Latest Cybersecurity News and Articles


FBI Distributes 7,000 LockBit Ransomware Decryption Keys to Help Victims

07 June 2024
The U.S. Federal Bureau of Investigation (FBI) has disclosed that it's in possession of more than 7,000 decryption keys associated with the LockBit ransomware operation to help victims get their data back at no cost. "We are reaching out to known LockBit victims and encouraging anyone who suspects they were a victim to visit our Internet Crime Complaint Center at ic3.gov," FBI Cyber Division

SPECTR Malware Targets Ukraine Defense Forces in SickSync Campaign

07 June 2024
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of cyber attacks targeting defense forces in the country with a malware called SPECTR as part of an espionage campaign dubbed SickSync. The agency attributed the attacks to a threat actor it tracks under the moniker UAC-0020, which is also called Vermin and is assessed to be associated with security agencies of the Luhansk

Commando Cat Cryptojacking Attacks Target Misconfigured Docker Instances

07 June 2024
The threat actor known as Commando Cat has been linked to an ongoing cryptojacking attack campaign that leverages poorly secured Docker instances to deploy cryptocurrency miners for financial gain. "The attackers used the cmd.cat/chattr docker image container that retrieves the payload from their own command-and-control (C&C) infrastructure," Trend Micro researchers Sunil Bharti and Shubham

90% of U.S. consumers prioritize personal information security

07 June 2024
A new report surveys financial service consumers with the purpose of understanding their priorities and concerns. 

97% of security experts worry about AI-related security incidents

06 June 2024
A new report highlights trends in AI-powered attacks and cybersecurity strategies. 

Muhstik Botnet Exploiting Apache RocketMQ Flaw to Expand DDoS Attacks

06 June 2024
The distributed denial-of-service (DDoS) botnet known as Muhstik has been observed leveraging a now-patched security flaw impacting Apache RocketMQ to co-opt susceptible servers and expand its scale. "Muhstik is a well-known threat targeting IoT devices and Linux-based servers, notorious for its ability to infect devices and utilize them for cryptocurrency mining and launching Distributed Denial

Cyberattack shuts down Seattle Public Library systems

06 June 2024
The Seattle Public Library experienced a cyberattack that forced it to shut down its systems. 

Third-Party Cyber Attacks: The Threat No One Sees Coming – Here's How to Stop Them

06 June 2024
Learn about critical threats that can impact your organization and the bad actors behind them from Cybersixgill’s threat experts. Each story shines a light on underground activities, the threat actors involved, and why you should care, along with what you can do to mitigate risk.  In an increasingly interconnected world, supply chain attacks have emerged as a formidable threat, compromising

Prevent Account Takeover with Better Password Security

06 June 2024
Tom works for a reputable financial institution. He has a long, complex password that would be near-impossible to guess. He’s memorized it by heart, so he started using it for his social media accounts and on his personal devices too. Unbeknownst to Tom, one of these sites has had its password database compromised by hackers and put it up for sale on the dark web. Now threat actors are working

Hackers Exploit Legitimate Packer Software to Spread Malware Undetected

06 June 2024
Threat actors are increasingly abusing legitimate and commercially available packer software such as BoxedApp to evade detection and distribute malware such as remote access trojans and information stealers. "The majority of the attributed malicious samples targeted financial institutions and government industries," Check Point security researcher Jiri Vinopal said in an analysis. The volume of

Google Maps Timeline Data to be Stored Locally on Your Device for Privacy

06 June 2024
Google has announced plans to store Maps Timeline data locally on users' devices instead of their Google account effective December 1, 2024. The changes were originally announced by the tech giant in December 2023, alongside changes to the auto-delete control when enabling Location History by setting it to three months by default, down from the previous limit of 18 months. Google Maps Timeline,

Hackers Target Python Developers with Fake "Crytic-Compilers" Package on PyPI

06 June 2024
Cybersecurity researchers have discovered a malicious Python package uploaded to the Python Package Index (PyPI) repository that's designed to deliver an information stealer called Lumma (aka LummaC2). The package in question is crytic-compilers, a typosquatted version of a legitimate library named crytic-compile. The rogue package was downloaded 441 times before it was taken down by PyPI

Research reveals top 10 malware detections

05 June 2024
The top 10 malware detections have been revealed in new research. 

29% of organizations have added data security to their AI systems

05 June 2024
Artificial intelligence (AI) security and employee preparation was analyzed in a recent survey by SHI International and Dell Technologies.

83% of organizations faced at least one account takeover the past year

05 June 2024
A new survey reveals that account takeovers are a prominent threat.

Chinese State-Backed Cyber Espionage Targets Southeast Asian Government

05 June 2024
An unnamed high-profile government organization in Southeast Asia emerged as the target of a "complex, long-running" Chinese state-sponsored cyber espionage operation codenamed Crimson Palace. "The overall goal behind the campaign was to maintain access to the target network for cyberespionage in support of Chinese state interests," Sophos researchers Paul Jaramillo, Morgan Demboski, Sean

Who are Qilin, the cybercriminals thought behind the London hospitals hack?

05 June 2024
Who are Qilin, the cybercriminals thought behind the London hospitals hack? Russian-speaking ransomware gang lets hackers use its tools in exchange for cut of proceedsA Russian-speaking ransomware criminal gang called Qilin is thought to be behind the cyber-attack on NHS medical services provider Synnovis, that halted tests and operations at hospital trusts to a halt and affected GPs across London.Although the location of the group is unknown, if it is based in Russia, it will be difficult for British law enforcement to directly target it. The Russian state has long had a ban on extraditing criminals overseas, and since it launched a full-scale invasion of Ukraine, it has largely ended all cooperation on cybersecurity matters so long as the hackers focus their attacks on foreign targets. Continue reading...

Unpacking 2024's SaaS Threat Predictions

05 June 2024
Early in 2024, Wing Security released its State of SaaS Security report, offering surprising insights into emerging threats and best practices in the SaaS domain. Now, halfway through the year, several SaaS threat predictions from the report have already proven accurate. Fortunately, SaaS Security Posture Management (SSPM) solutions have prioritized mitigation capabilities to address many of

Rebranded Knight Ransomware Targeting Healthcare and Businesses Worldwide

05 June 2024
An analysis of a nascent ransomware strain called RansomHub has revealed it to be an updated and rebranded version of Knight ransomware, itself an evolution of another ransomware known as Cyclops. Knight (aka Cyclops 2.0) ransomware first arrived in May 2023, employing double extortion tactics to steal and encrypt victims' data for financial gain. It's operational across multiple platforms,

Zyxel Releases Patches for Firmware Vulnerabilities in EoL NAS Models

05 June 2024
Zyxel has released security updates to address critical flaws impacting two of its network-attached storage (NAS) devices that have currently reached end-of-life (EoL) status. Successful exploitation of three of the five vulnerabilities could permit an unauthenticated attacker to execute operating system (OS) commands and arbitrary code on affected installations. Impacted models include NAS326