Latest Cybersecurity News and Articles


Operation First Light Seizes $257m in Global Scam Bust

29 June 2024
Police forces from 61 countries have collaborated in Operation First Light 2024, led by Interpol, resulting in the arrest of 3,950 suspects and the identification of 14,643 more.

Critical GitLab Bug Lets Attackers Run Pipelines as Any User

29 June 2024
A critical vulnerability has been discovered in certain versions of GitLab Community and Enterprise Edition products. This vulnerability allows an attacker to run pipelines as any user.

Examining Water Sigbin's Infection Routine Leading to an XMRig Cryptominer

29 June 2024
A sophisticated multi-stage malware campaign by the threat actor "Water Sigbin" (also known as the 8220 Gang) exploits Oracle WebLogic vulnerabilities to deliver a cryptocurrency miner called XMRig.

MerkSpy: Exploiting CVE-2021-40444 to Infiltrate Systems

29 June 2024
MerkSpy is designed to covertly monitor user activities, capture sensitive information like keystrokes and Chrome login credentials, and exfiltrate the data to the attacker's server.

China-Sponsored Attackers Target 40K Corporate Users in 90 Days

29 June 2024
The campaigns, named LegalQloud, Eqooqp, and Boomer, deploy highly evasive and adaptive threat (HEAT) attack techniques that can bypass multifactor authentication (MFA) and URL filtering.

FTC finds that government impersonation scam payments doubled in 2023

28 June 2024
New Federal Trade Commission (FTC) data reveals that government impersonation scammers are targeting consumers for payments in cash.

New Unfurling Hemlock Threat Actor Floods Systems with Malware

28 June 2024
Unfurling Hemlock is using a new method, referred to as a "malware cluster bomb," which allows the threat actor to use one malware sample to spread additional malware on compromised machines.

Kimsuky Using TRANSLATEXT Chrome Extension to Steal Sensitive Data

28 June 2024
The North Korea-linked threat actor known as Kimsuky has been linked to the use of a new malicious Google Chrome extension that's designed to steal sensitive information as part of an ongoing intelligence collection effort. Zscaler ThreatLabz, which observed the activity in early March 2024, has codenamed the extension TRANSLATEXT, highlighting its ability to gather email addresses, usernames,

Remote Access Giant TeamViewer Says Russian Spies Hacked Its Corporate Network

28 June 2024
TeamViewer, a leading provider of remote access tools, has confirmed that its corporate network is currently under a cyberattack. The company has identified the attackers as a government-backed Russian intelligence group known as APT29.

GitLab Releases Patch for Critical CI/CD Pipeline Vulnerability and 13 Others

28 June 2024
GitLab has released security updates to address 14 security flaws, including one critical vulnerability that could be exploited to run continuous integration and continuous deployment (CI/CD) pipelines as any user. The weaknesses, which affect GitLab Community Edition (CE) and Enterprise Edition (EE), have been addressed in versions 17.1.1, 17.0.3, and 16.11.5. The most severe of the

Kimsuky Deploys TRANSLATEXT to Target South Korean Academia

28 June 2024
Kimsuky uploaded TRANSLATEXT to their attacker-controlled GitHub repository on March 7, 2024, and it is capable of bypassing security measures for prominent email service providers like Gmail, Kakao, and Naver.

Malware Peddlers Experimenting with BPL Sideloading and Masking Malicious Payloads as PGP Keys

28 June 2024
The campaign involves a Bollywood pirate movie download site leading to a Bunny content delivery platform, which then points to a ZIP file. Inside the ZIP file, there is another password-protected ZIP file with a text file containing the password.

Gitleaks: Open-Source Solution for Detecting Secrets in Your Code

28 June 2024
Gitleaks is an open-source tool that detects and prevents hardcoded secrets in Git repositories, like passwords or API keys. It stands out for its easy-to-use and configurable system for scanning secrets.

‘Poseidon’ Mac stealer Distributed via Malicious Google Ads

28 June 2024
A new campaign targeting Mac users through malicious Google ads for the Arc browser has been observed. This is the second time Arc has been used as a lure, indicating its popularity.

Crypto-Gang Leader Convicted of Vicious Kidnaps, Robbery

28 June 2024
A 24-year-old leader of an international robbery crew, Remy St Felix, has been convicted in the US for carrying out violent home invasions to steal cryptocurrency tokens.

8220 Gang Exploits Oracle WebLogic Server Flaws for Cryptocurrency Mining

28 June 2024
Security researchers have shed more light on the cryptocurrency mining operation conducted by the 8220 Gang by exploiting known security flaws in the Oracle WebLogic Server. "The threat actor employs fileless execution techniques, using DLL reflective and process injection, allowing the malware code to run solely in memory and avoid disk-based detection mechanisms," Trend Micro researchers Ahmed

US Federal Agencies Warn Healthcare Sector of Payment Diversion Schemes

28 June 2024
Federal authorities are warning about social engineering and phishing scams that target IT help desk workers and allow attackers to steal login credentials in order to access healthcare sector entities' IT systems.

Nuance Ex-Employee Indicted for Breach Affecting 1 Million

28 June 2024
A former employee of Nuance Communications, a unit of Microsoft, is the main suspect in a 2023 data breach that affected over 1 million patients of Geisinger, a healthcare system based in Pennsylvania.

CISA Report Finds Critical Open-Source Memory Safety Risks

28 June 2024
CISA urges manufacturers to reduce memory safety vulnerabilities by ditching memory-unsafe languages, implementing secure coding practices, and adopting routine security testing measures.

Combatting the Evolving SaaS Kill Chain: How to Stay Ahead of Threat Actors

28 June 2024
The modern kill chain is eluding enterprises because they aren’t protecting the infrastructure of modern business: SaaS.  SaaS continues to dominate software adoption, and it accounts for the greatest share of public cloud spending. But enterprises and SMBs alike haven’t revised their security programs or adopted security tooling built for SaaS.  Security teams keep jamming on-prem