Latest Cybersecurity News and Articles


A Cost-Effective Encryption Strategy Starts With Key Management

15 May 2024
A cost-effective encryption strategy starts with effective key management, which involves making critical decisions about where to store encryption keys, how to manage them, and how to prepare for the post-quantum future.

Russian Actors Weaponize Legitimate Services in Multi-Malware Attack

15 May 2024
The threat actor, likely located in the Commonwealth of Independent States (CIS), strategically targeted a spectrum of operating systems and computer architectures in the credential harvesting campaign, including Windows and macOS.

FTC Fires ‘Shot Across the Bow’ at Automakers Over Connected-Car Data Privacy

15 May 2024
The FTC issued a strong warning to automakers about their data collection and sharing practices, particularly regarding the sale of sensitive geolocation data, and emphasized that it will take enforcement action to protect consumer privacy.

Report: Data Breaches in US Schools Exposed 37.6M Records

15 May 2024
According to Comparitech, data breaches in US schools have exposed over 37.6 million records since 2005, with a significant surge in 2023 due to vulnerabilities in the MOVEit file transfer software affecting over 800 institutions.

SideCopy APT Campaign Found Targeting Indian Universities

15 May 2024
Active since May 2023, the SideCopy APT campaign targets university students through sophisticated infection chains involving malicious LNK files, HTAs, and loader DLLs disguised as legitimate documents.

Australia: AFL Players Call for Data Protection Overhaul as Concerns Include Drug Test Results

15 May 2024
AFL players are concerned about the risk of their personal and sensitive information, such as drug test results and psychologist session notes, being leaked onto the dark web due to inadequate data protection measures.

CISA, FBI, and DHS Unveil Cybersecurity Guide For Civil Society Groups

15 May 2024
The publication Mitigating Cyber Threats with Limited Resources: Guidance for Civil Society is designed to provide high-risk communities with actionable steps to bolster their cybersecurity defenses.

AI Is an Expert Liar

15 May 2024
AI systems trained to excel at tasks can learn to lie and deceive in order to gain an advantage, posing serious risks to society such as fraud, election tampering, and even the potential loss of human control over AI.

NIST Issues New Guidelines on Protecting Unclassified Data in Government Systems

15 May 2024
The NIST issued new guidelines to help federal agencies and their private sector contractors better protect sensitive unclassified information, known as Controlled Unclassified Information (CUI), from cyber threats, particularly supply chain risks.

Several Vulnerabilities Addressed in Ubuntu 24.04

15 May 2024
Ubuntu 24.04 LTS has addressed several security vulnerabilities, including issues in less, Glibc, Curl, GnuTLS, libvirt, and Pillow, which could potentially lead to denial of service or arbitrary code execution.

Scammers are Getting Creative Using Malvertising, Deepfakes, and YouTube

15 May 2024
The Avast Q1 2024 Threat Report highlighted a massive surge in social engineering scams, with a staggering 90% of all mobile and 87% of desktop threats falling into this category.

Apple Fixes Safari WebKit Zero-Day Flaw Exploited at Pwn2Own

15 May 2024
Apple patched a zero-day vulnerability (CVE-2024-27834) in Safari that was exploited at the Pwn2Own hacking competition. The vulnerability allowed an attacker to bypass Pointer Authentication Codes (PACs) and potentially execute remote code.

Turla Group Deploys LunarWeb and LunarMail Backdoors in Diplomatic Missions

15 May 2024
An unnamed European Ministry of Foreign Affairs (MFA) and its three diplomatic missions in the Middle East were targeted by two previously undocumented backdoors tracked as LunarWeb and LunarMail. ESET, which identified the activity, attributed it with medium confidence to the Russia-aligned cyberespionage group Turla (aka Iron Hunter, Pensive Ursa, Secret Blizzard, Snake, Uroburos, and Venomous

Meet Hackbat: An Open-Source, More Powerful Flipper Zero Alternative

15 May 2024
Hackbat is built around a custom PCB and a Raspberry Pi Pico W microcontroller, providing features like Wi-Fi, NFC, RF, microSD storage, USB for keystroke injection, and a display with buttons.

Malware was almost 50% of threat detections in Q1 2024

15 May 2024
According to a cybersecurity and threat intelligence report, the U.S. was the 4th most targeted country in the world regarding phishing attacks. 

Ebury Botnet Compromised 400K Linux Servers for Crypto Theft and Financial Gain

15 May 2024
The malware modules spread via Ebury are used for various nefarious activities, such as proxying traffic, redirecting HTTP traffic, exfiltrating sensitive information, and intercepting HTTP requests.

(Cyber) Risk = Probability of Occurrence x Damage

15 May 2024
Here’s How to Enhance Your Cyber Resilience with CVSS In late 2023, the Common Vulnerability Scoring System (CVSS) v4.0 was unveiled, succeeding the eight-year-old CVSS v3.0, with the aim to enhance vulnerability assessment for both industry and the public. This latest version introduces additional metrics like safety and automation to address criticism of lacking granularity

DeRusha Stepping Down From Federal CISO Role

15 May 2024
Chris DeRusha is leaving his position as the federal CISO, a role he has held since January 2021. He is also departing from his role as the deputy national cyber director at the Office of the National Cyber Director (ONCD).

VMware Fixed Zero-Day Flaws Demonstrated at Pwn2Own2024

15 May 2024
VMware addressed four vulnerabilities, including three zero-day flaws demonstrated at the Pwn2Own Vancouver 2024 hacking contest, in its Workstation and Fusion desktop hypervisors.

Singapore Cybersecurity Update Puts Cloud Providers on Notice

15 May 2024
The Singapore government has updated its Cybersecurity Act to give its primary cybersecurity agency more power to regulate critical infrastructure and third-party providers, and to require the reporting of cyber incidents.