Latest Cybersecurity News and Articles


Microsoft Confirms Russian Hackers Stole Source Code, Some Customer Secrets

08 March 2024
Microsoft on Friday revealed that the Kremlin-backed threat actor known as Midnight Blizzard (aka APT29 or Cozy Bear) managed to gain access to some of its source code repositories and internal systems following a hack that came to light in January 2024. "In recent weeks, we have seen evidence that Midnight Blizzard is using information initially exfiltrated from our

Law Enforcement Personnel Say LexisNexis Retaliated When Asked to Remove Data

08 March 2024
More than 18,000 New Jersey law enforcement personnel are alleging that LexisNexis retaliated against them by freezing their credit and falsely reporting them as identity theft victims after they requested their information to remain private.

Today’s Biggest AI Security Challenges

08 March 2024
Adversaries can exploit AI-powered applications to manipulate information, create harmful content, and develop deep fake media, posing significant risks to organizations.

Report: 78% of MSPs Identify Cybersecurity as Prime IT Challenge

08 March 2024
Investment in the right technology and IT partners has led to fewer SMBs experiencing cyberattacks, with 64% of MSPs reporting less than 10% of their SMB customers being hit, according to Kaseya.

Russian Influence Operations Against Baltic States and Poland Having ‘Significant Impact’ on Society

08 March 2024
These campaigns aim to downplay the impact of Western sanctions on Russia's economy, fuel confrontation among Western countries, and spread fear and panic among the targeted populations.

Google Releases Android March 2024 Patches, Including Fixes for Two Critical Issues

08 March 2024
Google has released the Android March 2024 security patches, addressing a total of 38 vulnerabilities, including two critical issues. These vulnerabilities could lead to remote code execution and elevation of privilege for attackers.

Meta Details WhatsApp and Messenger Interoperability to Comply with EU's DMA Regulations

08 March 2024
Meta has offered details on how it intends to implement interoperability in WhatsApp and Messenger with third-party messaging services as the Digital Markets Act (DMA) went into effect in the European Union. “This allows users of third-party providers who choose to enable interoperability (interop) to send and receive messages with opted-in users of either Messenger or WhatsApp – both designated

A Close Up Look at the Consumer Data Broker Radaris

08 March 2024
If you live in the United States, the data broker Radaris likely knows a great deal about you, and they are happy to sell what they know to anyone. But how much do we know about Radaris? Publicly available data indicates that in addition to running a dizzying array of people-search websites, the co-founders of Radaris operate multiple Russian-language dating services and affiliate programs. It also appears many of their businesses have ties to a California marketing firm that works with a Russian state-run media conglomerate currently sanctioned by the U.S. government.

CISA expresses concerns with VPNs, and security leaders respond

08 March 2024
A recent announcement from the CISA warns that malicious actors are exploiting vulnerabilities within VPN services. 

Tazama: Open-Source Real-Time Fraud Management

08 March 2024
Tazama is an open-source platform that offers scalable and cost-effective solutions for fraud management in digital payment systems, aiming to democratize access to advanced financial monitoring tools.

New Python-Based Snake Info-Stealer Spreads Through Facebook Messages

08 March 2024
The Snake malware campaign has been active since at least August 2023 and is attributed to Vietnamese-speaking individuals based on indicators such as targeted browsers and comments in the scripts.

National Intelligence Agency of Moldova Warns of Russia Attacks Ahead of the Presidential Election

08 March 2024
The Russian cyber operations are expected to manipulate public sentiment, interfere with the referendum to join the EU, and discredit pro-European candidates during the presidential elections.

CISA, NSA Share Best Practices for Securing Cloud Services

08 March 2024
The NSA and CISA have issued five joint bulletins outlining best practices for securing cloud environments, covering identity and access management, key management, encryption, data security, and mitigating risks from managed service providers.

China-Linked Evasive Panda APT Leverages Monlam Festival to Target Tibetans

08 March 2024
The attacks involved compromising websites, such as the Kagyu International Monlam Trust's website, to specifically target users in India, Taiwan, Hong Kong, Australia, and the U.S.

Cybersecurity Leader Claroty Secures $100M for Strategic Expansion and Innovation

08 March 2024
The company reported annual recurring revenue (ARR) surpassing $100 million and secured investments from major players such as Delta-v Capital, Standard Investments, and Rockwell Automation.

Ransomware Spikes Against Critical Infrastructure, Says FBI

08 March 2024
According to the latest Internet Crime Complaint Center (IC3) annual report, digital crimes reported to the FBI in 2023 resulted in potential monetary losses of over $12.5 billion, marking a 22 percent increase from the previous year.

Cisco Secure Client Carriage Return Line Feed Injection Vulnerability Patched

08 March 2024
The vulnerability impacts Secure Client for Windows, Linux, and macOS, and has been addressed in specific versions, with Amazon security researcher Paulos Yibelo Mesfin credited with discovering and reporting the flaw.

Secrets Sensei: Conquering Secrets Management Challenges

08 March 2024
In the realm of cybersecurity, the stakes are sky-high, and at its core lies secrets management — the foundational pillar upon which your security infrastructure rests. We're all familiar with the routine: safeguarding those API keys, connection strings, and certificates is non-negotiable. However, let's dispense with the pleasantries; this isn't a simple 'set it and forget it' scenario. It's

Ex-Google Engineer Charged with Stealing AI Secrets

08 March 2024
Former Google engineer Linwei Ding has been charged with stealing trade secrets related to artificial intelligence (AI) and supercomputing data centres while secretly working for Chinese companies.

MitM Phishing Attack can Let Attackers Unlock and Steal a Tesla

08 March 2024
The attack exploited the lack of proper authentication security when linking a new phone key to a Tesla, allowing an attacker to add a new "Phone Key" and gain unauthorized access to the vehicle.