Latest Cybersecurity News and Articles


Students tackle tech innovation challenge set by UK cyber experts

28 May 2024
First ever Innovators Challenge held in Manchester for students studying NCSC-certified degrees.

Groundbreaking cyber advice will help construction firms build strong foundations against online threats

28 May 2024
New guidance, issued by the NCSC and the Chartered Institute of Building, is designed to help small and medium-sized construction businesses.

Indian National Pleads Guilty to $37 Million Cryptocurrency Theft Scheme

28 May 2024
An Indian national has pleaded guilty in the U.S. over charges of stealing more than $37 million by setting up a website that impersonated the Coinbase cryptocurrency exchange platform. Chirag Tomar, 30, pleaded guilty to wire fraud conspiracy, which carries a maximum sentence of 20 years in prison and a $250,000 fine. He was arrested on December 20, 2023, upon entering the country. "Tomar and

70% of CISOs feel vulnerable to a material cyberattack in 2024

28 May 2024
A report surveyed 1,600 CISOs worldwide in order to shed light on their experiences, insights and predictions. 

Ransomhub’s Latest Attack Raises Alarms for Industrial Control Systems (ICS) Security

28 May 2024
The Ransomhub ransomware group’s modus operandi involves encrypting data and leveraging access to SCADA systems to disrupt essential functions, as evidenced in their recent breach.

4-Step Approach to Mapping and Securing Your Organization's Most Critical Assets

28 May 2024
You’re probably familiar with the term “critical assets”. These are the technology assets within your company's IT infrastructure that are essential to the functioning of your organization. If anything happens to these assets, such as application servers, databases, or privileged identities, the ramifications to your security posture can be severe.  But is every technology asset considered

CERT-UA Warns of Malware Campaign Conducted by Threat Actor UAC-0006

28 May 2024
SmokeLoader acts as a loader for other malware, once it is executed it will inject malicious code into the currently running explorer process (explorer.exe) and download another payload to the system.

Researchers Warn of CatDDoS Botnet and DNSBomb DDoS Attack Technique

28 May 2024
The threat actors behind the CatDDoS malware botnet have exploited over 80 known security flaws in various software over the past three months to infiltrate vulnerable devices and co-opt them into a botnet for conducting distributed denial-of-service (DDoS) attacks. "CatDDoS-related gangs' samples have used a large number of known vulnerabilities to deliver samples," the QiAnXin XLab team 

SingCERT Warns Critical Vulnerabilities Found in Multiple WordPress Plugins

28 May 2024
Security updates have been promptly released to address these critical vulnerabilities in multiple WordPress plugins. SingCERT reported 9 critical plugin vulnerabilities and shared the mitigation strategies to avoid exploration by threat actors.

Digital ID Adoption: Implementation and Security Concerns

28 May 2024
As digital transformation accelerates, understanding how businesses are preparing for and implementing digital ID technologies is crucial for staying ahead in security and efficiency, according to Regula.

Update: Threat Actors Created Rogue VMs to Evade Detection During December 2023 Attack on MITRE

28 May 2024
According to the new update, threat actors exploited zero-day flaws in Ivanti Connect Secure (ICS) and created rogue virtual machines (VMs) within the organization’s VMware environment.

White House Announces Plans to Revamp Data Routing Security by Year-End

28 May 2024
The augmentations concern the Border Gateway Protocol, a backbone data transmission algorithm that determines the optimal path for data packets to move across networks, said National Cyber Director Harry Coker

Usage of TLS in DDNS Services leads to Information Disclosure in Multiple Vendors

28 May 2024
When DDNS is combined with automatic TLS certificate generation using ACME clients, the public Certificate Transparency logs can be abused by attackers to find vulnerable devices en masse.

Human Error Still Perceived as the Achilles’ Heel of Cybersecurity

28 May 2024
While fears of cyberattacks continue to rise, CISOs demonstrate increasing confidence in their ability to defend against these threats, reflecting a significant shift in the cybersecurity landscape, according to Proofpoint.

Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling

28 May 2024
One campaign uses HTML smuggling to hide the phishing content from network inspection. The other uses a method called transparent phishing, where the attacker uses Cloudflare Workers to act as a reverse proxy server for a legitimate login page.

WordPress Plugin Exploited to Steal Credit Card Data from E-commerce Sites

28 May 2024
Unknown threat actors are abusing lesser-known code snippet plugins for WordPress to insert malicious PHP code in victim sites that are capable of harvesting credit card data. The campaign, observed by Sucuri on May 11, 2024, entails the abuse of a WordPress plugin called Dessky Snippets, which allows users to add custom PHP code. It has over 200 active installations.

TP-Link Gaming Router Vulnerability Exposes Users to Remote Code Attacks

28 May 2024
A maximum-severity security flaw has been disclosed in the TP-Link Archer C5400X gaming router that could lead to remote code execution on susceptible devices by sending specially crafted requests. The vulnerability, tracked as CVE-2024-5035, carries a CVSS score of 10.0. It impacts all versions of the router firmware including and prior to 1_1.1.6. It has 

Security leaders respond to ransomware attack on the City of Wichita

28 May 2024
Security leaders respond to the announcement that the City of Wichita, Kansas, was targeted by a ransomware attack. 

Australian Telecom Watchdog Sues Optus Over 2022 Data Breach

27 May 2024
The Australian Communications and Media Authority said it has filed proceedings against Optus in a federal court as the company failed to protect sensitive customer data during a data breach in September 2022 that affected close to 10 million people.

NVD Leaves Exploited Vulnerabilities Unchecked

27 May 2024
In the report published on May 23, VulnCheck showed that 30 out of 59 known exploited vulnerabilities (KEVs) registered since February 12 have not yet been analyzed by the NVD team.