Latest Cybersecurity News and Articles


Alert: GhostSec and Stormous Launch Joint Ransomware Attacks in Over 15 Countries

06 March 2024
The cybercrime group called GhostSec has been linked to a Golang variant of a ransomware family called GhostLocker. “TheGhostSec and Stormous ransomware groups are jointly conducting double extortion ransomware attacks on various business verticals in multiple countries,” Cisco Talos researcher Chetan Raghuprasad said in a report shared with The Hacker News. “GhostLocker and

New APT Group 'Lotus Bane' Behind Recent Attacks on Vietnam's Financial Entities

06 March 2024
A financial entity in Vietnam was the target of a previously undocumented threat actor called Lotus Bane that was first detected in March 2023. Singapore-headquartered Group-IB described the hacking outfit as an advanced persistent threat group that's believed to have been active since at least 2022. The exact specifics of the infection chain remain unknown as yet, but it involves the

Urgent: Apple Issues Critical Updates for Actively Exploited Zero-Day Flaws

06 March 2024
Apple has released security updates to address several security flaws, including two vulnerabilities that it said have been actively exploited in the wild. The shortcomings are listed below - CVE-2024-23225 - A memory corruption issue in Kernel that an attacker with arbitrary kernel read and write capability can exploit to bypass kernel memory protections CVE-2024-23296 - A memory

BlackCat Ransomware Group Implodes After Apparent $22M Payment by Change Healthcare

05 March 2024
There are indications that U.S. healthcare giant Change Healthcare has made a $22 million extortion payment to the infamous BlackCat ransomware group (a.k.a. "ALPHV") as the company struggles to bring services back online amid a cyberattack that has disrupted prescription drug services nationwide for weeks. However, the cybercriminal who claims to have given BlackCat access to Change's network says the crime gang cheated them out of their share of the ransom, and that they still have the sensitive data that Change reportedly paid the group to destroy. Meanwhile, the affiliate's disclosure appears to have prompted BlackCat to cease operations entirely. 

Mr. Green Gaming Suffers Data Breach, Exposing Personal Information of 27,000 Users

05 March 2024
The Mr. Green Gaming data breach compromised the sensitive information of approximately 27,000 users, highlighting the urgent need for enhanced cybersecurity measures in the gaming industry.

Cyberattack Forces Canada’s Financial Intelligence Agency to Take Systems Offline

05 March 2024
Canada’s financial intelligence agency FINTRAC has experienced a cybersecurity incident, prompting the agency to take its corporate systems offline as a precautionary measure.

New CHAVECLOAK Banking Trojan Targets Brazilians via Malicious PDFs

05 March 2024
The malware uses DLL sideloading techniques to discreetly execute malicious code, actively monitors victims' interactions with financial portals, and communicates with a C2 server to facilitate data theft and deceptive pop-up windows.

GhostLocker 2.0 Haunts Businesses Across Middle East, Africa, and Asia

05 March 2024
Cybercriminal groups GhostSec and Stormous have collaborated to unleash GhostLocker 2.0 ransomware in targeted attacks across the Middle East, Africa, and Asia, affecting organizations in various sectors.

DDoS attacks against customers in the Americas increases by 196%

05 March 2024
DDoS attacks increased globally in 2023, with the Americas being a common target. 

Hackers Exploit ConnectWise ScreenConnect Flaws to Deploy TODDLERSHARK Malware

05 March 2024
North Korean threat actors have exploited the recently disclosed security flaws in ConnectWise ScreenConnect to deploy a new malware called TODDLERSHARK. According to a report shared by Kroll with The Hacker News, TODDLERSHARK overlaps with known Kimsuky malware such as BabyShark and ReconShark. “The threat actor gained access to the victim workstation by exploiting the exposed setup wizard

Update: BlackCat Ransomware Turns off Servers Amid Claim They Stole $22 Million Ransom

05 March 2024
The shutdown may indicate an exit scam, with the affiliate claiming they still have critical data from Optum and other providers, while ALPHV/BlackCat has shut down its negotiation sites and messaging platform.

Hacktivist Collective NoName057(16) Strikes European Targets

05 March 2024
The cyber threat actor NoName057(16) is adapting its DDoS tactics with enhanced encryption and tailored software versions to target European entities, particularly those supporting Ukraine.

Security leaders weigh in on the recent UnitedHealth cyberattack

05 March 2024
UnitedHealth Group recently experienced a cyberattack caused by Blackcat, and experts are offering their insights on the ransomware group's behavior. 

Ukraine Claims it Hacked Russian Ministry of Defense Servers

05 March 2024
The Main Intelligence Directorate (GUR) of Ukraine's Ministry of Defense has announced that it successfully breached the servers of the Russian Ministry of Defense (Minoborony) and obtained sensitive documents.

South Korea Says Semiconductor Industry Targeted by Cyber-Spies From North Korea

05 March 2024
The National Intelligence Service (NIS) of South Korea reported that North Korean hackers targeted two South Korean microchip equipment companies, using "living-off-the-land" techniques to steal product designs and facility photos.

Self-Propagating Worm Created to Target Generative AI Systems

05 March 2024
Researchers from Israel Institute of Technology, Intuit and Cornell Tech have developed a computer worm called "Morris II" that targets generative AI (GenAI) applications to spread malware and steal personal data.

What is Exposure Management and How Does it Differ from ASM?

05 March 2024
Startups and scales-ups are often cloud-first organizations and rarely have sprawling legacy on-prem environments. Likewise, knowing the agility and flexibility that cloud environments provide, the mid-market is predominantly running in a hybrid state, partly in the cloud but with some on-prem assets. While there has been a bit of a backswing against the pricing and lock-in presented when using

Cybercriminals Using Novel DNS Hijacking Technique for Investment Scams

05 March 2024
A new DNS threat actor dubbed Savvy Seahorse is leveraging sophisticated techniques to entice targets into fake investment platforms and steal funds. “Savvy Seahorse is a DNS threat actor who convinces victims to create accounts on fake investment platforms, make deposits to a personal account, and then transfers those deposits to a bank in Russia,” Infoblox said in a report

Over 225,000 Compromised ChatGPT Credentials Up for Sale on Dark Web Markets

05 March 2024
More than 225,000 logs containing compromised OpenAI ChatGPT credentials were made available for sale on underground markets between January and October 2023, new findings from Group-IB show. These credentials were found within information stealer logs associated with LummaC2, Raccoon, and RedLine stealer malware. “The number of infected devices decreased slightly in mid- and late

Update: Optum Offering Financial Aid to Some Providers Hit by Outage

05 March 2024
UnitedHealth Group is offering short-term financial assistance to healthcare providers affected by the Change Healthcare IT outage, providing interest-free, fee-free funding.