Latest Cybersecurity News and Articles


Rhadamanthys Malware Deployed By TA547 Against German Targets

11 April 2024
What’s particularly intriguing according to the researchers is the actor’s apparent employment of a PowerShell script likely generated by large language models (LLMs) such as ChatGPT, Gemini or CoPilot.

UK's Attitude to Security Spotlit by Government Figures

11 April 2024
The report from the Department for Science, Innovation and Technology (DSIT), painted security as more of an afterthought for UK businesses, especially when considering the figures about how breaches are handled.

CISO Role Shows Significant Gains Amid Corporate Recognition of Cyber Risk

11 April 2024
CISOs and other management-level cybersecurity executives are gaining more influence and importance as companies have begun to recognize the need for strong cyber governance and oversight, according to a report from Moody’s Ratings.

A vulnerability in Linux distributions may allow unauthorized access

11 April 2024
A recently detected vulnerability in many Linux distributions may open the door for malicious actors to gain unauthorized access. 

Python's PyPI Reveals Its Secrets

11 April 2024
GitGuardian is famous for its annual State of Secrets Sprawl report. In their 2023 report, they found over 10 million exposed passwords, API keys, and other credentials exposed in public GitHub commits. The takeaways in their 2024 report did not just highlight 12.8 million new exposed secrets in GitHub, but a number in the popular Python package repository PyPI. PyPI,

TA547 Phishing Attack Hits German Firms with Rhadamanthys Stealer

11 April 2024
A threat actor tracked as TA547 has targeted dozens of German organizations with an information stealer called Rhadamanthys as part of an invoice-themed phishing campaign. "This is the first time researchers observed TA547 use Rhadamanthys, an information stealer that is used by multiple cybercriminal threat actors," Proofpoint said. "Additionally, the actor appeared to

Python's PyPI Reveals Its Secrets

11 April 2024
GitGuardian is famous for its annual State of Secrets Sprawl report. In their 2023 report, they found over 10 million exposed passwords, API keys, and other credentials exposed in public GitHub commits. The takeaways in their 2024 report did not just highlight 12.8 million new exposed secrets in GitHub, but a number in the popular Python package repository PyPI. PyPI,

New Google Workspace Feature Prevents Sensitive Security Changes if Two Admins Don’t Approve Them

11 April 2024
If the feature is enabled, certain sensitive admin actions can be taken only if approved by an admin who did not initiate them and thus, in theory, preventing accidental or unauthorized changes made by either malicious insiders or outsiders

Wiz Buys Startup Gem Security for $350M to Spot Cloud Issues

11 April 2024
Wiz purchased a cloud detection and response startup founded by a longtime Israeli Military Intelligence leader to address security operations and incident response use cases.

New Technique Detected in an Open Source Supply Chain Attack

11 April 2024
Attackers create malicious GitHub repositories with popular names and topics, using techniques like automated updates and fake stars to boost search rankings and deceive users.

AI Data Security Startup Cyera Confirms $300M Raise at a $1.4B Valuation

11 April 2024
The lead investor for the Series C funding is Coatue, which is new to the startup’s cap table. Other new investors include Spark Capital, Georgian, and strategic backer AT&T Ventures.

Rust Addresses Critical Vulnerability on Windows

11 April 2024
The vulnerability, which carries a perfect 10 base severity score, is tracked as CVE-2024-24576. It affects the Rust standard library, which was found to be improperly escaping arguments when invoking batch files on Windows using the Command API.

Raspberry Robin Now Spreading Through Windows Script Files

11 April 2024
First identified in late 2021, Raspberry Robin is a Windows worm initially seen targeting technology and manufacturing organizations. It has since grown to become one of the most prevalent threats facing enterprises.

Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs

11 April 2024
Only three critical vulnerabilities were fixed as part of the April 2024 Patch Tuesday updates, but there are over 67 remote code execution bugs. More than half of the RCE flaws are found within Microsoft SQL drivers, likely sharing a common flaw.

Analyzing CryptoJS Encrypted Phishing Attempt

11 April 2024
ARC Labs recently analyzed a phishing email used in a credential harvesting campaign that leveraged a lure notifying the target they received a voice message and needed to visit a link to access it.

Fortinet Fixed a Critical RCE Bug in FortiClientLinux

11 April 2024
Fortinet fixed a dozen vulnerabilities in multiple products, including a critical-severity remote code execution (RCE) issue, tracked as CVE-2023-45590 (CVSS score of 9.4), in FortiClientLinux.

Apple Expands Spyware Alert System to Warn Users of Mercenary Attacks

11 April 2024
Apple on Wednesday revised its documentation pertaining to its mercenary spyware threat notification system to mention that it alerts users when they may have been individually targeted by such attacks. It also specifically called out companies like NSO Group for developing commercial surveillance tools such as Pegasus that are used by state actors to pull off "individually targeted

Fortinet Rolls Out Critical Security Patches for FortiClientLinux Vulnerability

11 April 2024
Fortinet has released patches to address a critical security flaw impacting FortiClientLinux that could be exploited to achieve arbitrary code execution. Tracked as CVE-2023-45590, the vulnerability carries a CVSS score of 9.4 out of a maximum of 10. "An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientLinux may allow an unauthenticated attacker to

Twitter’s Clumsy Pivot to X.com Is a Gift to Phishers

10 April 2024
On April 9, Twitter/X began automatically modifying links that mention "twitter.com" to redirect to "x.com" instead. But over the past 48 hours, dozens of new domain names have been registered that demonstrate how this change could be used to craft convincing phishing links -- such as fedetwitter[.]com, which is currently rendered as fedex.com in tweets.

'eXotic Visit' Spyware Campaign Targets Android Users in India and Pakistan

10 April 2024
An active Android malware campaign dubbed eXotic Visit has been primarily targeting users in South Asia, particularly those in India and Pakistan, with malware distributed via dedicated websites and Google Play Store. Slovak cybersecurity firm said the activity, ongoing since November 2021, is not linked to any known threat actor or group. It's tracking the group behind the operation under the