Latest Cybersecurity News and Articles


Email Bomb Attacks: Filling Up Inboxes and Servers Near You

22 March 2024
The HHS' Health Sector Cybersecurity Coordination Center in an alert warned that email bomb attacks - also known as letter bomb attacks - pose a considerable potential threat.

Luxury Yacht Dealer Attack Claimed by Rhysida Gang

22 March 2024
MarineMax, which posted multibillion-dollar revenues last year, disclosed a cyberattack to the Securities and Exchange Commission (SEC) on March 10, saying portions of its business were disrupted as a result of the containment measures it enacted.

WebCopilot: Open-Source Automation Tool Enumerates Subdomains, Detects Bugs

22 March 2024
WebCopilot is an open-source automation tool that enumerates a target’s subdomains and discovers bugs using various free tools. It simplifies the application security workflow and reduces reliance on manual scripting.

South China Athletic Association Suffers Cyberattack Potentially Compromising 70,000 Members’ Data

22 March 2024
The South China Athletic Association (SCAA) was rocked by a cyberattack as unauthorized third parties breached the organization’s computer servers, sparking concerns over the security of member data.

New StrelaStealer Phishing Attacks Hit Over 100 Organizations in E.U. and U.S.

22 March 2024
Cybersecurity researchers have detected a new wave of phishing attacks that aim to deliver an ever-evolving information stealer referred to as StrelaStealer. The campaigns impact more than 100 organizations in the E.U. and the U.S., Palo Alto Networks Unit 42 researchers said in a new report published today. "These campaigns come in the form of spam emails with attachments that eventually

US Airlines’ Privacy Protection Practices to Get DOT Review

22 March 2024
The Department of Transportation (DOT) will review data collection practices for the country's 10 largest airlines in a bid to improve passenger privacy protections, Secretary Pete Buttigieg said on Thursday.

AWS Patches Critical 'FlowFixation' Bug in Airflow Service to Prevent Session Hijacking

22 March 2024
Cybersecurity researchers have shared details of a now-patched security vulnerability in Amazon Web Services (AWS) Managed Workflows for Apache Airflow (MWAA) that could be potentially exploited by a malicious actor to hijack victims' sessions and achieve remote code execution on underlying instances. The vulnerability, now addressed by AWS, has been codenamed FlowFixation by Tenable.

78% of organizations plan to increase ransomware protection

22 March 2024
Ransomware protection is top of mind for both CXOs and practitioners but most organizations continue to struggle in the wake of attacks.

Fake Data Breaches: Countering the Damage

22 March 2024
Amid the constant drumbeat of successful cyberattacks, some fake data breaches have also cropped up to make sensational headlines. Unfortunately, even fake data breaches can have real repercussions.

GitHub’s New AI-Powered Tool Auto-Fixes Vulnerabilities in Your Code

22 March 2024
GitHub introduced a new AI-powered feature capable of speeding up vulnerability fixes while coding. This feature is in public beta and automatically enabled on all private repositories for GitHub Advanced Security (GHAS) customers.

The CISA releases a secure software development attestation form

22 March 2024
The CISA has released a set of guidelines to ensure that software developers are creating secure software systems for the government.

Jacksonville Beach Report Data Breach Following Cyberattacks

22 March 2024
The city government of Jacksonville Beach was just the latest to report such an incident, disclosing Wednesday evening that 48,949 people had personal information accessed during a January cyberattack.

RaaS Groups Increasing Efforts to Recruit Affiliates

22 March 2024
Smaller RaaS groups are trying to recruit new and “displaced” LockBit and Alphv/BlackCat affiliates by foregoing deposits and paid subscriptions, offering better payout splits, 24/7 support, and other “perks.”

China-Linked Group Breaches Networks via Connectwise, F5 Software Flaws

22 March 2024
A China-linked threat cluster leveraged security flaws in Connectwise ScreenConnect and F5 BIG-IP software to deliver custom malware capable of delivering additional backdoors on compromised Linux hosts as part of an "aggressive" campaign. Google-owned Mandiant is tracking the activity under its uncategorized moniker UNC5174 (aka Uteus or Uetus), describing it as a "former

Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects

22 March 2024
A massive malware campaign dubbed Sign1 has compromised over 39,000 WordPress sites in the last six months, using malicious JavaScript injections to redirect users to scam sites. The most recent variant of the malware is estimated to have infected no less than 2,500 sites over the past two months alone, Sucuri said in a report published this week. The attacks entail injecting rogue

Implementing Zero Trust Controls for Compliance

22 March 2024
The ThreatLocker® Zero Trust Endpoint Protection Platform implements a strict deny-by-default, allow-by-exception security posture to give organizations the ability to set policy-based controls within their environment and mitigate countless cyber threats, including zero-days, unseen network footholds, and malware attacks as a direct result of user error. With the capabilities of the

Chinese Government Hacker Exploiting Screenconnect, F5 Bugs To Attack Defense and Government Entities

22 March 2024
A hacker allegedly connected to the People's Republic of China has been exploiting two popular vulnerabilities to attack U.S. defense contractors, U.K. government entities, and institutions in Asia.

Change Healthcare Cyberattack Could Damage Credit at Small Providers: Fitch

22 March 2024
The cyberattack against Change Healthcare could damage the credit of smaller providers, pharmacies, and other healthcare organizations that rely on the UnitedHealth-owned technology company for financial services, as per a report from Fitch Ratings.

API Environments Becoming Hotspots for Exploitation

22 March 2024
A total of 29% of web attacks targeted APIs over 12 months (January through December 2023), indicating that APIs are a focus area for cybercriminals, according to Akamai.

Windows 11, Tesla, and Ubuntu Linux Hacked at Pwn2Own Vancouver

22 March 2024
On the first day of Pwn2Own Vancouver 2024, contestants demoed 19 zero-day vulnerabilities in Windows 11, Tesla, Ubuntu Linux, and other devices and software to win $732,500 and a Tesla Model 3 car.