Latest Cybersecurity News and Articles


Update: Optum Offering Financial Aid to Some Providers Hit by Outage

05 March 2024
UnitedHealth Group is offering short-term financial assistance to healthcare providers affected by the Change Healthcare IT outage, providing interest-free, fee-free funding.

Warning: Thread Hijacking Attack Targets IT Networks, Stealing NTLM Hashes

05 March 2024
The threat actor known as TA577 has been observed using ZIP archive attachments in phishing emails with an aim to steal NT LAN Manager (NTLM) hashes. The new attack chain “can be used for sensitive information gathering purposes and to enable follow-on activity,” enterprise security firm Proofpoint said in a Monday report. At least two campaigns taking advantage of this

ScreenConnect Flaws Exploited to Drop New ToddleShark Malware

05 March 2024
The North Korean hacking group Kimsuky is using newly disclosed ScreenConnect vulnerabilities to deploy a polymorphic malware variant called ToddleShark for espionage and data theft.

Securing Software Repositories Leads to Better OSS Security

05 March 2024
The OpenSSF has implemented various initiatives to improve open-source software security, including the creation of a Malicious Packages repository and partnering with CISA to develop a security maturity framework for package repositories.

Iowa Electric, Water Utility Says Information of Nearly 37,000 Leaked in January Ransomware Attack

05 March 2024
A utility company in eastern Iowa, Muscatine Power and Water, was hit by a ransomware attack in January, leading to the exposure of sensitive information of nearly 37,000 residents.

GitHub Push Protection Now on by Default for Public Repositories

05 March 2024
GitHub has implemented push protection as a default security feature for all public repositories to prevent accidental leaks of sensitive information such as API keys and tokens.

TA577 Exploits NTLM Authentication Vulnerability

05 March 2024
The group targeted hundreds of organizations globally with emails containing zipped HTML attachments designed to capture NTLM hashes. This method could enable password cracking or "Pass-The-Hash" attacks.

Exploit Available for New Critical JetBrains TeamCity Authentication Bypass Bug, Patch Now

05 March 2024
The JetBrains TeamCity On-Premises CI/CD solution has been found to have two critical vulnerabilities (CVE-2024-27198 and CVE-2024-27199) that can allow remote attackers to take control of the server and modify system settings without authentication.

Report: 95% Believe LLMs Making Phishing Detection More Challenging

05 March 2024
More than 95% of responding IT and security professionals believe social engineering attacks have become more sophisticated in the last year, according to a survey by LastPass.

How the Application ‘XHelper’ Is Powering the Indian Money-Laundering Gig Economy

05 March 2024
Cybercriminals in India are using the XHelper app to recruit money mules in order to launder illicitly obtained funds through fake payment gateways and cryptocurrency conversions.

Critical JetBrains TeamCity On-Premises Flaws Could Lead to Server Takeovers

04 March 2024
A new pair of security vulnerabilities have been disclosed in JetBrains TeamCity On-Premises software that could be exploited by a threat actor to take control of affected systems. The flaws, tracked as CVE-2024-27198 (CVSS score: 9.8) and CVE-2024-27199 (CVSS score: 7.3), have been addressed in version 2023.11.4. They impact all TeamCity On-Premises versions through 2023.11.3. “The

Silence Laboratories, a Cryptographic Security Startup, Secures Funding

04 March 2024
The funding, co-led by Pi Ventures and Kira Studio, brings the total raised to $6 million. The company plans to use the funding to expand its teams and research and development efforts.

American Express Credit Cards Exposed in Vendor Data Breach

04 March 2024
American Express has issued a data breach notification after one of its service providers experienced unauthorized access to its systems. This has led to the exposure of American Express Card account numbers, names, and card expiration dates.

Evolving cloud threats were observed in the last half of 2023

04 March 2024
A recent report indicates that malicious actors broadened their techniques and may present more threats to security leaders. 

Update: Ivanti Disputes CISA Findings of Post-Factory Reset Hacking

04 March 2024
Ivanti disputes the U.S. cybersecurity agency's claim that hackers can establish persistence on rooted appliances through a factory reset, stating that it won't succeed in a live customer environment.

86% of CIOS have implemented formal AI policies

04 March 2024
According to a report, 85% of organizations are investing in AI technologies with transformative potential in 2024, despite economic uncertainty.

CyberFirst Girls scoop prizes following success in national cyber security competition

04 March 2024
Winning teams from across the UK have been recognised for their success in the CyberFirst Girls Competition at an awards ceremony hosted at the University of Oxford’s Robotics Institute

CyberFirst Girls scoop prizes following success in national cyber security competition

04 March 2024
Winning teams from across the UK have been recognised for their success in the CyberFirst Girls Competition at an awards ceremony hosted at the University of Oxford’s Robotics Institute

How Cybercriminals are Exploiting India's UPI for Money Laundering Operations

04 March 2024
Cybercriminals are using a network of hired money mules in India using an Android-based application to orchestrate a massive money laundering scheme. The malicious application, called XHelper, is a "key tool for onboarding and managing these money mules," CloudSEK researchers Sparsh Kulshrestha, Abhishek Mathew, and Santripti Bhujel said in a report. Details about the scam 

Update: ALPHV Website Goes Down Amid Growing Fallout From Change Healthcare Attack

04 March 2024
The website used by the ransomware group responsible for breaching a major US healthcare payment processor went down, causing financial pressure on medical providers and difficulty for consumers to access medicine.