Latest Cybersecurity News and Articles


Andariel Hackers Target South Korean Institutes with New Dora RAT Malware

03 June 2024
The North Korea-linked threat actor known as Andariel has been observed using a new Golang-based backdoor called Dora RAT in its attacks targeting educational institutes, manufacturing firms, and construction businesses in South Korea. "Keylogger, Infostealer, and proxy tools on top of the backdoor were utilized for the attacks," the AhnLab Security Intelligence Center (ASEC) said in a report

Security leaders respond to the cyberattack on Christie’s

03 June 2024
Security leaders respond to the claim that a ransomware group has accessed the data of at least 500,000 of Christie’s customers globally.

Beware: Fake Browser Updates Deliver BitRAT and Lumma Stealer Malware

02 June 2024
Fake web browser updates are being used to deliver remote access trojans (RATs) and information stealer malware such as BitRAT and Lumma Stealer (aka LummaC2). "Fake browser updates have been responsible for numerous malware infections, including those of the well-known SocGholish malware," cybersecurity firm eSentire said in a new report. "In April 2024, we observed FakeBat being distributed

Live Nation investigating data breach of its US Ticketmaster unit

01 June 2024
Live Nation investigating data breach of its US Ticketmaster unit Cybercrime group ShinyHunters said it had stolen data of 500m customers of concert promoter’s ticketing armLive Nation Entertainment said it is investigating a data breach at its Ticketmaster unit that it discovered on 20 May, the latest in a string of high-profile corporate hacks in the past year.In a filing with the US Securities and Exchange Commission, Live Nation said it had found “unauthorised activity” in a third-party cloud database that mainly contained Ticketmaster data, and was working with forensic investigators. Continue reading...

AI Company Hugging Face Notifies Users of Suspected Unauthorized Access

01 June 2024
Artificial Intelligence (AI) company Hugging Face on Friday disclosed that it detected unauthorized access to its Spaces platform earlier this week. "We have suspicions that a subset of Spaces’ secrets could have been accessed without authorization," it said in an advisory. Spaces offers a way for users to create, host, and share AI and machine learning (ML) applications. It also functions as a

Ticketek customer details exposed in cyber security breach

31 May 2024
Ticketek customer details exposed in cyber security breach Clare O’Neil says incident affecting many Australians but appears restricted to the release of names, dates of birth and email addressesGet our morning and afternoon news emails, free app or daily news podcastTicketek has been hit by a “cyber incident” with personal information of Australian customers stolen from a third-party global cloud-based platform.The cybersecurity minister, Clare O’Neil, said late on Friday night the breach was “affecting many Australians” but appeared restricted to the release of names, dates of birth and email addresses.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...

Mysterious Cyber Attack Took Down 600,000+ Routers in the U.S.

31 May 2024
More than 600,000 small office/home office (SOHO) routers are estimated to have been bricked and taken offline following a destructive cyber attack staged by unidentified cyber actors, disrupting users' access to the internet. The mysterious event, which took place between October 25 and 27, 2023, and impacted a single internet service provider (ISP) in the U.S., has been codenamed Pumpkin

Microsoft Warns of Surge in Cyber Attacks Targeting Internet-Exposed OT Devices

31 May 2024
Microsoft has emphasized the need for securing internet-exposed operational technology (OT) devices following a spate of cyber attacks targeting such environments since late 2023. "These repeated attacks against OT devices emphasize the crucial need to improve the security posture of OT devices and prevent critical systems from becoming easy targets," the Microsoft Threat Intelligence team said.

Beyond Threat Detection – A Race to Digital Security

31 May 2024
Digital content is a double-edged sword, providing vast benefits while simultaneously posing significant threats to organizations across the globe. The sharing of digital content has increased significantly in recent years, mainly via email, digital documents, and chat. In turn, this has created an expansive attack surface and has made ‘digital content’ the preferred carrier for cybercriminals

Russian Hackers Target Europe with HeadLace Malware and Credential Harvesting

31 May 2024
The Russian GRU-backed threat actor APT28 has been attributed as behind a series of campaigns targeting networks across Europe with the HeadLace malware and credential-harvesting web pages. APT28, also known by the names BlueDelta, Fancy Bear, Forest Blizzard, FROZENLAKE, Iron Twilight, ITG05, Pawn Storm, Sednit, Sofacy, and TA422, is an advanced persistent threat (APT) group affiliated with

OpenAI, Meta, TikTok Disrupt Multiple AI-Powered Disinformation Campaigns

31 May 2024
OpenAI on Thursday disclosed that it took steps to cut off five covert influence operations (IO) originating from China, Iran, Israel, and Russia that sought to abuse its artificial intelligence (AI) tools to manipulate public discourse or political outcomes online while obscuring their true identity. These activities, which were detected over the past three months, used its AI models to

CISA Alerts Federal Agencies to Patch Actively Exploited Linux Kernel Flaw

30 May 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a security flaw impacting the Linux kernel to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Tracked as CVE-2024-1086 (CVSS score: 7.8), the high-severity issue relates to a use-after-free bug in the netfilter component that permits a local attacker to elevate privileges

FlyingYeti Exploits WinRAR Vulnerability to Deliver COOKBOX Malware in Ukraine

30 May 2024
Cloudflare on Thursday said it took steps to disrupt a month-long phishing campaign orchestrated by a Russia-aligned threat actor called FlyingYeti targeting Ukraine. "The FlyingYeti campaign capitalized on anxiety over the potential loss of access to housing and utilities by enticing targets to open malicious files via debt-themed lures," Cloudflare's threat intelligence team Cloudforce One

OpenAI Board establishes Safety and Security Committee

30 May 2024
A Safety and Security committee has been formed by the OpenAI Board. Security leaders are sharing their thoughts. 

Cyber Espionage Alert: LilacSquid Targets IT, Energy, and Pharma Sectors

30 May 2024
A previously undocumented cyber espionage-focused threat actor named LilacSquid has been linked to targeted attacks spanning various sectors in the United States (U.S.), Europe, and Asia as part of a data theft campaign since at least 2021. "The campaign is geared toward establishing long-term access to compromised victim organizations to enable LilacSquid to siphon data of interest to

‘Operation Endgame’ Hits Malware Delivery Platforms

30 May 2024
Law enforcement agencies in the United States and Europe today announced Operation Endgame, a coordinated action against some of the most popular cybercrime platforms for delivering ransomware and data-stealing malware. Dubbed "the largest ever operation against botnets," the international effort is being billed as the opening salvo in an ongoing campaign targeting advanced malware "droppers" or "loaders" like IcedID, Smokeloader and Trickbot.

Best Buy was the top most impersonated brand in 2023

30 May 2024
The Federal Trade Commission (FTC) released data on which brands were most often impersonated by scammers, and which scams were the most costly.

RedTail Crypto-Mining Malware Exploiting Palo Alto Networks Firewall Vulnerability

30 May 2024
The threat actors behind the RedTail cryptocurrency mining malware have added a recently disclosed security flaw impacting Palo Alto Networks firewalls to its exploit arsenal. The addition of the PAN-OS vulnerability to its toolkit has been complemented by updates to the malware, which now incorporates new anti-analysis techniques, according to findings from web infrastructure and security

Researchers Uncover Active Exploitation of WordPress Plugin Vulnerabilities

30 May 2024
Cybersecurity researchers have warned that multiple high-severity security vulnerabilities in WordPress plugins are being actively exploited by threat actors to create rogue administrator accounts for follow-on exploitation. "These vulnerabilities are found in various WordPress plugins and are prone to unauthenticated stored cross-site scripting (XSS) attacks due to inadequate input sanitization

How to Build Your Autonomous SOC Strategy

30 May 2024
Security leaders are in a tricky position trying to discern how much new AI-driven cybersecurity tools could actually benefit a security operations center (SOC). The hype about generative AI is still everywhere, but security teams have to live in reality. They face constantly incoming alerts from endpoint security platforms, SIEM tools, and phishing emails reported by internal users. Security