Latest Cybersecurity News and Articles


Pokémon Resets Some Users’ Passwords After Hacking Attempts

20 March 2024
“The account system was not compromised. What we did experience and catch was an attempt to log in to some accounts. To protect our customers we have reset some passwords which prompted the message,” said Daniel Benkwitt, a company spokesperson said.

50,000 Vulnerabilities Discovered in DoD Systems Through Bug Bounty

20 March 2024
The DoD Cyber Crime Center (DC3) reported on March 15, 2024, that it processed its 50,000th vulnerability since introducing its crowd-sourced ethical hacking scheme in November 2016.

TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types

20 March 2024
Threat actors can exploit CVE-2024-27198 to perform a variety of malicious operations, including dropping the Jasmin ransomware, XMRig miner, Cobalt Strike beacons, SparkRAT backdoor, and executing domain discovery and persistence commands.

Ransomware Groups: Trust Us. Uh, Don't.

20 March 2024
Double extortion demands from ransomware groups aren't subtle: Pay us, or we'll publish stolen internal data for all the world to see. Being listed on the group's dark web leak sites is an intermediary step.

A new report predicts the threats that will be most prevalent in 2024

20 March 2024
A recent report has analyzed emerging threat trends as well as potential trends that may grow in influence in the coming months. 

Pharmaceutical Development Company Investigating Cyberattack After LockBit Posting

20 March 2024
A Nasdaq-listed pharmaceutical development company said it is investigating a cybersecurity incident following claims from the LockBit ransomware gang that data was stolen.

Ransomware Payment Debate Resurfaces Amid Change Healthcare Incident

20 March 2024
A hotly debated flashpoint in the cybersecurity community is getting renewed attention as healthcare stakeholders work to rebound from a major ransomware attack that’s roiled the U.S. health insurance market over the past month.

Generative AI Security - Secure Your Business in a World Powered by LLMs

20 March 2024
Did you know that 79% of organizations are already leveraging Generative AI technologies? Much like the internet defined the 90s and the cloud revolutionized the 2010s, we are now in the era of Large Language Models (LLMs) and Generative AI. The potential of Generative AI is immense, yet it brings significant challenges, especially in security integration. Despite their powerful capabilities,

TeamCity Flaw Leads to Surge in Ransomware, Cryptomining, and RAT Attacks

20 March 2024
Multiple threat actors are exploiting the recently disclosed security flaws in JetBrains TeamCity software to deploy ransomware, cryptocurrency miners, Cobalt Strike beacons, and a Golang-based remote access trojan called Spark RAT. The attacks entail the exploitation of CVE-2024-27198 (CVSS score: 9.8) that enables an adversary to bypass authentication measures and gain administrative

FTC Warns Scammers are Impersonating its Employees to Steal Money

20 March 2024
FTC staff has received numerous reports from consumers who have fallen victim to scams in which fraudsters exploited the identities of agency personnel to coerce them via phone calls, email, or text messages into transferring or wiring money.

What’s Material to the SEC, Three Months Into Cyber Disclosure Rules?

20 March 2024
Three months since the launch of the Securities and Exchange Commission’s cyber incident reporting rule, companies are grappling with the question of when the impact of a breach or attack is considered material.

LockBit Attempts to Stay Afloat With a New Version

20 March 2024
Recently, researchers came into possession of a sample believed to represent a new evolution of LockBit: an in-development version of a platform-agnostic malware-in-testing that is different from previous versions.

US is Still Chasing Down Pieces of Chinese Hacking Operation, NSA Official Says

20 March 2024
The U.S. government has yet to learn the full extent of a massive Chinese espionage campaign that targeted American critical infrastructure, according to a senior National Security Agency official.

CISA Shares Critical Infrastructure Defense Tips Against Chinese Hackers

20 March 2024
U.S. authorities are concerned that this Chinese group may exploit access to Operational Technology (OT) assets to further disrupt critical infrastructure and cause disruptions during military conflicts or geopolitical tensions.

New BunnyLoader Malware Variant Surfaces with Modular Attack Features

20 March 2024
Cybersecurity researchers have discovered an updated variant of a stealer and malware loader called BunnyLoader that modularizes its various functions as well as allow it to evade detection. "BunnyLoader is dynamically developing malware with the capability to steal information, credentials and cryptocurrency, as well as deliver additional malware to its victims," Palo Alto Networks

Threat Environment is Changing for Individuals and SMBs, White House Order Shows

20 March 2024
An executive order is trying to prevent the large-scale transfer of Americans’ data, as countries seek troves of U.S. data for blackmail, AI training, and analysis, among a multitude of other purposes.

Researchers Uncover New “Conversation Overflow” Tactics

20 March 2024
An advisory published by SlashNext today called the tactic a “Conversation Overflow” attack, a method that circumvents advanced security measures to deliver phishing messages directly into victims’ inboxes.

Earth Krahang APT Targets Organizations Worldwide

20 March 2024
An Earth Krahang APT campaign has been found targeting government entities worldwide, primarily in Southeast Asia, by exploiting vulnerabilities, spear-phishing, and abusing compromised government infrastructure. So far, seventy organizations spread across 23 countries have been targeted in the campaign. Leverage related IOCs to protect yourself.

In the Rush to Build AI Apps, Don’t Leave Security Behind

20 March 2024
While in a rush to understand, build, and ship AI products, developers and data scientists are being urged to be mindful of security and not fall prey to supply-chain attacks.

TMChecker Tool Lowers Barrier for Malicious Hacking

20 March 2024
It is priced at $200 per month and targets corporate VPN gateways, email servers, content management systems and hosting panels, according to a report by Resecurity researchers.