Latest Cybersecurity News and Articles
14 March 2024
The vulnerability affects default installations of Kubernetes earlier than version 1.28.4 running on-prem deployments and Azure Kubernetes Service, highlighting the importance of patching.
14 March 2024
A 34-year-old Russian-Canadian national has been sentenced to nearly four years in jail in Canada for his participation in the LockBit global ransomware operation.
Mikhail Vasiliev, an Ontario resident, was originally arrested in November 2022 and charged by the U.S. Department of Justice (DoJ) with "conspiring with others to intentionally damage protected computers and to transmit
14 March 2024
To aid manufacturers, researchers, developers, and cybersecurity professionals, the methodology includes resources for assessing the security of Bluetooth communications and will publish proofs of concept and scripts on GitHub.
14 March 2024
The vulnerability in the portal, built on Salesforce's health cloud, allowed any member of the public registering with the portal to access the vaccination records of other registered users, including personal details and internal HSE documents.
14 March 2024
The scam involves cybercriminals posing as Microsoft or Apple employees and convincing victims to transfer their funds to a fake "treasury account." The scammers also had victims install a digital currency wallet and transfer funds to USDT accounts.
14 March 2024
Threat actors have been observed using SVG image files to distribute Agent Tesla keylogger and XWorm RAT malware in a two-month campaign. The use of SVG files allows threat actors to evade detection and successfully deliver harmful payloads.
14 March 2024
Data from the Federal Trade Commission (FTC) revealed that investment scams resulted in over $4.6 billion in fraud losses in the United States in 2023, marking a troubling 21% rise from the previous year.
14 March 2024
New research discloses the areas in ChatGPT plugins that could have been exploited.
14 March 2024
Details have been made public about a now-patched high-severity flaw in Kubernetes that could allow a malicious attacker to achieve remote code execution with elevated privileges under specific circumstances.
“The vulnerability allows remote code execution with SYSTEM privileges on all Windows endpoints within a Kubernetes cluster,” Akamai security researcher Tomer Peled said. “To exploit
14 March 2024
PixPirate utilizes two apps, including a downloader and a hidden malware app, to steal information and automate fraudulent transactions on the popular Brazilian payment platform Pix.
14 March 2024
The Zero Day Initiative (ZDI) recently discovered a DarkGate campaign in mid-January 2024, leveraging CVE-2024-21412 with fake software installers distributed via Google DoubleClick Digital Marketing open redirects.
14 March 2024
These types of malware are used by attackers to steal data and credentials, which are then leveraged to gain unauthorized access, deploy ransomware, and carry out extortion.
14 March 2024
The CISA and the Office of Management and Budget (OMB) have released an attestation form aimed at ensuring compliance with secure development practices for software producers working with the U.S. government.
14 March 2024
The BlackCat ransomware gang claims to have stolen 6TB of data from Change Healthcare, including sensitive information from various healthcare providers and insurance companies.
14 March 2024
Being a CISO is a balancing act: ensuring organizations are secure without compromising users’ productivity. This requires taking multiple elements into consideration, like cost, complexity, performance and user experience. CISOs around the globe use Cato SSE 360, as part of the Cato SASE Cloud platform to balance these factors without compromise.
This article details how CISOs are
14 March 2024
The Russian-speaking cybercrime group called RedCurl is leveraging a legitimate Microsoft Windows component called the Program Compatibility Assistant (PCA) to execute malicious commands.
“The Program Compatibility Assistant Service (pcalua.exe) is a Windows service designed to identify and address compatibility issues with older programs,” Trend Micro said in an analysis
14 March 2024
Bitcoin Fog was a prominent cryptocurrency "tumbler" on the dark web, allowing cybercriminals to obscure the origins of their digital assets and make them harder to trace.
14 March 2024
With the emergence of "interactive AI," security considerations become crucial. Interactive AI expands chatbots and digital assistants' capabilities, presenting new risks. Companies must exercise control and set boundaries to manage these risks.
14 March 2024
LockBit ransomware affiliate Mikhail Vasiliev received a nearly four-year prison sentence in Canada and consented to extradition to the United States for conspiracy to commit computer intrusion.
14 March 2024
Fortinet patched a critical SQL injection vulnerability (CVE-2023-48788) in its FortiClient EMS software, allowing unauthenticated attackers to achieve remote code execution with SYSTEM privileges.