Latest Cybersecurity News and Articles


Investigators Trace $100 Million in Crypto Payments to Myanmar Scam Syndicate

27 February 2024
Two cryptocurrency addresses linked to a company operating in a notorious scam compound in Myanmar have received nearly $100 million worth of deposits in less than two years.

Hackers Exploit 14-Year-Old CMS Editor on Government and Educational Sites for SEO Poisoning

27 February 2024
The deprecated FCKeditor plugin is being abused to create open redirects on university, government, and corporate websites, allowing threat actors to poison search engine results with malicious content.

Web Check Provides Open-Source Intelligence for Any Website

27 February 2024
The tool offers a wide range of features including IP info, SSL chain, DNS records, cookies, headers, server location, open ports, and more, making it a valuable resource for both OSINT investigations and general curiosity.

Over 13,000 Hijacked Major-Brand Subdomains Found Bombarding Users With Millions of Malicious Emails

27 February 2024
The threat actors hijack abandoned subdomains and domains of well-known companies, allowing the emails to bypass spam filters and appear legitimate. Brands like MSN, VMware, and eBay have been unwittingly involved.

From Alert to Action: How to Speed Up Your SOC Investigations

27 February 2024
Processing alerts quickly and efficiently is the cornerstone of a Security Operations Center (SOC) professional's role. Threat intelligence platforms can significantly enhance their ability to do so. Let's find out what these platforms are and how they can empower analysts. The Challenge: Alert Overload The modern SOC faces a relentless barrage of security alerts generated by SIEMs and EDRs.

How the FBI and CISA Look to Mature the Government’s Top Ransomware Task Force

27 February 2024
The Joint Ransomware Task Force aims to enhance collaboration to identify ransomware groups and drive a comprehensive government and societal response to protect critical infrastructure and businesses.

Five Eyes Agencies Expose APT29's Evolving Cloud Attack Tactics

27 February 2024
Cybersecurity and intelligence agencies from the Five Eyes nations have released a joint advisory detailing the evolving tactics of the Russian state-sponsored threat actor known as APT29. The hacking outfit, also known as BlueBravo, Cloaked Ursa, Cozy Bear, Midnight Blizzard (formerly Nobelium), and The Dukes, is assessed to be affiliated with the Foreign Intelligence Service (SVR) of the

China Warns of Fake Digital Yuan Wallets

27 February 2024
Fake wallet apps for China's digital currency are circulating, leading to warnings from the Ministry of Industry and Information Technology about potential scams and data theft.

New Hugging Face Vulnerability Exposes AI Models to Supply Chain Attacks

27 February 2024
Cybersecurity researchers have found that it's possible to compromise the Hugging Face Safetensors conversion service to ultimately hijack the models submitted by users and result in supply chain attacks. "It's possible to send malicious pull requests with attacker-controlled data from the Hugging Face service to any repository on the platform, as well as hijack any models that are submitted

White House Urges Tech Industry to Switch to Memory-Safe Programming Languages

27 February 2024
A new report by the Office of the National Cyber Director (ONCD) highlighted that up to 70% of security vulnerabilities are due to memory safety issues in certain programming languages.

It’s Time for Security Operations to Ditch Excel

27 February 2024
Security teams often rely on manual Excel work to manage their cybersecurity operations, despite the limitations and inefficiencies of using spreadsheets for such critical tasks.

WordPress Plugin Alert - Critical SQLi Vulnerability Threatens 200K+ Websites

27 February 2024
A critical security flaw (CVE-2024-1071) in the Ultimate Member WordPress plugin allowed unauthenticated attackers to perform SQL injection and extract sensitive data, affecting users who enabled the "Enable custom table for usermeta" option.

Report: CVE Count Set to Rise by 25% in 2024

27 February 2024
A report from Coalition predicts a 25% increase in common vulnerabilities and exposures (CVEs) in 2024, reaching 34,888 vulnerabilities. This sharp rise in CVEs raises concerns about software vulnerability and the potential for ransomware attacks.

New IDAT Loader Version Uses Steganography to Push Remcos RAT

27 February 2024
The attackers employed sophisticated techniques such as code injection, execution modules, and dynamic loading of Windows API functions to evade detection by automated security products.

MGM Resorts’ Cyberattack Headache Continues as Regulators Launch Investigations

27 February 2024
MGM Resorts is facing regulatory investigations and potential fines following a cyberattack that disrupted its operations, with the possibility of incurring losses from legal proceedings.

UK: NCSC to Offer Cyber Governance Guidance to Boards

27 February 2024
Boards have a legal responsibility to understand and manage cyber-governance within their organizations and should seek practical guidance to enhance their cybersecurity understanding.

PayPal Files Patent for New Method to Detect Stolen Cookies

27 February 2024
PayPal has filed a patent application for a method to detect when "super-cookies" are stolen, aiming to improve cookie-based authentication and prevent account takeover attacks.

Earth Lusca Uses Geopolitical Lure to Target Taiwan Before Elections

27 February 2024
The attack involved a multi-stage infection chain, including spear phishing, obfuscated JavaScript files, and DLL hijacking, ultimately leading to the deployment of a Cobalt Strike payload.

WordPress Plugin Alert - Critical SQLi Vulnerability Threatens 200K+ Websites

27 February 2024
A critical security flaw has been disclosed in a popular WordPress plugin called Ultimate Member that has more than 200,000 active installations. The vulnerability, tracked as CVE-2024-1071, carries a CVSS score of 9.8 out of a maximum of 10. Security researcher Christiaan Swiers has been credited with discovering and reporting the flaw. In an advisory published last week, WordPress

48% of executives focus AI strategy on SaaS applications

26 February 2024
According to the report, more than 90% of enterprises are currently experiencing limitations integrating AI into their technology stack.