Latest Cybersecurity News and Articles


Security leaders discuss Microsoft's stolen source code

12 March 2024
Following a cyberattack from Midnight Blizzard, Security leaders share their thoughts. 

EquiLend Warns Employees Their Data Was Stolen by Ransomware Gang

12 March 2024
The company initially took some systems offline to contain the breach. Although the nature of the incident was not immediately disclosed, LockBit ransomware claimed responsibility for the attack.

CISA Lacks Staff with Skills Needed to Safeguard OT

12 March 2024
The U.S. Government Accountability Office (GAO) recently released a report critiquing the information-sharing practices of the CISA with critical infrastructure stakeholders, warning about staffing shortages for handling OT incidents.

CTEM 101 - Go Beyond Vulnerability Management with Continuous Threat Exposure Management

12 March 2024
In a world of ever-expanding jargon, adding another FLA (Four-Letter Acronym) to your glossary might seem like the last thing you’d want to do. But if you are looking for ways to continuously reduce risk across your environment while making significant and consistent improvements to security posture, in our opinion, you probably want to consider establishing a Continuous Threat Exposure

French Government Agencies Hit by Cyberattacks of ‘Unprecedented Intensity’

12 March 2024
In response to the cyberattacks, a crisis cell has been activated to deploy countermeasures, reducing the impact on most public services and restoring access to state websites.

Tuta Mail Adds New Quantum-Resistant Encryption to Protect Email

12 March 2024
Tuta Mail has introduced TutaCrypt, a new post-quantum encryption protocol to safeguard communications from anticipated decryption attacks, offering strong protection against future threats.

US Federal Budget Proposes $27.5B for Cybersecurity

12 March 2024
The Biden administration has unveiled a $1.67 trillion discretionary spending proposal, which includes a modest increase in federal cybersecurity spending. The budget allocates $13 billion for federal civilian cybersecurity.

Broadcom Axes Carbon Black Sale, to Merge Unit with Symantec

12 March 2024
This decision came after offers to purchase Carbon Black fell short of expectations, resulting in Broadcom's strategic shift to retain the company and merge it with Symantec.

Update: Okta Says Data Leaked on Hacking Forum Not From its Systems

12 March 2024
The leaked data claimed to be from Okta includes user IDs, full names, company names, office addresses, phone numbers, email addresses, positions/roles, and other information.

Malware Campaign Exploits Popup Builder WordPress Plugin to Infect 3,900+ Sites

12 March 2024
A new malware campaign is leveraging a high-severity security flaw in the Popup Builder plugin for WordPress to inject malicious JavaScript code. According to Sucuri, the campaign has infected more than 3,900 sites over the past three weeks. "These attacks are orchestrated from domains less than a month old, with registrations dating back to February 12th, 2024," security researcher

British Authorities Have Never Detected a Breach of Ransomware Sanctions — But is That Good or Bad News?

12 March 2024
Aside from frustrating ransomware payments, the sanctions regime is used by law enforcement agencies to hamper the ability of cyber threat actors to monetize their criminal activities and sow discord within certain groups.

Roku Cancels Unauthorized Subscriptions and Provides Refunds for 15K Breached Accounts

12 March 2024
Roku canceled unauthorized subscriptions, refunded affected user accounts, and reset passwords after discovering a breach involving hacked username and password combinations.

Ransomware Attacks are Hitting Critical Infrastructure More Often, FBI Says

12 March 2024
According to the FBI's annual Internet Crime Report for 2023, more than 2 in 5 ransomware attacks in 2023 targeted organizations in critical infrastructure sectors, indicating a growing threat to essential services.

Update: Third-Party Breach and Missing MFA Led to British Library Attack

12 March 2024
The attackers successfully copied a significant amount of data, including personal details of Library users and staff, leading to a deep and extensive impact on the institution.

South Korean Citizen Detained in Russia on Cyber Espionage Charges

12 March 2024
Russia has detained a South Korean national for the first time on cyber espionage charges and transferred from Vladivostok to Moscow for further investigation. The development was first reported by Russian news agency TASS. “During the investigation of an espionage case, a South Korean citizen Baek Won-soon was identified and detained in Vladivostok, and put into custody under a court

Belgian Village Whose Brewery was Hit by Cyberattack Faces Another on its Coffee Roastery

11 March 2024
The Belgian village of Breendonk has experienced cyberattacks targeting both Duvel Moortgat Brewery and local coffee roasters Koffie Beyers, with the incidents occurring at the same time and in close geographic proximity.

CISA shares resources to bolster election security for 2024 primaries

11 March 2024
A statement released by the CISA discusses the importance of election security as well as the organization’s measures to support election officials. 

BianLian Group Exploits JetBrains TeamCity Bugs in Ransomware Attacks

11 March 2024
The BianLian ransomware group exploited vulnerabilities in JetBrains TeamCity software to gain initial access to target environments. The group attempted to execute a custom GO backdoor but switched to LotL and utilized a PowerShell backdoor instead.

Incognito Darknet Market Mass-Extorts Buyers, Sellers

11 March 2024
Borrowing from the playbook of ransomware purveyors, the darknet narcotics bazaar Incognito Market has begun extorting all of its vendors and buyers, threatening to publish cryptocurrency transaction and chat records of users who refuse to pay a fee ranging from $100 to $20,000. The bold mass extortion attempt comes just days after Incognito Market administrators reportedly pulled an "exit scam" that left users unable to withdraw millions of dollars worth of funds from the platform.

Fake Leather Wallet App on Apple App Store is a Crypto Drainer

11 March 2024
The developers of the Leather cryptocurrency wallet have issued a warning about a counterfeit app on the Apple App Store. This fake app has led to users reporting that it drains their wallets and steals their digital assets.