Latest Cybersecurity News and Articles


AUCloud Announces $30 Million Acquisition of Three IT Firms

20 March 2024
The ASX-listed cloud and cyber security provider AUCloud has announced it has entered into binding agreements to acquire Australian IT firms PCG Cyber, Venn IT, and Arado.

Three New Critical Vulnerabilities Uncovered in Argo

20 March 2024
The vulnerabilities, identified by KTrust’s in-house researchers, pose significant risks to system security, including bypassing rate limit and brute force protection mechanisms, triggering DoS attacks and compromising user account safety.

Ukraine Arrests Trio for Hijacking Over 100 Million Email and Instagram Accounts

20 March 2024
The Cyber Police of Ukraine has arrested three individuals on suspicion of hijacking more than 100 million emails and Instagram accounts from users across the world. The suspects, aged between 20 and 40, are said to be part of an organized criminal group living in different parts of the country. If convicted, they face up to 15 years in prison. The accounts, authorities said, were

U.S. EPA Forms Task Force to Protect Water Systems from Cyberattacks

20 March 2024
The U.S. Environmental Protection Agency (EPA) said it's forming a new "Water Sector Cybersecurity Task Force" to devise methods to counter the threats faced by the water sector in the country. "In addition to considering the prevalent vulnerabilities of water systems to cyberattacks and the challenges experienced by some systems in adopting best practices, this Task Force in its deliberations

900 Sites, 125 million accounts, 1 vulnerability

19 March 2024
Hundreds of websites misconfigured Google Firebase, leaking more than 125 million user records, including plaintext passwords, security researchers warn. It all started with the hacking of Chattr, a US-based AI hiring system.

APIs Drive the Majority of Internet Traffic and Cybercriminals are Taking Advantage

19 March 2024
Application programming interfaces (APIs) are the connective tissue behind digital modernization, helping applications and databases exchange data more effectively. The State of API Security in 2024 Report from Imperva, a Thales company, found that the majority of internet traffic (71%) in 2023 was API calls. What’s more, a typical enterprise site saw an average of 1.5 billion API

Cyberattack Knocks Out Pensacola City Government Phone Lines

19 March 2024
City spokesperson Jason Wheeler told Recorded Future News that officials are experiencing phone issues across city departments that are causing delays in receiving service through the 311 Citizen Support system.

Public Anxiety Mounts Over Critical Infrastructure Resilience to Cyberattacks

19 March 2024
With temporary failures of critical infrastructure on the rise in the recent years, 81% of US residents are worried about how secure critical infrastructure may be, according to MITRE and The Harris Poll.

Mintlify Says Customer GitHub Tokens Exposed in Data Breach

19 March 2024
In a blog post on Monday, Mintlify blamed its March 1 incident on a vulnerability in its own systems but said 91 of its customers had their GitHub tokens compromised as a result.

Finland, Germany, Ireland, Japan, Poland, South Korea Added to US-Led Spyware Agreement

19 March 2024
The signees agree to establish “robust guardrails and procedures" around spyware, prevent the export of technology that will be used for malicious cyber activity, share information on spyware proliferation and work to raise awareness globally.

Nations Direct Mortgage Alerts 83,000 to Personal Data Breach From December 2023 Cyberattack

19 March 2024
In filings with regulators in Maine and California, the company said it discovered a cybersecurity incident on December 30 that prompted an investigation. Law enforcement and other governmental agencies were notified of the cyberattack.

From Deepfakes to Malware: AI's Expanding Role in Cyber Attacks

19 March 2024
Large language models (LLMs) powering artificial intelligence (AI) tools today could be exploited to develop self-augmenting malware capable of bypassing YARA rules. "Generative AI can be used to evade string-based YARA rules by augmenting the source code of small malware variants, effectively lowering detection rates," Recorded Future said in a new report shared with The Hacker News.

BigID Raises $60M, Eyes M&A Around Data Security, Compliance

19 March 2024
This investment round, led by Riverwood Capital with contributions from Silver Lake Waterman and Advent, bolsters BigID's efforts in data hygiene and securing sensitive data access.

Researchers Spot Updated Version of Malware That Hit Viasat

19 March 2024
Wiper attacks have been a go-to for Russian attacks on Ukrainian government and private-sector targets in the past two years, and the latest version of the software used to target Viasat shows how Russian hacking groups are evolving their tools.

A newly uncovered phishing campaign that spreads remote access trojans

19 March 2024
Experts share their insights on the newly discovered phishing campaign that encourages targets to download a malicious Java downloader. 

Crafting and Communicating Your Cybersecurity Strategy for Board Buy-In

19 March 2024
In an era where digital transformation drives business across sectors, cybersecurity has transcended its traditional operational role to become a cornerstone of corporate strategy and risk management. This evolution demands a shift in how cybersecurity leaders—particularly Chief Information Security Officers (CISOs)—articulate the value and urgency of cybersecurity investments to their boards.&

Hackers Exploiting Popular Document Publishing Sites for Phishing Attacks

19 March 2024
Threat actors are leveraging digital document publishing (DDP) sites hosted on platforms like FlipSnack, Issuu, Marq, Publuu, RelayTo, and Simplebooklet for carrying out phishing, credential harvesting, and session token theft, once again underscoring how threat actors are repurposing legitimate services for malicious ends. "Hosting phishing lures on DDP sites increases the likelihood

Update: 133k+ Fortinet Appliances Still Vulnerable to CVE-2024-21762

19 March 2024
The wide geographic distribution of vulnerable SSL VPNs highlights the extensive attack surface for the critical vulnerability, with Asia having the highest number of exposed appliances.

The Aviation and Aerospace Sectors Face Skyrocketing Cyber Threats

19 March 2024
In an increasingly fragmented geopolitical landscape, influenced by the war in Ukraine and rising tensions in the Middle East, the aerospace sector’s designation as critical infrastructure has become a double-edged sword.

PoC Exploit for Critical RCE in Fortra FileCatalyst Tool Released

19 March 2024
The critical vulnerability, tracked as CVE-2024-25153 with a CVSS score of 9.8, allows remote attackers to upload files outside the intended directory and execute arbitrary code.