in Java that allows users to share and edit geospatial data. It is the reference implementation of the Open

Over 4000 Domains Used By FIN7 Actors Mimic Popular Brands

15 July 2024
By targeting famous brands like tech firms and financial industry players, FIN7 actors deploy redirects, multi-stage phishing campaigns, and impersonate open directories to spread malware.

Malvertising Campaign Lures Mac Users with Fake Microsoft Teams Ad

15 July 2024
The malicious ad campaign employed advanced filtering techniques to evade detection and appeared as a top search result for Microsoft Teams. It redirected users through deceptive links despite displaying microsoft.com as its URL.

CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth

15 July 2024
The US Cybersecurity and Infrastructure Security Agency (CISA) conducted a red team exercise at an unnamed federal agency in 2023, exposing serious security failings that left critical assets vulnerable.

GitHub Token Leak Exposes Python's Core Repositories to Potential Attacks

15 July 2024
Cybersecurity researchers said they discovered an accidentally leaked GitHub token that could have granted elevated access to the GitHub repositories of the Python language, Python Package Index (PyPI), and the Python Software Foundation (PSF) repositories. JFrog, which found the GitHub Personal Access Token, said the secret was leaked in a public Docker container hosted on Docker Hub. "This

Researchers: Weak Security Defaults Enabled Squarespace Domains Hijacks

15 July 2024
At least a dozen organizations with domain names at domain registrar Squarespace saw their websites hijacked last week. Squarespace bought all assets of Google Domains a year ago, but many customers still haven't set up their new accounts. Experts say malicious hackers learned they could commandeer any migrated Squarespace accounts that hadn't yet been registered, merely by supplying an email address tied to an existing domain.

Zeus Banking Malware Player Gets Nine-Year Prison Term

15 July 2024
Vyacheslav Igorevich Penchukov, a criminal who used Zeus and IcedID malware to steal millions of dollars from victims, has been sentenced to almost a decade in prison and ordered to pay $73 million in restitution by a Nebraska federal court judge.

Netgear Warns Users to Patch Auth Bypass, XSS Router Flaws

15 July 2024
Netgear released firmware patches to fix stored XSS and authentication bypass flaws in the XR1000 Nighthawk gaming router and CAX30 Nighthawk AX6 6-Stream cable modem routers, respectively.

10,000 Victims a Day: Infostealer Garden of Low-Hanging Fruit

15 July 2024
Imagine you could gain access to any Fortune 100 company for $10 or less, or even for free. Terrifying thought, isn’t it? Or exciting, depending on which side of the cybersecurity barricade you are on. Well, that’s basically the state of things today. Welcome to the infostealer garden of low-hanging fruit. Over the last few years, the problem has grown bigger and bigger, and only now are we

Google Reportedly in Talks to Acquire Cloud Security Company Wiz for $23B

15 July 2024
Alphabet, Google's parent company, is in advanced talks to acquire cloud security provider Wiz for around $23 billion. Wiz recently raised $1 billion at a $12 billion valuation and has a total of $1.9 billion in funding.

CRYSTALRAY Hackers Infect Over 1,500 Victims Using Network Mapping Tool

15 July 2024
A threat actor that was previously observed using an open-source network mapping tool has greatly expanded their operations to infect over 1,500 victims. Sysdig, which is tracking the cluster under the name CRYSTALRAY, said the activities have witnessed a 10x surge, adding it includes "mass scanning, exploiting multiple vulnerabilities, and placing backdoors using multiple [open-source software]

Palo Alto Networks Fixed a Critical Bug in the Expedition Tool

15 July 2024
Palo Alto Networks has released security updates to address five vulnerabilities in its products, including a critical flaw in the Expedition tool that could enable admin account takeover.

NATO Set to Build New Cyber Defense Center

15 July 2024
The new cyber-defense facility, dubbed NATO Integrated Cyber Defence Centre (NICC), will be located in Belgium at SHAPE and will consist of civilian and military experts from member states.

Signal Downplays Encryption Key Flaw, Fixes it After X Drama

15 July 2024
Signal has now taken steps to address the issue by integrating Electron's SafeStorage API to secure the data store from offline attacks. The new implementation is currently being tested and will soon be available in a Beta version.

White House Calls for Defending Critical Infrastructure

15 July 2024
The Office of Management and Budget has issued a memorandum outlining the administration's cybersecurity priorities for fiscal year 2026, aligning with the national cybersecurity strategy.

CISA Urges Software Makers to Eliminate OS Command Injection Flaws

15 July 2024
The US government is pressuring software manufacturers to address operating system command injection vulnerabilities following high-profile threat actor campaigns exploiting these flaws in 2024.

Several DOD IT Programs Still Don’t Have a Cyber Strategy, Watchdog Finds

15 July 2024
The U.S. Government Accountability Office's annual assessment of the Defense Department's IT spending revealed that several programs lack approved cybersecurity strategies, leaving them vulnerable to potential cyberattacks.