Latest Cybersecurity News and Articles


Generative AI is a Looming Cybersecurity Threat

09 May 2024
Researchers have not identified any AI-engineered cyberattack campaigns, yet, but they say it’s only a matter of time before an AI system is dominant enough in the market to draw attention.

Security Tools Fail to Translate Risks for Executives

09 May 2024
CISOs stress the importance of DevSecOps automation to mitigate risks associated with AI and emphasize the need for modernized security tools to combat evolving cyber threats and comply with regulations.

Mirai Botnet Exploits Ivanti Connect Secure Flaws for Payload Delivery

09 May 2024
In the attack chain observed by Juniper Threat Labs, CVE-2023-46805 is exploited to gain access to the "/api/v1/license/key-status/;" endpoint, which is vulnerable to command injection, and inject the payload.

CISA Extends CIRCIA Rule Comment Period

09 May 2024
The CISA will prolong the comment period for new regulations under the Cyber Incident Reporting for Critical Infrastructure Act for another month after requests from the energy and information technology sectors and other industries.

Findings Show MFA Bypass in Microsoft Azure Entra ID Using Seamless SSO

09 May 2024
Researchers at Pen Test Partners successfully bypassed Azure’s MFA requirement for SSO by changing the user-agent of a browser. They used a browser that resembled Chrome on Linux but encountered an error message stating MFA was required.

Report: 97% of Organizations Hit by Ransomware Turn to Law Enforcement

09 May 2024
According to a new Sophos report, 59% of those organizations that did engage with law enforcement found the process easy or somewhat easy. Only 10% of those surveyed said the process was very difficult.

97% of organizations report difficulties with identity verification

09 May 2024
A survey of 700 IT decision-makers reveals the state of identity fraud. Notably, almost all organizations face challenges with identity verification. 

Fake E-commerce Network Scams $50M from American, European, Australian Shoppers

09 May 2024
According to a report by the German cybersecurity firm Security Research Labs GmbH (SRLabs), the BogusBazaar network has attempted to process an estimated $50 million in fake purchases since the operation launched three years ago.

Six Austrians Arrested in Multi-Million Euro Crypto Scheme

09 May 2024
Law enforcement agencies from Austria, Cyprus, and Czechia have collaborated to dismantle an online cryptocurrency scam, resulting in the arrest of six Austrians allegedly behind the scheme.

New Guide: How to Scale Your vCISO Services Profitably

09 May 2024
Cybersecurity and compliance guidance are in high demand among SMEs. However, many of them cannot afford to hire a full-time CISO. A vCISO can answer this need by offering on-demand access to top-tier cybersecurity expertise. This is also an opportunity for MSPs and MSSPs to grow their business and bottom line. MSPs and MSSPs that expand their offerings and provide vCISO services

Mirai Botnet Exploits Ivanti Connect Secure Flaws for Malicious Payload Delivery

09 May 2024
Two recently disclosed security flaws in Ivanti Connect Secure (ICS) devices are being exploited to deploy the infamous Mirai botnet. That's according to findings from Juniper Threat Labs, which said the vulnerabilities CVE-2023-46805 and CVE-2024-21887 have been leveraged to deliver the botnet payload. While CVE-2023-46805 is an authentication bypass flaw,

FBI Warns of Gift Card Fraud Ring Targeting Retail Companies

09 May 2024
The FBI has issued a warning about a hacking group named Storm-0539 targeting retail companies in the United States through phishing attacks on employees in gift card departments.

Pktstat: Open-Source Ethernet Interface Traffic Monitor

09 May 2024
Pktstat is an open-source tool that is a straightforward alternative to ncurses-based Pktstat. On Linux, it utilizes AF_PACKET, while on other platforms, it employs generic PCAP live wire capture.

Android Update Patches Critical Vulnerability

09 May 2024
Google recently released a series of security updates for Android to address 26 vulnerabilities, including a critical flaw in the System component (CVE-2024-23706) that could allow attackers to escalate privileges on vulnerable devices.

Report Shows AI Fraud, Deepfakes are Top Challenges for Banks

09 May 2024
A report by Mitek Systems reveals that banks are facing a significant challenge with fraud, including traditional issues like money laundering and account takeover, as well as newer threats such as AI-generated fraud and deepfakes.

Ransomware Criminals SIM Swap Executives' Kids to Pressure Parents

09 May 2024
Ransomware infections have morphed into "a psychological attack against the victim organization," as criminals use increasingly personal and aggressive tactics to force victims to pay up, according to Google-owned Mandiant.

US Advances on Cyber Goals Amid Rapidly Changing Threat Environment, White House Says

09 May 2024
Despite the progress in improving cybersecurity posture, the United States still faces various threats, including ransomware attacks, cyberattacks on critical infrastructure, and the growing use of artificial intelligence in malicious activities.

Two-Thirds of Organizations Failing to Address AI Risks, ISACA Finds

09 May 2024
Only a third of organizations are adequately addressing security, privacy and ethical risks with AI, despite surging use of these technologies in the workplace, according to new ISACA research.

Veeam Fixes RCE Flaw in Backup Management Platform

09 May 2024
The vulnerability exists due to an unsafe deserialization method used by the Veeam Service Provider Console (VSPC) server during communication between the management agent and its components.

Undetectable Threats Found in F5 BIG-IP Next Central Manager

09 May 2024
The two vulnerabilities, an SQL injection flaw (CVE-2024-26026) and an OData injection vulnerability (CVE-2024-21793), could allow attackers to gain admin control and create hidden rogue accounts on managed assets.