Latest Cybersecurity News and Articles


CryptoChameleon: New Phishing Tactics Exhibited in FCC-Targeted Attack

02 March 2024
A sophisticated phishing kit with novel tactics targets cryptocurrency platforms and the FCC through a combination of email, SMS, and voice phishing, successfully stealing high-quality data from mobile device users in the United States.

U.S. Charges Iranian Hacker, Offers $10 Million Reward for Capture

01 March 2024
The U.S. Department of Justice (DoJ) on Friday unsealed an indictment against an Iranian national for his alleged involvement in a multi-year cyber-enabled campaign designed to compromise U.S. governmental and private entities. More than a dozen entities are said to have been targeted, including the U.S. Departments of the Treasury and State, defense contractors that support U.S. Department of

Golden Corral Restaurant Chain Suffers Data Breach Impacting 183,000 People

01 March 2024
The stolen data may include a wide range of personal information such as Social Security numbers, financial account details, medical information, and usernames and passwords.

FBI, CISA Release IoCs for Phobos Ransomware

01 March 2024
The Phobos ransomware strain, distributed through ransomware-as-a-service, has targeted a wide range of organizations, including governments, healthcare, education, and critical infrastructure sectors.

New Bifrost Variant Uses Domain Deception Tactic to Deceive Users

01 March 2024
The latest variant of BIFROSE masquerades as VMware by reaching out to a deceptive domain. There has been a spike in BIFROSE activity since October 2023, and a new Arm version of the malware has been discovered.

Researchers Found a Zero-Click Facebook Account Takeover

01 March 2024
The critical vulnerability in Facebook's password reset process involved a rate-limiting issue in a specific endpoint, which could be exploited to brute-force a nonce and gain access to a user's account.

Security leaders discuss ONCD's call for memory-safe software

01 March 2024
Security leaders weigh in on the recent announcement by the ONCD, which encourages technological manufactures to develop software with memory safety in mind.

Leaky Database Spilled 2FA Codes for Global Tech Giants

01 March 2024
An exposed database belonging to YX International leaked sensitive data including one-time security codes for major tech and online companies like Facebook, Google, and TikTok.

Law Firm Reports Data Breach Affecting More Than 325,000 People

01 March 2024
The breached data included names, Social Security numbers, financial account information, and medical information. An unauthorized third party accessed the firm's network, leading to a data breach.

Update: Irish Foreign Affairs Ministry Says ‘No Evidence’ of Cyber Breach Following Extortion Claim

01 March 2024
The Department of Foreign Affairs in Ireland has found no evidence to support the claim of a cyber extortion group called Mogilevich that it stole data from their IT systems.

New Phishing Kit Leverages SMS, Voice Calls to Target Cryptocurrency Users

01 March 2024
A novel phishing kit has been observed impersonating the login pages of well-known cryptocurrency services as part of an attack cluster designed to primarily target mobile devices. “This kit enables attackers to build carbon copies of single sign-on (SSO) pages, then use a combination of email, SMS, and voice phishing to trick the target into sharing usernames, passwords, password reset URLs,

Abyss Locker Ransomware Attacks Both Windows And Linux Users

01 March 2024
This ransomware steals and encrypts files, demanding ransom for decryption and not releasing stolen data. It is based on the HelloKitty ransomware source code and has been observed in various regions.

Research finds that cybersecurity leaders are taking on multiple roles

01 March 2024
A new study shows trends in cybersecurity leader employment, compensation and retention.

Chinese PC-Maker Acemagic Shipped Machines Infected with Malware

01 March 2024
The company attributed the infection to software adjustments made by developers to reduce boot times, which inadvertently affected network settings and omitted digital signatures.

New Silver SAML Attack Bypasses Golden SAML MItigations

01 March 2024
The technique works with identity providers like Microsoft Entra ID and can enable attackers to access applications by forging SAML responses with compromised private keys.

Utility Regulators Take Steps to Raise Sector’s Cybersecurity ‘Baselines’

01 March 2024
The cybersecurity baselines aim to improve the security of distribution systems and distributed energy resources by including cybersecurity requirements in utilities’ procurement processes.

4 Instructive Postmortems on Data Downtime and Loss

01 March 2024
More than a decade ago, the concept of the ‘blameless’ postmortem changed how tech companies recognize failures at scale. John Allspaw, who coined the term during his tenure at Etsy, argued postmortems were all about controlling our natural reaction to an incident, which is to point fingers: “One option is to assume the single cause is incompetence and scream at engineers to make them

20 Million Cutout.Pro User Records Leaked on Data Breach Forum

01 March 2024
Users of Cutout.Pro are advised to reset their passwords immediately and be cautious of targeted phishing scams due to the potential threat of threat actors brute-forcing the leaked password hashes.

New BIFROSE Linux Malware Variant Using Deceptive VMware Domain for Evasion

01 March 2024
Cybersecurity researchers have discovered a new Linux variant of a remote access trojan (RAT) called BIFROSE (aka Bifrost) that uses a deceptive domain mimicking VMware. "This latest version of Bifrost aims to bypass security measures and compromise targeted systems," Palo Alto Networks Unit 42 researchers Anmol Maurya and Siddharth Sharma said. BIFROSE is one of the long-standing

Epic Games Says “Zero Evidence” of Hacking by Mogilevich Gang

01 March 2024
Epic Games found no evidence of a cyberattack or data theft after the Mogilevich group claimed to have breached their servers. The group offered to sell stolen data for $15,000 but only shared samples with those who proved they had the funds.