Latest Cybersecurity News and Articles


Report provides key insights into the energy and utilities sector

04 March 2024
A survey of more than 1,000 security professionals worldwide has been conducted to gain valuable insights into the energy and utilities sector. 

NTT Boss Takes Early Retirement to Atone for Data Leak

04 March 2024
NTT West president resigned to take responsibility for the leak of 9.28 million customers' data, reflecting the significance of social responsibility in Japanese corporate culture.

From 500 to 5000 Employees - Securing 3rd Party App-Usage in Mid-Market Companies

04 March 2024
A company’s lifecycle stage, size, and state have a significant impact on its security needs, policies, and priorities. This is particularly true for modern mid-market companies that are either experiencing or have experienced rapid growth. As requirements and tasks continue to accumulate and malicious actors remain active around the clock, budgets are often stagnant at best. Yet, it is crucial

Multistage RA World Ransomware Uses Anti-AV Tactics, Exploits GPO

04 March 2024
The RA World ransomware employs multi-stage components to target healthcare organizations in the Latin American region, signifying a strategic and targeted approach to compromising systems within the target network.

Cybercriminals Harness AI for New Era of Malware Development

04 March 2024
The Group-IB Hi-Tech Crime Trends 2023/2024 report highlights the increasing alliance between ransomware groups and initial access brokers, leading to a 74% rise in companies having their data uploaded on leak sites.

U.S. Judge Ordered NSO Group to Hand Over the Pegasus Spyware Code to WhatsApp

04 March 2024
This decision came after Meta won a legal battle against NSO Group. The lawsuit originated from allegations that NSO Group had conducted malicious attacks against WhatsApp users.

U.S. Authorities Charged an Iranian National for Long-Running Hacking Campaign

04 March 2024
Iranian national Alireza Shafie Nasab has been charged by the U.S. DoJ for orchestrating a multi-year hacking campaign targeting U.S. government and defense entities, using techniques like spear phishing and social engineering.

Malicious Meeting Invite Fix Targets Mac Users

04 March 2024
Scammers impersonating cryptocurrency investors on Telegram are luring targets into fake partnership meetings, using AppleScripts to compromise Mac users and gain administrator permissions.

New Wave of SocGholish Infections Impersonates WordPress Plugins

04 March 2024
The malware has evolved to infect websites through modified versions of legitimate WordPress plugins, emphasizing the need for vigilance in managing plugin installations.

Over 100 Malicious AI/ML Models Found on Hugging Face Platform

04 March 2024
As many as 100 malicious artificial intelligence (AI)/machine learning (ML) models have been discovered in the Hugging Face platform. These include instances where loading a pickle file leads to code execution, software supply chain security firm JFrog said. "The model's payload grants the attacker a shell on the compromised machine, enabling them to gain full control over victims'

Researchers Spot New Infrastructure Likely Used for Predator Spyware

04 March 2024
Insikt Group researchers uncovered new infrastructure used by the operators of the Predator spyware in 11 countries, including Angola, Egypt, Saudi Arabia, and the Philippines.

Report: Info-Stealers Target Stored Browser Credentials

04 March 2024
Hackers are increasingly targeting saved passwords in browsers and using various malware and info stealers to steal credentials, leading to a growing number of stolen logs and compromised accounts.

US Coast Guard Expands Cyber Command to Combat New Threats

04 March 2024
The U.S. Coast Guard is expanding its cybersecurity capabilities and building out cybersecurity protection teams to assess, identify, and respond to cyber risks and threats in the maritime transportation system.

Eken Camera Doorbells Allow Ill-Intentioned Individuals to Spy on You

04 March 2024
Camera doorbells manufactured by Eken Group Ltd under the brands EKEN and Tuck have major vulnerabilities that could allow threat actors to view footage from the devices or control them completely.

Phobos Ransomware Aggressively Targeting U.S. Critical Infrastructure

04 March 2024
U.S. cybersecurity and intelligence agencies have warned of Phobos ransomware attacks targeting government and critical infrastructure entities, outlining the various tactics and techniques the threat actors have adopted to deploy the file-encrypting malware. “Structured as a ransomware as a service (RaaS) model, Phobos ransomware actors have targeted entities including municipal and

Taiwan's Biggest Telco Breached by Suspected Chinese Hackers

02 March 2024
Hackers stole sensitive information, including military and government documents, from Chunghwa Telecom and sold it on the dark web. The leaked data included documents from the armed forces, foreign affairs ministry, coast guard, and other units.

Police Seized Crimemarket, the Largest German-Speaking Cybercrime Marketplace

02 March 2024
The platform had over 180,000 registered users and was accessible through both the "Darknet" and the "Clearnet." The investigation is ongoing, with plans to identify and target the platform's users.

CISA adds Microsoft Streaming Service bug to its Known Exploited Vulnerabilities catalog

02 March 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the CVE-2023-29360 Microsoft Streaming Service vulnerability to its Known Exploited Vulnerabilities catalog, which allows attackers to gain SYSTEM privileges.

U.S. Court Orders NSO Group to Hand Over Pegasus Spyware Code to WhatsApp

02 March 2024
A U.S. judge has ordered NSO Group to hand over its source code for Pegasus and other products to Meta as part of the social media giant's ongoing litigation against the Israeli spyware vendor. The decision, which marks a major legal victory for Meta, which filed the lawsuit in October 2019 for using its infrastructure to distribute the spyware to approximately

UK Unveils Draft Cybersecurity Governance Code

02 March 2024
The UK Department for Science, Innovation and Technology (DSIT) has revealed what its future Cybersecurity Governance Code of Practice will look like and the five principals it will include.