Latest Cybersecurity News and Articles


Hackers Exploit Misconfigured YARN, Docker, Confluence, Redis Servers for Crypto Mining

06 March 2024
Threat actors are targeting misconfigured and vulnerable servers running Apache Hadoop YARN, Docker, Atlassian Confluence, and Redis services as part of an emerging malware campaign designed to deliver a cryptocurrency miner and spawn a reverse shell for persistent remote access. “The attackers leverage these tools to issue exploit code, taking advantage of common misconfigurations and

69% of financial services consumers prioritize fraud protection

06 March 2024
According to a report, 69% of consumers rank good fraud protection in their top three considerations when choosing a financial service provider.

Exit Scam: BlackCat Ransomware Group Vanishes After $22 Million Payout

06 March 2024
The threat actors behind the BlackCat ransomware have shut down their darknet website and likely pulled an exit scam after uploading a bogus law enforcement seizure banner. "ALPHV/BlackCat did not get seized. They are exit scamming their affiliates," security researcher Fabian Wosar said. "It is blatantly obvious when you check the source code of the new takedown notice." "There

Organizations are Knowingly Releasing Vulnerable Applications

06 March 2024
Application security responsibilities have shifted to involve both AppSec managers and developers, with a high percentage of companies knowingly releasing vulnerable applications due to time and business pressures.

Boston Red Sox partner with Centripetal for cyber network security

06 March 2024
A partnership between the Boston Red Sox and Centripetal seeks to bolster the stadium's cyber network security.  

CrowdStrike to Buy Israeli Data Defense Vendor Flow Security

06 March 2024
CrowdStrike has announced plans to acquire Tel Aviv-based Flow Security, a data security posture management startup, for an undisclosed amount with the deal expected to close by the end of April.

Hornetsecurity Buys Vade to Fuel Strength in France, Germany

06 March 2024
The joint company plans to integrate their products and teams by the end of 2024, enabling MSPs to manage security, compliance, and data loss prevention for Microsoft 365 from a single control portal.

Researchers Warn of Stuxnet-Style Web-Based PLC Malware

06 March 2024
Researchers from the Georgia Institute of Technology have developed web-based malware called IronSpider, targeting modern programmable logic controllers (PLCs) used in industrial control systems.

A New Way To Manage Your Web Exposure: The Reflectiz Product Explained

06 March 2024
An in-depth look into a proactive website security solution that continuously detects, prioritizes, and validates web threats, helping to mitigate security, privacy, and compliance risks.  [Reflectiz shields websites from client-side attacks, supply chain risks, data breaches, privacy violations, and compliance issues] You Can’t Protect What You Can’t See Today’s websites are connected

DTEX Systems Raises $50M in Series E Funding

06 March 2024
The funding round was led by CapitalG, with James Luo joining the DTEX board of directors. The company plans to utilize the funding to expand its U.S. engineering team and grow its global go-to-market operations.

Fidelity Customers' Financial Information Feared Stolen in Cyberattack

06 March 2024
Nearly 30,000 Fidelity Investments Life Insurance customers' personal and financial information, including bank account and routing numbers, may have been stolen after criminals breached Infosys' IT systems.

Apple Emergency Security Updates Fix Two New iOS Zero-Days

06 March 2024
The vulnerabilities, tracked as CVE-2024-23225 and CVE-2024-23296, are related to kernel and RTKit memory corruptions. The affected devices include iPhone XS and later, iPad Pro, iPad Air, and iPad mini models.

Axonius, a Specialist in Cyber Asset Management, secures $200M at a $2.6B Valuation

06 March 2024
Axonius, a leader in enterprise asset management, has secured an additional $200 million in funding to support its business expansion. The investment is an extension of its existing Series E round, maintaining a valuation of $2.6 billion.

New WogRAT Malware Abuses Online Notepad Service to Store Malicious Code

06 March 2024
The 'WogRAT' malware targets both Windows and Linux systems and uses the online notepad platform 'aNotepad' to store and retrieve malicious code, making its infection chain stealthy.

How to Find and Fix Risky Sharing in Google Drive

06 March 2024
Every Google Workspace administrator knows how quickly Google Drive becomes a messy sprawl of loosely shared confidential information. This isn't anyone's fault; it’s inevitable as your productivity suite is purposefully designed to enable real-time collaboration – both internally and externally.  For Security & Risk Management teams, the untenable risk of any Google Drive footprint

Android and Windows RATs Distributed Via Online Meeting Lures

06 March 2024
The attackers used fake Russian-language online meeting sites hosted on a single IP address to distribute malicious APK and BAT files targeting Windows and Android users.

Urgent VMware Updates Address Critical ESXi Sandbox Escape Bugs

06 March 2024
The addressed vulnerabilities include use-after-free flaws in XHCI and UHCI USB controllers, an out-of-bounds write vulnerability, and an information disclosure vulnerability.

Ubuntu 18.04 Security Updates for Linux Kernel Vulnerabilities

06 March 2024
Ubuntu has rolled out security updates addressing several Linux kernel vulnerabilities in Ubuntu 18.04, including CVE-2024-0646, CVE-2024-0565, CVE-2023-51782, CVE-2023-51781, CVE-2023-51780, and CVE-2023-7192.

U.S. Cracks Down on Predatory Spyware Firm for Targeting Officials and Journalists

06 March 2024
The U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC) sanctioned two individuals and five entities associated with the Intellexa Alliance for their role in “developing, operating, and distributing” commercial spyware designed to target government officials, journalists, and policy experts in the country. “The proliferation of commercial spyware poses distinct and growing

VMware Issues Security Patches for ESXi, Workstation, and Fusion Flaws

06 March 2024
VMware has released patches to address four security flaws impacting ESXi, Workstation, and Fusion, including two critical flaws that could lead to code execution. Tracked as CVE-2024-22252 and CVE-2024-22253, the vulnerabilities have been described as use-after-free bugs in the XHCI USB controller. They carry a CVSS score of 9.3 for Workstation and Fusion, and 8.4 for ESXi systems. "A