Latest Cybersecurity News and Articles


AnyCubic Fixes Exploited 3D Printer Zero Day Flaw With New Firmware

08 March 2024
AnyCubic released new firmware for its Kobra 3D printers to fix a zero-day vulnerability that allowed hackers to send security warnings to the printers. This vulnerability was due to insecure permissions in the company's MQTT server.

Cisco Issues Patch for High-Severity VPN Hijacking Bug in Secure Client

08 March 2024
Cisco has released patches to address a high-severity security flaw impacting its Secure Client software that could be exploited by a threat actor to open a VPN session with that of a targeted user. The networking equipment company described the vulnerability, tracked as CVE-2024-20337 (CVSS score: 8.2), as allowing an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF

QEMU Emulator Exploited as Tunneling Tool to Breach Company Network

08 March 2024
Threat actors have been observed leveraging the QEMU open-source hardware emulator as tunneling software during a cyber attack targeting an unnamed "large company" to connect to their infrastructure. While a number of legitimate tunneling tools like Chisel, FRP, ligolo, ngrok, and Plink have been used by adversaries to their advantage, the development marks the first QEMU that has been

CISA Warns of Actively Exploited JetBrains TeamCity Vulnerability

08 March 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting JetBrains TeamCity On-Premises software to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability, tracked as CVE-2024-27198 (CVSS score: 9.8), refers to an authentication bypass bug that allows for a complete

Minnesota's South St. Paul Public Schools Investigating Potential Cybersecurity Threat

07 March 2024
This incident is impacting online platforms, emails, and other digital services. The school district is working to restore its systems and maintain a secure online environment for students and staff.

Canadian City Says Timeline for Recovery From Ransomware Attack ‘Unknown’

07 March 2024
The city of Hamilton, Canada, is recovering from a ransomware attack that has disrupted online government services, forcing residents to use cash transactions and manual methods for payments.

Ransomware Attackers Leak Sensitive Swiss Government Documents, Login

07 March 2024
The leaked data included 65,000 documents, with 5% related to the federal government. Most of the leaked federal government files contained personal data, technical information, classified data, and passwords.

Update: Critical TeamCity Flaw Now Widely Exploited to Create Admin Accounts

07 March 2024
Hackers are exploiting a critical authentication bypass vulnerability (CVE-2024-27198) in TeamCity On-Premises, leading to the creation of hundreds of unauthorized users on unpatched instances.

New research uncovers an emerging malware campaign

07 March 2024
Research done by Cado Security has revealed a new malware campaign as well as its most common targets. 

Duvel Says It Has “More Than Enough” Beer After Ransomware Attack

07 March 2024
The Duvel Moortgat Brewery in Belgium was hit by a ransomware attack, causing the halt of beer production in their bottling facilities. The company's IT systems detected the attack, leading to an immediate stop in production.

AI Tools Put Companies at Risk of Data Exfiltration

07 March 2024
The rise of GenAI, along with cloud applications, has made it challenging to monitor and protect critical data. As a result, organizations are concerned about the impact of AI on sensitive data and struggle to comply with data protection laws.

American Express announces data breach

07 March 2024
American Express announced that card members' account and financial data may have been affected by a data breach involving third party partners.

Recognising UK-based security researchers who have disclosed vulnerabilities to UK government

07 March 2024
The NCSC recently hosted a small number of those who have helped make UK government services more secure and resilient.

Recognising UK-based security researchers who have disclosed vulnerabilities to UK government

07 March 2024
The NCSC recently hosted a small number of those who have helped make UK government services more secure and resilient.

Feds Get Second Guilty Plea in Prosecution of Nigerian-Led BEC Case

07 March 2024
Nigerian national Henry Onyedikachi Echefu pleaded guilty to wire fraud and money laundering in connection with a $6 million business email compromise scheme dating back to 2017.

ITRC Finds Online Job Scams on the Rise

07 March 2024
The surge in online job scams, targeting job seekers for personal information, has seen a significant increase in reported incidents, with a 545% spike in January 2024 compared to December 2023, according to the Identity Theft Resource Center (ITRC).

RiskInDroid Performs Open-Source Risk Analysis of Android Apps

07 March 2024
RiskInDroid is an open-source tool for analyzing the risk level of Android applications using machine learning. Unlike other tools, RiskInDroid conducts reverse engineering on apps to extract permissions and assess their usage in the bytecode.

EU Agrees 'Cyber Solidarity Act' to Bolster Incident Response and Recovery

07 March 2024
The regulations will establish an EU-wide cybersecurity alert system and a cybersecurity emergency mechanism to support preparedness, financial assistance, and a cybersecurity reserve for large-scale incidents.

Hacked WordPress Sites Abusing Visitors' Browsers for Distributed Brute-Force Attacks

07 March 2024
Threat actors are conducting brute-force attacks against WordPress sites by leveraging malicious JavaScript injections, new findings from Sucuri reveal. The attacks, which take the form of distributed brute-force attacks, “target WordPress websites from the browsers of completely innocent and unsuspecting site visitors,” security researcher Denis Sinegubko said. The activity is part of a&

Chinese State Hackers Target Tibetans with Supply Chain, Watering Hole Attacks

07 March 2024
The China-linked threat actor known as Evasive Panda orchestrated both watering hole and supply chain attacks targeting Tibetan users at least since September 2023. The end of the attacks is to deliver malicious downloaders for Windows and macOS that deploy a known backdoor called MgBot and a previously undocumented Windows implant known as Nightdoor. The findings come from ESET, which