Latest Cybersecurity News and Articles


Update: Stanford Says Data From 27,000 People Leaked in September Ransomware Attack

13 March 2024
The breach specifically targeted the Department of Public Safety's network, resulting in the potential exposure of sensitive data such as Social Security numbers, driver's license numbers, and other personal information collected by the department.

Microsoft's March Updates Fix 61 Vulnerabilities, Including Critical Hyper-V Flaws

13 March 2024
Microsoft on Tuesday released its monthly security update, addressing 61 different security flaws spanning its software, including two critical issues impacting Windows Hyper-V that could lead to denial-of-service (DoS) and remote code execution. Of the 61 vulnerabilities, two are rated Critical, 58 are rated Important, and one is rated Low in severity. None of the flaws are listed as

How an infamous ransomware gang found itself hacked – podcast

12 March 2024
How an infamous ransomware gang found itself hacked – podcast LockBit was a sophisticated criminal operation, offering the tools needed to steal a company’s data and hold it to ransom. Then it was itself hacked. Alex Hern reportsA ransomware site on the dark web has allowed criminals to extort hospitals, businesses and schools for years. By encrypting data or threatening to post data online, hackers have cost companies millions of pounds.It’s called LockBit, and it was very successful until one day last month when hackers who logged on to the site found it had been hacked by authorities including the UK National Crime Agency and the FBI. These agencies announced they were in control of LockBit’s site, marking a new stage in their war on cybercrime. Continue reading...

Patch Tuesday, March 2024 Edition

12 March 2024
Apple and Microsoft recently released software updates to fix dozens of security holes in their operating systems. Microsoft today patched at least 60 vulnerabilities in its Windows OS. Meanwhile, Apple's new macOS Sonoma addresses at least 68 security weaknesses, and its latest updates for iOS fixes two zero-day flaws.

New DoNex Ransomware Observed in the Wild Targeting Enterprises

12 March 2024
The DoNex ransomware strain is actively targeting companies in the United States and Europe, employing a double-extortion method to hold files and sensitive data hostage.

ODNI Appoints New Election Security Leader Ahead of Presidential Race

12 March 2024
The Office of the Director of National Intelligence (ODNI) has appointed Jessica Brandt as the director of the Foreign Malign Influence Center, which aims to combat foreign interference in U.S. elections.

Steadybit's Chaos Engineering Platform Attracts $6M in Series A Funding

12 March 2024
By simulating disturbances and potential failures, Steadybit helps organizations preempt and mitigate system vulnerabilities, ultimately improving performance and user experience.

Stephen Ford hired as CISO at Rockwell Automation

12 March 2024
Rockwell Automation announced that Stephen Ford is joining the company as Vice President and Chief Information Security Officer (CISO).

Experts Released PoC Exploit for Critical Progress Software OpenEdge Bug

12 March 2024
Researchers from Horizon3.ai have disclosed technical details and a proof-of-concept exploit for a critical security flaw (CVE-2024-1403) in Progress Software OpenEdge Authentication Gateway and AdminServer.

CISA undertakes new efforts to fortify open source ecosystem

12 March 2024
The CISA announces new plans to secure the open source ecosystem. 

Report: Victims Lose $47 Million to Crypto Phishing Scams in February

12 March 2024
Impersonated accounts on X, formerly known as Twitter, have been responsible for a majority of crypto phishing attacks in the previous month. Per Scam Sniffer, victims lost almost $47 million to cybercriminals who stole from over 57,000 individuals.

Muddled Libra Threat Group Abuses Pentesting Tools to Infiltrate Networks

12 March 2024
Muddled Libra threat actors leverage pentesting tools to identify vulnerabilities in target systems and networks, enabling them to exploit security gaps and gain unauthorized access.

Tax-Related Scams Escalate as Filing Deadline Approaches

12 March 2024
Scammers are taking advantage of the rush to file personal federal income tax returns, using tactics such as impersonation, phone calls, tax identity theft, phishing scams, and unethical tax return preparers.

Incognito Darknet Market Mass-Extorts Buyers, Sellers

12 March 2024
The darknet narcotics market Incognito Market is extorting its vendors and buyers by threatening to publish their cryptocurrency transaction and chat records if they refuse to pay a fee.

Report: Three-Quarters of Cyber Incident Victims are Small Businesses

12 March 2024
Over 90% of cyber-attacks on small and medium businesses involve data or credential theft, with a notable increase in information-stealing malware targeting macOS, according to Sophos.

Malicious PyPI Packages Target Crypto Wallet Recovery Passwords in BIPClip Campaign

12 March 2024
The malicious packages used name squatting, disguised dependencies, and legitimate-looking code to steal mnemonic phrases, evading detection and targeting crypto assets without broader system compromise.

ODNI Releases New Open-Source Intelligence Strategy With Limited Details

12 March 2024
Intelligence agencies are developing new strategies to collect and process open-source intelligence (OSINT) through 2026, in response to the explosion of publicly and commercially available information.

Researchers Expose Microsoft SCCM Misconfigurations Usable in Cyberattacks

12 March 2024
The Misconfiguration Manager repository provides a comprehensive resource for both offensive professionals and defenders to understand and manage the attack path related to Microsoft Configuration Manager (MCM), formerly known as SCCM.

CloudGrappler: Open-Source Tool Detects Activity in Cloud Environments

12 March 2024
The open-source tool offers enhanced detection capabilities based on the tactics, techniques, and procedures (TTPs) of modern cloud threat actors like LUCR-3 (Scattered Spider).

Watch Out: These PyPI Python Packages Can Drain Your Crypto Wallets

12 March 2024
Threat hunters have discovered a set of seven packages on the Python Package Index (PyPI) repository that are designed to steal BIP39 mnemonic phrases used for recovering private keys of a cryptocurrency wallet. The software supply chain attack campaign has been codenamed BIPClip by ReversingLabs. The packages were collectively downloaded 7,451 times prior to them being removed from