Latest Cybersecurity News and Articles


Google Advanced Protection Program gets passkeys for high-risk users

11 July 2024
Google announced that passkeys are now available for high-risk users enrolling in the Advanced Protection Program, ensuring top-notch account security. The program offers free protection for accounts of high-risk individuals.

New Malware Campaign Targeting Spanish Language Victims and the Mining Sector

11 July 2024
Poco RAT was first categorized on February 7, 2024, and has since targeted customers in multiple sectors, with Mining being the primary focus. One company was the most targeted, responsible for 67% of the total volume of campaigns.

Streamlined Security Solutions: PAM for Small to Medium-sized Businesses

11 July 2024
Today, all organizations are exposed to the threat of cyber breaches, irrespective of their scale. Historically, larger companies were frequent targets due to their substantial resources, sensitive data, and regulatory responsibilities, whereas smaller entities often underestimated their attractiveness to hackers. However, this assumption is precarious, as cybercriminals frequently exploit

Diversifying Cyber Teams to Tackle Complex Threats

11 July 2024
A diverse workforce brings different perspectives, experiences, and problem-solving approaches to the table, enabling teams to identify vulnerabilities and develop more robust defense strategies.

Citrix Fixed Critical and High-Severity Bugs in NetScaler Product

11 July 2024
The most severe flaw is an improper authorization issue (CVE-2024-6235) with a CVSS score of 9.4, allowing attackers to access sensitive information through the NetScaler Console IP.

New Poco RAT Targets Spanish-Speaking Victims in Phishing Campaign

11 July 2024
Spanish language victims are the target of an email phishing campaign that delivers a new remote access trojan (RAT) called Poco RAT since at least February 2024. The attacks primarily single out mining, manufacturing, hospitality, and utilities sectors, according to cybersecurity company Cofense. "The majority of the custom code in the malware appears to be focused on anti-analysis,

Universal Code Execution by Chaining Messages in Browser Extensions

11 July 2024
Cybersecurity analyst Eugene Lim discovered the risk posed by this vulnerability, which hackers can exploit by chaining messaging APIs in browsers and extensions, bypassing security measures like the Same Origin Policy.

VMware Fixed Critical SQL Injection Flaw in Aria Automation Platform

11 July 2024
VMware has fixed a high-severity SQL-Injection vulnerability, known as CVE-2024-22280, in its Aria Automation platform. This flaw could allow authenticated users to execute unauthorized database operations through specially crafted SQL queries.

Smishing Triad Targets India with Fraud Surge

11 July 2024
Warnings have been issued in India regarding a rise in fraudulent smishing attacks, with scammers impersonating India Post to deceive people into giving personal information or clicking on malicious links.

DarkGate: Dancing the Samba With Alluring Excel Files

11 July 2024
Campaigns distributing DarkGate malware use various methods like email attachments and malicious ads. A campaign in March-April 2024 used Samba file shares hosting malicious files for DarkGate infections.

PHP Vulnerability Exploited to Spread Malware and Launch DDoS Attacks

11 July 2024
Multiple threat actors have been observed exploiting a recently disclosed security flaw in PHP to deliver remote access trojans, cryptocurrency miners, and distributed denial-of-service (DDoS) botnets. The vulnerability in question is CVE-2024-4577 (CVSS score: 9.8), which allows an attacker to remotely execute malicious commands on Windows systems using Chinese and Japanese language locales. It

GitLab Patches Critical Flaw Allowing Unauthorized Pipeline Jobs

10 July 2024
GitLab has shipped another round of updates to close out security flaws in its software development platform, including a critical bug that allows an attacker to run pipeline jobs as an arbitrary user. Tracked as CVE-2024-6385, the vulnerability carries a CVSS score of 9.6 out of a maximum of 10.0. "An issue was discovered in GitLab CE/EE affecting versions 15.8 prior to 16.11.6, 17.0 prior to

The Stark Truth Behind the Resurgence of Russia’s Fin7

10 July 2024
The Russia-based cybercrime group dubbed "Fin7," known for phishing and malware attacks that have cost victim organizations an estimated $3 billion in losses since 2013, was declared dead last year by U.S. authorities. But experts say Fin7 has roared back to life in 2024 -- setting up thousands of websites mimicking a range of media and technology companies -- with the help of Stark Industries Solutions, a sprawling hosting provider is a persistent source of cyberattacks against enemies of Russia.

Malware campaign targets Spanish-speaking individuals

10 July 2024
A new malware campaign targets Spanish-speaking individuals within the mining sector. 

Most Security Pros Admit Shadow SaaS and AI Use

10 July 2024
A recent Next DLP poll revealed that 73% of cybersecurity professionals used unauthorized apps, including AI, last year. Top concerns were data loss, lack of control, and breaches, with 10% admitting to a breach due to these tools.

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

10 July 2024
In episode 24 of the Cybersecurity & Geopolitical Discussion, our trio of hosts discuss paradoxes surrounding money laundering and the reasons it’s so popular, particularly among well-establish organized criminal gangs.

A vulnerability was discovered in an NSA SkillTree training platform

10 July 2024
Research has unveiled a potential vulnerability within a training platform called SkillTree.

US Busts Russian AI-Driven Disinformation Operation

10 July 2024
The Department of Justice investigated around 1,000 accounts on social media platform X, previously Twitter, which were used by the Kremlin to spread pro-Moscow propaganda created by the AI-driven Meliorator software.

Regional Transport Office Themed Phishing Campaign Targets Android Users In India

10 July 2024
Phishing messages impersonating the Regional Transport Office have been circulating since 2024, claiming traffic violations and prompting users to download a malicious APK named "VAHAN PARIVAHAN.apk".

New Ransomware Group Exploiting Veeam Backup Software Vulnerability

10 July 2024
A now-patched security flaw in Veeam Backup & Replication software is being exploited by a nascent ransomware operation known as EstateRansomware. Singapore-headquartered Group-IB, which discovered the threat actor in early April 2024, said the modus operandi involved the exploitation of CVE-2023-27532 (CVSS score: 7.5) to carry out the malicious activities. Initial access to the target