Latest Cybersecurity News and Articles


AI-Powered Russian Network Pushes Fake Political News

13 May 2024
Security researchers have discovered a major new Russian disinformation campaign using generative AI (GenAI) to “plagiarize and weaponize” content from major news organizations, in a bid to influence Western voters.

Malicious Go Binary Delivered via Steganography in PyPI

13 May 2024
The malicious package, called "requests-darwin-lite", was a fork of the popular "requests" Python package. The attacker used the cmdclass feature in the setup.py file to customize the package installation process.

Feds, Military Personnel Compete in President’s Cyber Cup Challenge

13 May 2024
Artificially Intelligent — a team of four Army servicemembers and one from the Air Force — won the 2024 President’s Cyber Cup Challenge, a five-year-old competition open to federal government and U.S. military personnel.

Selfie Spoofing Becomes Popular Identity Document Fraud Technique

13 May 2024
Selfie spoofing and document image-of-image fraud have become the most prevalent identity document fraud techniques, with older demographics being targeted at nearly four times the rate, according to Socure.

FIN7 Uses Trusted Brands and Sponsored Google Ads to Distribute MSIX Payloads

13 May 2024
The financially motivated group FIN7 has been observed leveraging malicious Google ads that impersonate legitimate brands to deliver NetSupport RAT, highlighting the ongoing threat of malvertising and the abuse of signed MSIX files by cybercriminals.

Malicious Python Package Hides Sliver C2 Framework in Fake Requests Library Logo

13 May 2024
Cybersecurity researchers have identified a malicious Python package that purports to be an offshoot of the popular requests library and has been found concealing a Golang-version of the Sliver command-and-control (C2) framework within a PNG image of the project's logo.  The package employing this steganographic trickery is requests-darwin-lite, which has been

National Cyber Security Centre CTO: The tech market isn't working

12 May 2024
Ollie Whitehouse will say in his keynote speech that companies globally know how to build resilient, secure technology, but the market does not incentivise them to do so.

Attack Makes Autonomous Vehicle Tech Ignore Road Signs

11 May 2024
Researchers have developed a technique called "GhostStripe" that can exploit the camera-based computer vision systems of autonomous vehicles, causing them to fail to recognize road signs, making it very risky for Tesla and Baidu Apollo vehicles.

FIN7 Hacker Group Leverages Malicious Google Ads to Deliver NetSupport RAT

11 May 2024
The financially motivated threat actor known as FIN7 has been observed leveraging malicious Google ads spoofing legitimate brands as a means to deliver MSIX installers that culminate in the deployment of NetSupport RAT. "The threat actors used malicious websites to impersonate well-known brands, including AnyDesk, WinSCP, BlackRock, Asana, Concur, The Wall

'The Mask' Espionage Group Resurfaces After 10-Year Hiatus

11 May 2024
An advanced persistent threat (APT) group that has been missing in action for more than a decade has suddenly resurfaced in a cyber-espionage campaign targeting organizations in Latin America and Central Africa.

Update your Chrome browser ASAP. Google has confirmed a zero-day exploited in the wild

10 May 2024
A new Chrome JavaScript security hole is nasty, so don't waste any time patching your systems.

MoD contractor hacked by China failed to report breach for months

10 May 2024
MoD contractor hacked by China failed to report breach for months Exclusive: Defence ministry was told in recent days that staff details accessed but sources say SSCL knew in FebruaryThe IT company targeted in a Chinese hack that accessed the data of hundreds of thousands of Ministry of Defence staff failed to report the breach for months, the Guardian can reveal.The UK defence secretary, Grant Shapps, told MPs on Tuesday that Shared Services Connected Ltd (SSCL) had been breached by a malign actor and “state involvement” could not be ruled out. Continue reading...

North Korean Hackers Deploy New Golang Malware 'Durian' Against Crypto Firms

10 May 2024
The North Korean threat actor tracked as Kimsuky has been observed deploying a previously undocumented Golang-based malware dubbed Durian as part of highly-targeted cyber attacks aimed at South Korean cryptocurrency firms. "Durian boasts comprehensive backdoor functionality, enabling the execution of delivered commands, additional file downloads and exfiltration of files," Kaspersky&

Telus Acquires Cybersecurity Services Firm Vumetric

10 May 2024
Telus announced Tuesday its acquisition of Vumetric Cybersecurity, a Toronto-based cybersecurity provider that specializes in advanced penetration testing designed to identify cyber vulnerabilities and threats to companies across North America.

New LLMjacking Attack Uses Stolen Cloud Credentials to Target Cloud-Hosted AI Models

10 May 2024
Sysdig researchers discovered evidence of a reverse proxy for LLMs being used to provide access to the compromised accounts, suggesting a financial motivation. However, another possible motivation is to extract LLM training data.

Update: Thwarted Cyberattack Targeted Library of Congress in Tandem With October British Library Breach

10 May 2024
The Library of Congress was targeted in a cyberattack that occurred in parallel with a high-profile intrusion into the British Library in October 2023 but it was a failed attempt, according to internal documents obtained by Nextgov/FCW.

Android Remote Access Trojan Equipped to Harvest Credentials

10 May 2024
This malware uses famous Android app icons to mislead users and trick victims into installing the malicious app on their devices. This includes the icons of Google, Instagram, Snapchat, WhatsApp, and X (formerly Twitter).

Report: Global Ransomware Crisis Worsens

10 May 2024
According to NTT Security Holdings’ 2024 Global Threat Intelligence report, ransomware and extortion incidents increased by 67% in 2023, with over 5,000 victims detected or posted across social channels, up from 3,000 in 2022.

CensysGPT: AI-Powered Threat Hunting for Cybersecurity Pros (Webinar)

10 May 2024
Artificial intelligence (AI) is transforming cybersecurity, and those leading the charge are using it to outsmart increasingly advanced cyber threats. Join us for an exciting webinar, "The Future of Threat Hunting is Powered by Generative AI," where you'll explore how AI tools are shaping the future of cybersecurity defenses. During the session, Censys Security Researcher Aidan Holland will

Monday.com Removes “Share Update” Feature Abused for Phishing Attacks

10 May 2024
The phishing emails pretended to come from a "Human Resources" department, asking users to either acknowledge the "organization's workplace sex policy" or submit feedback as part of a "2024 Employee Evaluation."