Latest Cybersecurity News and Articles


New Golang-based Planet Stealer Emerges in Underground Forums

11 March 2024
Planet Stealer is a Go-based information-stealing trojan that targets sensitive information from victim hosts. The trojan's capabilities include browser information theft, cryptocurrency wallet theft, and sandbox evasion.

UK Government’s Ransomware Failings Leave Country ‘Exposed and Unprepared’

11 March 2024
The UK government has been criticized for a lack of preparedness and strategic response to the growing threat of ransomware attacks, with a parliamentary committee accusing it of an "ostrich strategy" of burying its head in the sand.

Cisco Addressed Severe Flaws in Its Secure Client

11 March 2024
Cisco Secure Client is affected by two high-severity vulnerabilities, CVE-2024-20337 and CVE-2024-20338, which could lead to code execution and unauthorized remote access VPN sessions.

Zama’s Homomorphic Encryption Tech Lands it $73M on a Valuation of Nearly $400M

11 March 2024
Zama, a Paris-based startup, has raised $73 million in a Series A funding round to develop and commercialize homomorphic encryption technology for blockchain transactions and AI data exchange.

BianLian Threat Actors Exploiting JetBrains TeamCity Flaws in Ransomware Attacks

11 March 2024
The threat actors behind the BianLian ransomware have been observed exploiting security flaws in JetBrains TeamCity software to conduct their extortion-only attacks. According to a new report from GuidePoint Security, which responded to a recent intrusion, the incident "began with the exploitation of a TeamCity server which resulted in the deployment of a PowerShell implementation of

QNAP Warns of Critical Auth Bypass Flaw in its NAS Devices

11 March 2024
Three vulnerabilities have been disclosed, including an authentication bypass, command injection, and SQL injection, with one allowing remote execution without authentication.

Defense Unicorns Raises $35 Million to Enhance National Security Through Open-Source Software

11 March 2024
The company has developed open source projects like Zarf, LeapfrogAI, Pepr, and Lula to overcome technical hurdles and offers core capabilities such as Your App Your Environment, Software Factory, and AI for National Security.

Critical Fortinet Flaw May Impact 150,000 Exposed Devices

11 March 2024
Approximately 150,000 Fortinet FortiOS and FortiProxy secure web gateway systems are vulnerable to CVE-2024-21762, a critical security issue that allows code execution without authentication.

Update: Change Healthcare Systems Expected to Come back Online in Mid-March

11 March 2024
UnitedHealth Group is providing additional financial relief to healthcare providers affected by the cyberattack, including advancing funds and expanding temporary financing programs.

Microsoft Says Russian Hackers Stole Source Code After Spying on Its Executives

11 March 2024
Microsoft is facing an ongoing attack from a Russia state-sponsored threat actor that stole data from senior-level executives and is attempting to gain unauthorized access to the company's systems.

Lithuania Warns China Has Ramped up Espionage Campaigns

11 March 2024
The opening of Taiwan's Representative Office in Lithuania has prompted China to increase its focus on gathering information about the country's internal affairs and political landscape.

UK: Jersey Regulator’s Data Breach Leaks Names and Addresses

11 March 2024
The leak did not connect individuals to registered entities or roles, and the organization is working with the Jersey Office of the Information Commissioner to investigate further.

Proof-of-Concept Exploit Released for Progress Software OpenEdge Vulnerability

11 March 2024
Technical specifics and a proof-of-concept (PoC) exploit have been made available for a recently disclosed critical security flaw in Progress Software OpenEdge Authentication Gateway and AdminServer, which could be potentially exploited to bypass authentication protections. Tracked as CVE-2024-1403, the vulnerability has a maximum severity rating of 10.0 on the CVSS scoring system. It

Magnet Goblin Hacker Group Leveraging 1-Day Exploits to Deploy Nerbian RAT

11 March 2024
A financially motivated threat actor called Magnet Goblin is swiftly adopting one-day security vulnerabilities into its arsenal in order to opportunistically breach edge devices and public-facing services and deploy malware on compromised hosts. “Threat actor group Magnet Goblin’s hallmark is its ability to swiftly leverage newly disclosed vulnerabilities, particularly targeting

Cybersecurity and the current skills gap

11 March 2024
Staffing shortages and limited skillsets negatively impact security.

Canva Warns of Three Security Vulnerabilities in Fonts

09 March 2024
The first, CVE-2023-45139, involved a high-severity bug in the FontTools library. The second and third vulnerabilities, CVE-2024-25081 and CVE-2024-25082, were related to naming conventions and compression.

Tycoon and Storm-1575 Linked to Phishing Attacks on US Schools

09 March 2024
The Tycoon and Storm-1575 threat groups use stealthy tactics, social engineering, and phishing techniques to bypass MFA protections and target Microsoft 365 credentials at large US school districts.

Flaws in Public Records Management Tool Could Let Hackers Nab Sensitive Data Linked to Requests

09 March 2024
The GovQA platform, used by state and local governments for public records requests, had vulnerabilities that could have allowed hackers to access sensitive personal information, edit requests, and download unsecured files.

New Malware Campaign Found Exploiting Stored XSS in Popup Builder

09 March 2024
A new malware campaign was found targeting the Popup Builder WordPress plugin, exploiting a vulnerability disclosed in November 2023. The campaign injects malicious code into websites, leading to over 3,300 infections.

CISA Adds Apple iOS and iPadOS Memory Corruption Bugs to its Known Exploited Vulnerabilities Catalog

09 March 2024
These memory corruption vulnerabilities, tracked as CVE-2024-23225 and CVE-2024-23296, were exploited in attacks against iPhone devices. Apple released emergency security updates to address these zero-day vulnerabilities.