Latest Cybersecurity News and Articles
30 May 2024
Europol on Thursday said it shut down the infrastructure associated with several malware loader operations such as IcedID, SystemBC, PikaBot, SmokeLoader, Bumblebee, and TrickBot as part of a coordinated law enforcement effort codenamed Operation Endgame.
"The actions focused on disrupting criminal services through arresting High Value Targets, taking down the criminal infrastructures and
30 May 2024
The U.S. Department of Justice (DoJ) on Wednesday said it dismantled what it described as "likely the world's largest botnet ever," which consisted of an army of 19 million infected devices that was leased to other threat actors to commit a wide array of offenses.
The botnet, which has a global footprint spanning more than 190 countries, functioned as a residential proxy service known as 911 S5.
30 May 2024
Okta is warning that a cross-origin authentication feature in Customer Identity Cloud (CIC) is susceptible to credential stuffing attacks orchestrated by threat actors.
"We observed that the endpoints used to support the cross-origin authentication feature being attacked via credential stuffing for a number of our customers," the Identity and access management (IAM) services provider said.
The
30 May 2024

The notorious ShinyHunters collective is claiming hack of personal details of 560 million global customersFollow our Australia news live blog for latest updatesGet our morning and afternoon news emails, free app or daily news podcastTicketmaster is yet to confirm whether it has experienced a major data breach or if Australians are impacted, after a notorious hacker collective claimed it had the personal details of millions of the ticketing giant’s global customers for sale.The collective, ShinyHunters, claimed on Wednesday on the dark web it had the personal details of 560 million Ticketmaster customers for a one time sale of US$500,000. It also demanded a ransom for the data to not be released.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...
29 May 2024
The U.S. Department of Justice (DOJ) today said they arrested the alleged operator of 911 S5, a ten-year-old online anonymity service that was powered by what the director of the FBI called "likely the world's largest botnet ever." The arrest coincided with the seizure of the 911 S5 website and supporting infrastructure, which the government says turned computers running various "free VPN" products into Internet traffic relays that facilitated billions of dollars in online fraud and cybercrime.
29 May 2024
Cybersecurity researchers have warned of a new malicious Python package that has been discovered in the Python Package Index (PyPI) repository to facilitate cryptocurrency theft as part of a broader campaign.
The package in question is pytoileur, which has been downloaded 316 times as of writing. Interestingly, the package author, who goes by the name PhilipsPY, has uploaded a new version of the
29 May 2024
A recent study suggests that leading LLMs may come with security concerns, and security leaders are sharing their insights.
29 May 2024
Public sector security debt and application risk management was analyzed in a recent report by Veracode, finding 3% of applications are flaw free.
29 May 2024
Check Point is warning of a zero-day vulnerability in its Network Security gateway products that threat actors have exploited in the wild.
Tracked as CVE-2024-24919, the issue impacts CloudGuard Network, Quantum Maestro, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark appliances.
"The vulnerability potentially allows an attacker to read certain information on
29 May 2024
Brazilian banking institutions are the target of a new campaign that distributes a custom variant of the Windows-based AllaKore remote access trojan (RAT) called AllaSenha.
The malware is "specifically aimed at stealing credentials that are required to access Brazilian bank accounts, [and] leverages Azure cloud as command-and-control (C2) infrastructure," French cybersecurity company HarfangLab
29 May 2024
A new report discusses cyberattack trends in the United States, with healthcare and finance industries being hit the hardest.
29 May 2024
The U.S. Department of Justice (DoJ) has sentenced a 31-year-old to 10 years in prison for laundering more than $4.5 million through business email compromise (BEC) schemes and romance scams.
Malachi Mullings, 31, of Sandy Springs, Georgia pleaded guilty to the money laundering offenses in January 2023.
According to court documents, Mullings is said to have opened 20 bank accounts in the name of
29 May 2024
A recent study by Wing Security found that 63% of businesses may have former employees with access to organizational data, and that automating SaaS Security can help mitigate offboarding risks.
Employee offboarding is typically seen as a routine administrative task, but it can pose substantial security risks, if not handled correctly. Failing to quickly and thoroughly remove access for
29 May 2024
A never-before-seen North Korean threat actor codenamed Moonstone Sleet has been attributed as behind cyber attacks targeting individuals and organizations in the software and information technology, education, and defense industrial base sectors with ransomware and bespoke malware previously associated with the infamous Lazarus Group.
"Moonstone Sleet is observed to set up fake companies and
29 May 2024
The online criminal bazaar BreachForums has been resurrected merely two weeks after a U.S.-led coordinated law enforcement action dismantled and seized control of its infrastructure.
Cybersecurity researchers and dark web trackers Brett Callow, Dark Web Informer, and FalconFeeds revealed the site's online return at breachforums[.]st – one of the dismantled sites – by a user named ShinyHunters,
29 May 2024
90% of organizations reported an identity-related event in the last year.
28 May 2024
The U.S. Department of the Treasury today unveiled sanctions against three Chinese nationals for allegedly operating 911 S5, an online anonymity service that for many years was the easiest and cheapest way to route one's Web traffic through malware-infected computers around the globe. KrebsOnSecurity identified one of the three men in a July 2022 investigation into 911 S5, which was massively hacked and then closed ten days later.
28 May 2024
WD Associates announced a recent data security incident involving personal information including Social Security numbers and insurance information.
28 May 2024
Opportunity for cyber security startups with ideas to protect small businesses to work with the NCSC's cyber security experts.
28 May 2024
Thirteen teams around the country claimed victory at the finals of the new-look 2022 CyberFirst Girls Competition.