Latest Cybersecurity News and Articles


Thread Hijacking: Phishes That Prey on Your Curiosity

28 March 2024
Thread hijacking attacks. They happen when someone you know has their email account compromised, and you are suddenly dropped into an existing conversation between the sender and someone else. These missives draw on the recipient's natural curiosity about being copied on a private discussion, which is modified to include a malicious link or attachment. Here's the story of a recent thread hijacking attack in which a journalist was copied on a phishing email from the unwilling subject of a recent scoop.

Linux Version of DinodasRAT Spotted in Cyber Attacks Across Several Countries

28 March 2024
A Linux version of a multi-platform backdoor called DinodasRAT has been detected in the wild targeting China, Taiwan, Turkey, and Uzbekistan, new findings from Kaspersky reveal. DinodasRAT, also known as XDealer, is a C++-based malware that offers the ability to harvest a wide range of sensitive data from compromised hosts. In October 2023, Slovak cybersecurity firm ESET 

Finland Blames Chinese Hacking Group APT31 for Parliament Cyber Attack

28 March 2024
The Police of Finland (aka Poliisi) has formally accused a Chinese nation-state actor tracked as APT31 for orchestrating a cyber attack targeting the country's Parliament in 2020. The intrusion, per the authorities, is said to have occurred between fall 2020 and early 2021. The agency described the ongoing criminal probe as both demanding and time-consuming, involving extensive analysis of a "

Darcula Phishing Network Leveraging RCS and iMessage to Evade Detection

28 March 2024
A sophisticated phishing-as-a-service (PhaaS) platform called Darcula has set its sights on organizations in over 100 countries by leveraging a massive network of more than 20,000 counterfeit domains to help cyber criminals launch attacks at scale. "Using iMessage and RCS rather than SMS to send text messages has the side effect of bypassing SMS firewalls, which is being used to great

Hackers Developing Malicious LLMs After WormGPT Falls Flat

28 March 2024
Cybercrooks are exploring ways to develop custom, malicious large language models after existing tools such as WormGPT failed to cater to their demands for advanced intrusion capabilities, security researchers said.

'Darcula' Phishing-as-a-Service Operation Bleeds Victims Across 100 More Than Countries

28 March 2024
The Chinese-language, phishing-as-a-service platform "Darcula" has created 19,000 phishing domains in cyberattacks against more than 100 countries, Netcraft researchers say.

Update: INC Ransom Claims Responsibility for Attack on NHS Scotland

28 March 2024
The INC Ransom group this week claimed responsibility for the assault on 'NHS Scotland', saying it stole 3TB worth of data while leaking a small number of sensitive files.

Vietnam Securities Broker Suffers Cyberattack That Resulted in Trading Suspension

28 March 2024
In a social media post, VNDirect described a four-stage process of restoration, starting with customer accounts, which is now complete, and followed by restoring floor trading and then its other financial services.

New Webinar: Avoiding Application Security Blind Spots with OPSWAT and F5

28 March 2024
Considering the ever-changing state of cybersecurity, it's never too late to ask yourself, "am I doing what's necessary to keep my organization's web applications secure?" The continuous evolution of technology introduces new and increasingly sophisticated threats daily, posing challenges to organizations all over the world and across the broader spectrum of industries striving to maintain

Municipalities in Texas, Georgia See Services Disrupted Following Ransomware Attacks

28 March 2024
On Tuesday evening, the government of Gilmer County in Georgia posted a notice on its website warning that a ransomware attack was affecting its ability to provide services to its more than 30,000 residents.

Google Fixes Chrome Zero-Days Exploited at Pwn2Own 2024

28 March 2024
Google fixed seven security vulnerabilities in the Chrome web browser on Tuesday, including two zero-days exploited during the Pwn2Own Vancouver 2024 hacking competition.

Apps Secretly Turning Devices Into Proxy Network Nodes Removed From Google Play

28 March 2024
Though the LumiApps’s privacy policy talks about devices being part of the LumiApps networks, app developers might not read it before starting to use the malicious SDK in their apps.

Behind the Scenes: The Art of Safeguarding Non-Human Identities

28 March 2024
In the whirlwind of modern software development, teams race against time, constantly pushing the boundaries of innovation and efficiency. This relentless pace is fueled by an evolving tech landscape, where SaaS domination, the proliferation of microservices, and the ubiquity of CI/CD pipelines are not just trends but the new norm. Amidst this backdrop, a critical aspect subtly weaves into the

New ZenHammer Attack Bypasses Rowhammer Defenses on AMD CPUs

28 March 2024
Cybersecurity researchers from ETH Zurich have developed a new variant of the RowHammer DRAM (dynamic random-access memory) attack that, for the first time, successfully works against AMD Zen 2 and Zen 3 systems despite mitigations such as Target Row Refresh (TRR). "This result proves that AMD systems are equally vulnerable to Rowhammer as Intel systems, which greatly increases the attack

CISA Adds One Known Exploited Vulnerability in Microsoft Sharepoint Server to Catalog

28 March 2024
The vulnerability, tracked as CVE-2023-24955 (CVSS score: 7.2), is a critical remote code execution flaw that allows an authenticated attacker with Site Owner privileges to execute arbitrary code.

Trezor’s Twitter Account Hijacked by Cryptocurrency Scammers via Bogus Calendly Invite

28 March 2024
According to Trezor, someone posing as "a credible entity from the crypto space", using a Twitter account with thousands of followers, approached its PR team on February 29, 2024. The imposter asked to interview Trezor CEO Matej Zak.

UK: NCSC Warns of Hackers Hitting High-Risk Individuals' Personal Accounts

28 March 2024
Britain's National Cyber Security Center is warning that criminals and nation-state hacking groups, confronted with well-managed corporate cybersecurity defenses, have turned their sights to individual personal devices and accounts.

Telegram Offers Premium Subscription in Exchange for Using Your Number to Send OTPs

28 March 2024
In June 2017, a study of more than 3,000 Massachusetts Institute of Technology (MIT) students published by the National Bureau for Economic Research (NBER) found that 98% of them were willing to give away their friends' email addresses in exchange for free pizza. "Whereas people say they care about privacy, they are willing to relinquish private data quite easily when

Leaked Documents Reveal Australia Targeted by Chinese APT31 Hackers

27 March 2024
A Chinese cybersecurity company with links to the Communist Party government used its guns-for-hire hacking operation to target Australia, leaked documents from iSoon revealed.

US State Department Warns Employees of Fraud Scheme Targeting Payroll Systems

27 March 2024
The State Department alert said that cybercriminals are attempting to use “phishing, email account takeovers, and social engineering” to veer employee payroll deposits into their own bank accounts.