Latest Cybersecurity News and Articles


Funding Round Secures $20M for Reach Security

11 March 2024
The Series A funding was led by new investors Ballistic Ventures and Artisanal Ventures, as well as existing backers Webb Investment Network, Ridge Ventures, and TechOperators.

UK: Cyberattack Cripples Leicester City Council Systems Until ‘At Least Midweek'

11 March 2024
While the nature of the cyberattack has not been disclosed, it is noted that this incident is part of a series of attacks on local authorities this year, with the latest affecting the council's ability to provide essential services.

Dozens of Data Brokers Disclose Selling Reproductive Healthcare Info, Precise Geolocation and Data Belonging to Minors

11 March 2024
New information from the state of California reveals that many data brokers collect and sell sensitive information, including data related to reproductive health, geolocation, and minors.

New Banking Trojan CHAVECLOAK Targets Brazilian Users via Phishing Tactics

11 March 2024
Users in Brazil are the target of a new banking trojan known as CHAVECLOAK that's propagated via phishing emails bearing PDF attachments. "This intricate attack involves the PDF downloading a ZIP file and subsequently utilizing DLL side-loading techniques to execute the final malware," Fortinet FortiGuard Labs researcher Cara Lin said. The attack chain involves the use of

Embracing the Cloud: Revolutionizing Privileged Access Management with One Identity PAM Essentials

11 March 2024
As cyber threats loom around every corner and privileged accounts become prime targets, the significance of implementing a robust Privileged Access Management (PAM) solution can't be overstated. With organizations increasingly migrating to cloud environments, the PAM Solution Market is experiencing a transformative shift toward cloud-based offerings. One Identity PAM Essentials stands

Iran-Linked ‘Lord Nemesis’ Group Appears Intent on Intimidating Israeli Organizations, Report Says

11 March 2024
An Iranian state-backed hacking group, known as Lord Nemesis, targeted an Israeli academic administration software company called Rashim Software. The attackers used their access to infiltrate several of the company's clients.

How New and Old Security Threats Keep Persisting

11 March 2024
New research by Cymulate highlights the correlation between threat exposures, vulnerabilities, misconfigurations, and security controls. It emphasizes the importance of proactive security measures to prevent cyberattacks.

CISA Forced to Take Two Systems Offline Last Month After Ivanti Compromise

11 March 2024
The breach was limited to two systems, the Infrastructure Protection (IP) Gateway and the Chemical Security Assessment Tool (CSAT), which house critical information about U.S. infrastructure interdependency and private sector chemical security plans.

78% of MSPs state cybersecurity is a prominent IT challenge

11 March 2024
A recent report surveyed 1,000 MSPs, revealing attitudes about the value of cybersecurity. 

Bills Targeting Data Brokers and TikTok Approved in House Committee

11 March 2024
The House Energy and Commerce Committee approved two significant data privacy bills, including one targeting TikTok's Chinese ownership and another blocking data brokers from selling Americans' data to foreign adversaries.

Magnet Goblin Targets Publicly Facing Servers Using 1-Day Vulnerabilities

11 March 2024
Magnet Goblin is a financially motivated threat actor that rapidly exploits 1-day vulnerabilities in public-facing services to initiate attacks. This actor has targeted Ivanti, Magento, Qlink Sense, and possibly Apache ActiveMQ.

Paysign Investigating Reports of Stolen Database Being Sold by Hackers

11 March 2024
Hackers attempted to sell a database allegedly belonging to the company, which is said to contain millions of records. Despite this, Paysign assured that there has been no disruption to their services, and customers can continue using their accounts.

Dropbox Used to Steal Credentials and Bypass MFA in Phishing Campaign

11 March 2024
The use of legitimate Dropbox infrastructure in the phishing campaign allowed the attackers to effectively evade detection by email security tools and bypass MFA protocols.

Data Leakage Prevention in the Age of Cloud Computing: A New Approach

11 March 2024
As the shift of IT infrastructure to cloud-based solutions celebrates its 10-year anniversary, it becomes clear that traditional on-premises approaches to data security are becoming obsolete. Rather than protecting the endpoint, DLP solutions need to refocus their efforts to where corporate data resides - in the browser. A new guide by LayerX titled "On-Prem is Dead. Have You Adjusted Your Web

Immediate AI Risks and Tomorrow's Dangers

11 March 2024
AI has given malicious attackers superpowers, making fishing, smishing, vishing, and other attacks more accessible and impactful. Immediate threats include sensitive data leakage from AI-powered systems.

New Golang-based Planet Stealer Emerges in Underground Forums

11 March 2024
Planet Stealer is a Go-based information-stealing trojan that targets sensitive information from victim hosts. The trojan's capabilities include browser information theft, cryptocurrency wallet theft, and sandbox evasion.

UK Government’s Ransomware Failings Leave Country ‘Exposed and Unprepared’

11 March 2024
The UK government has been criticized for a lack of preparedness and strategic response to the growing threat of ransomware attacks, with a parliamentary committee accusing it of an "ostrich strategy" of burying its head in the sand.

Cisco Addressed Severe Flaws in Its Secure Client

11 March 2024
Cisco Secure Client is affected by two high-severity vulnerabilities, CVE-2024-20337 and CVE-2024-20338, which could lead to code execution and unauthorized remote access VPN sessions.

Zama’s Homomorphic Encryption Tech Lands it $73M on a Valuation of Nearly $400M

11 March 2024
Zama, a Paris-based startup, has raised $73 million in a Series A funding round to develop and commercialize homomorphic encryption technology for blockchain transactions and AI data exchange.

BianLian Threat Actors Exploiting JetBrains TeamCity Flaws in Ransomware Attacks

11 March 2024
The threat actors behind the BianLian ransomware have been observed exploiting security flaws in JetBrains TeamCity software to conduct their extortion-only attacks. According to a new report from GuidePoint Security, which responded to a recent intrusion, the incident "began with the exploitation of a TeamCity server which resulted in the deployment of a PowerShell implementation of