Latest Cybersecurity News and Articles


Cybercriminals are Targeting Elections in India With Influence Campaigns

23 May 2024
Around 16 different independent hacktivist groups are targeting Indian elections, including Anon Black Flag Indonesia, Anonymous Bangladesh, and Morocco Black Cyber Army, among others.

Chinese Hackers Hide on Military and Government Networks for Six Years

23 May 2024
Bitdefender researchers who discovered the threat group report that its operations align with Chinese geo-political interests, focusing on intelligence collection and espionage.

Microsoft's Recall Stokes Security and Privacy Concerns

23 May 2024
Microsoft's new automatic screenshot retrieval feature could enable hackers to steal sensitive information such as online banking credentials, security experts warned. Additionally, the U.K ICO will probe Recall for compliance with privacy law.

Keylogger Malware Campaign Exploits Microsoft Exchange Server Flaws to Hit Over 30 Victims

23 May 2024
This campaign, active since at least 2021, has targeted over 30 victims in various countries, primarily in Africa and the Middle East, with government agencies being the main victims.

New Frontiers, Old Tactics: Chinese Espionage Group Targets Africa & Caribbean Govts

23 May 2024
The China-linked threat actor known as Sharp Panda has expanded their targeting to include governmental organizations in Africa and the Caribbean as part of an ongoing cyber espionage campaign. "The campaign adopts Cobalt Strike Beacon as the payload, enabling backdoor functionalities like C2 communication and command execution while minimizing the exposure of their custom tools," Check Point

U.S. House Panel Takes on AI Security and Misuse

23 May 2024
Much of the testimony – and concerns raised by the committee – focused on the AI advantages for cybercriminals and nation-state actors, advantages that cybersecurity officials say must be countered by increasingly building AI into products.

CLOUD#REVERSER Campaign Leverages Cloud Storage for Malware Delivery

23 May 2024
Delivered via a phishing email attachment, the malicious file makes use of the hidden right-to-left override (RLO) Unicode character (U+202E) to reverse the order of the characters that come after that character in the string.

Ransomware Fallout: 94% Experience Downtime, 40% Face Work Stoppage

23 May 2024
According to Arctic Wolf, 66% of organizations that suffered a data breach in the last year chose to publicly disclose information regarding their incidents, while 30% only disclosed their breaches to impacted parties.

Consumer-Grade Spyware App Found on US Hotel Check-in Computers

23 May 2024
pcTattletale allows remote monitoring of Android or Windows devices and their data. The app claims to run invisibly in the background, undetectable on the target’s workstation.

Snowflake's Anvilogic Investment Signals Changes in SIEM Market

23 May 2024
The joint Snowflake and Anvilogic solution would lead to reduced costs — on the order of 50% to 80%, the companies claim — and will eventually replace legacy SIEM platforms, argues Karthik Kannan, CEO of Anvilogic.

EPA reveals most water systems do not meet compliance requirements

23 May 2024
An investigation by the EPA reveals that a majority of water systems do not meet compliance standards. Security leaders are sharing their thoughts. 

Nearly 90% of organizations suffer damage after a security incident

23 May 2024
According to a recent cybersecurity incident report, nearly 90% of organizations suffer damage before containing and investigating incidents.

UserPro Plugin Vulnerability Allows Account Takeover

23 May 2024
Patchstack discovered the critical flaw in the plugin’s password reset mechanism, specifically within the userpro_process_form function, which allowed unauthenticated users to change the passwords of other users under certain conditions.

Rockwell Automation Urges Disconnection of ICS from the Internet

23 May 2024
Rockwell Automation warned customers to disconnect industrial control systems (ICS) from the internet, citing escalating cyber threats and rising global geopolitical tensions.

Inside Operation Diplomatic Specter: Chinese APT Group's Stealthy Tactics Exposed

23 May 2024
Governmental entities in the Middle East, Africa, and Asia are the target of a Chinese advanced persistent threat (APT) group as part of an ongoing cyber espionage campaign dubbed Operation Diplomatic Specter since at least late 2022. "An analysis of this threat actor’s activity reveals long-term espionage operations against at least seven governmental entities," Palo Alto Networks

Are Your SaaS Backups as Secure as Your Production Data?

23 May 2024
Conversations about data security tend to diverge into three main threads: How can we protect the data we store on our on-premises or cloud infrastructure? What strategies and tools or platforms can reliably backup and restore data? What would losing all this data cost us, and how quickly could we get it back? All are valid and necessary conversations for technology organizations of all shapes

Apple Wi-Fi Positioning System Open to Global Tracking Abuse

23 May 2024
Apple is one of several companies, along with Google, Skyhook, and others, that operate a WPS. They offer client devices a way to determine their location that's more energy efficient than using the Global Positioning System (GPS).

Former White House Cyber Official Jeff Greene to Join CISA

23 May 2024
Former White House National Security Council cyber staff member Jeff Greene, the current cybersecurity programs director at the Aspen Institute think tank, is joining the CISA next month, the agency confirmed.

SEC Fines NYSE Owner ICE for Delay in Reporting VPN Breach

23 May 2024
The U.S. Securities and Exchange Commission (SEC) announced today that a major player in the U.S. financial system has agreed to pay a $10 million penalty for failing to timely report an April 2021 VPN breach.

OpenText Boosts MDR Offering for MSPs With Pillr Acquisition

23 May 2024
The MDR business was stood up in 2018 as a standalone unit within Novacoast, and rebranded in September 2022 from novaSOC to Pillr. Novacoast CEO Paul Anderson served as Pillr's chief executive for most of its existence.