Latest Cybersecurity News and Articles


CEO of Data Privacy Company Onerep.com Founded Dozens of People-Search Firms

18 March 2024
Historical domain registration records suggest that the founder of Onerep, Dimitri Shelest, has been involved in numerous people-search services, indicating potential conflicts of interest.

Fortra Patches Critical RCE Vulnerability in FileCatalyst Transfer Tool

18 March 2024
Fortra has released details of a now-patched critical security flaw impacting its FileCatalyst file transfer solution that could allow unauthenticated attackers to gain remote code execution on susceptible servers. Tracked as CVE-2024-25153, the shortcoming carries a CVSS score of 9.8 out of a maximum of 10. "A directory traversal within the 'ftpservlet' of the FileCatalyst Workflow

Hackers Using Sneaky HTML Smuggling to Deliver Malware via Fake Google Sites

18 March 2024
Cybersecurity researchers have discovered a new malware campaign that leverages bogus Google Sites pages and HTML smuggling to distribute a commercial malware called AZORult in order to facilitate information theft. "It uses an unorthodox HTML smuggling technique where the malicious payload is embedded in a separate JSON file hosted on an external website," Netskope Threat Labs

Human Risk Factors Remain Outside of Cybersecurity Pros’ Control

18 March 2024
Concerns are especially high in the public sector, with 87% worrying about employee email and social media lapses damaging their institutions, according to a Mimecast report.

'Gitgub' Malware Campaign Targets GitHub Users with RisePro Info-Stealer

18 March 2024
Multiple GitHub repositories were hosting cracked software designed to deliver the RisePro info-stealer, indicating a widespread campaign to distribute the malware. The repositories were taken down by GitHub, and all used the same download link.

CISA Launches 911 Cybersecurity Hub Empowering Emergency Responders

18 March 2024
The hub offers a centralized repository of essential resources and expertise, sourced from federal agencies, industry partners, academia, and the private sector, to enhance the cybersecurity posture of Emergency Communications Centers (ECCs).

AT&T Says Leaked Data of 70 Million People is Not From its Systems

18 March 2024
The leaked data includes customers' sensitive personal information such as names, addresses, mobile phone numbers, encrypted dates of birth, and encrypted Social Security numbers.

Key MITRE ATT&CK Techniques Used by Cyberattackers

18 March 2024
In 2023, researchers identified new adversary techniques targeting macOS, Microsoft, and Linux users, including increased stealer activity in macOS environments, reflective code loading, and AppleScript abuse.

Report: Only 13% of Medical Devices Support Endpoint Protection Agents

18 March 2024
About 63% of CISA-tracked known exploited vulnerabilities can be found on healthcare networks, with 23% of medical devices having at least one known exploited vulnerability, according to Claroty.

Hackers Exploit Aiohttp Bug to Find Vulnerable Networks

18 March 2024
The ransomware actor 'ShadowSyndicate' has been scanning for servers vulnerable to CVE-2024-23334, a directory traversal flaw in the aiohttp Python library. Aiohttp is widely used by tech firms and web developers to handle concurrent HTTP requests.

WordPress Admins Urged to Remove miniOrange Plugins Due to Critical Flaw

18 March 2024
WordPress users of miniOrange's Malware Scanner and Web Application Firewall plugins are being urged to delete them from their websites following the discovery of a critical security flaw. The flaw, tracked as CVE-2024-2172, is rated 9.8 out of a maximum of 10 on the CVSS scoring system. It impacts the following versions of the two plugins - Malware Scanner (versions <= 4.7.2) Web

Stronger FCC Data Breach Reporting Rules for Telecom Go Live

18 March 2024
The new FCC rules not only mandate reporting to the FCC and law enforcement agencies but also require carriers to promptly inform customers about the breach and the potential risk to their personal information.

US Moves to Recover $2.3 Million From “Pig Butchers” on Binance

18 March 2024
The U.S. Department of Justice (DoJ) has successfully recovered $2.3 million worth of cryptocurrency associated with a "pig butchering" fraud scheme that targeted at least 37 individuals across the United States.

Audit Committees Rank Cybersecurity as Top Priority Amid SEC Crackdown

18 March 2024
Audit committees rank cybersecurity as their top oversight priority, the Center for Audit Quality and Deloitte found in a survey conducted as the Securities and Exchange Commission pushed forward with strict rules on cyberattack disclosure.

Estonian Startup BotGuard OÜ Raises $13M for Web Traffic Control

18 March 2024
The Series A funding round was led by MMC Ventures, with participation from Tera Ventures, Expeditions Fund, and prominent angel investors. The company was founded in 2019 by Nik Rozenberg and Denis Prochko.

Hackers Claim Accessing 740GB of Data from Viber Messaging App

18 March 2024
The hackers demanded a ransom of 8 Bitcoin (equivalent to $583,000) for the stolen information. Viber denies the breach but is conducting an investigation to verify the claim.

APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme

18 March 2024
The Russia-linked threat actor known as APT28 has been linked to multiple ongoing phishing campaigns that employ lure documents imitating government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America. "The uncovered lures include a mixture of internal and publicly available documents, as well as possible actor-generated

Millions more in cash needed to fund UK’s open-banking watchdog

17 March 2024
Millions more in cash needed to fund UK’s open-banking watchdog Exclusive: £10m needed for regulator charged with developing tools to thwart financial crime and protect consumersBanks are under pressure to stump up millions of pounds in interim funding for the organisation that polices open banking, with regulators saying the new money is needed to prevent financial crime and protect consumers if things “go wrong”.Large banks including NatWest, HSBC, Lloyds and Santander UK were among more than 40 City firms summoned by the Financial Conduct Authority (FCA) last week to discuss a cash injection into Open Banking Limited (OPL), the body that oversees innovation in this area. Continue reading...

Hackers Using Cracked Software on GitHub to Spread RisePro Info Stealer

16 March 2024
Cybersecurity researchers have found a number of GitHub repositories offering cracked software that are used to deliver an information stealer called RisePro. The campaign, codenamed gitgub, includes 17 repositories associated with 11 different accounts, according to G DATA. The repositories in question have since been taken down by the Microsoft-owned subsidiary. "The repositories look

Lazarus Group Hackers Appear to Return to Tornado Cash for Money Laundering

16 March 2024
North Korea’s Lazarus hacking group has reportedly used the Tornado Cash mixing service to launder $23 million stolen during a November 2023 cyberattack on the HTX cryptocurrency exchange.