Latest Cybersecurity News and Articles
26 February 2024
Last year, the Open Worldwide Application Security Project (OWASP) published multiple versions of the "OWASP Top 10 For Large Language Models," reaching a 1.0 document in August and a 1.1 document in October. These documents not only demonstrate the rapidly evolving nature of Large Language Models, but the evolving ways in which they can be attacked and defended. We're going to talk in this
26 February 2024
The U.S. Department of Health and Human Services (HHS) reached a settlement with Green Ridge Behavioral Health after a ransomware attack exposed the health information of over 14,000 individuals.
26 February 2024
Cybersecurity researchers are warning about a spike in email phishing campaigns that are weaponizing the Google Cloud Run service to deliver various banking trojans such as Astaroth (aka Guildma), Mekotio, and Ousaban (aka Javali) to targets across Latin America (LATAM) and Europe.
"The infection chains associated with these malware families feature the use of malicious
26 February 2024
The campaign involves a substantial network of social media accounts, sophisticated infrastructure, and tactics to evade detection, posing a challenge to combat such influence operations.
26 February 2024
According to Citrix, 42% of organizations surveyed in the US are considering or already have moved at least half of their cloud-based workloads back to on-premises infrastructures, a phenomenon known as cloud repatriation.
26 February 2024
New advisory reveals evolving tactics used by Russian state-linked cyber actors as more organisations move to cloud-based infrastructure.
26 February 2024
New advisory reveals evolving tactics used by Russian state-linked cyber actors as more organisations move to cloud-based infrastructure.
26 February 2024
The Malawi government has suspended passport issuance for two weeks due to a ransomware attack on the immigration service's network. President Lazarus Chakwera stated that the hackers are demanding a ransom, but the government refuses to pay.
26 February 2024
The protocol combines Kyber and ECC, aims to mitigate the impact of key compromises, and will be integrated into Apple's iOS, iPadOS, macOS, and watchOS in the next update.
26 February 2024
The attacker stripped the package of its original content, leaving only an __init__.py and example.py file, and introduced an executable named "Updater_1.4.4_x64.exe" to launch the Nova Sentinel malware.
26 February 2024
Cloud security and incident response are top priorities, attracting 47% of additional cybersecurity spending, followed by areas such as MSSP outsourcing, identity management, and security awareness training, according to Infosecurity Europe.
26 February 2024
The leaked files include personal information of employees, former employees, and independent contractors, as well as sensitive internal documents, and only 98% of the stolen data has been leaked so far.
26 February 2024
Some countries experience disproportionate hacktivist attacks based on their aid to Ukraine, shedding light on the complexities of political motivations in cyber warfare.
26 February 2024
The theft, attributed to a "wallet compromise," did not affect the validation or operations of the Ronin chain or Sky Mavis, but highlighted the vulnerability of personal cryptocurrency wallets.
25 February 2024
The threat actors behind the LockBit ransomware operation have resurfaced on the dark web using new infrastructure, days after an international law enforcement exercise seized control of its servers.
To that end, the notorious group has moved its data leak portal to a new .onion address on the TOR network, listing 12 new victims as of writing.
The administrator behind LockBit, in a&
25 February 2024
The FBI's takedown of the LockBit ransomware group last week came as LockBit was preparing to release sensitive data stolen from government computer systems in Fulton County, Ga. But LockBit is now regrouping, and the gang says it will publish the stolen Fulton County data on March 2 unless paid a ransom. LockBit claims the cache includes documents tied to the county's ongoing criminal prosecution of former President Trump, but court watchers say teaser documents published by the crime gang suggest a total leak of the Fulton County data could put lives at risk and jeopardize a number of other criminal trials.
25 February 2024
LockBitSupp, the individual(s) behind the persona representing the LockBit ransomware service on cybercrime forums such as Exploit and XSS, "has engaged with law enforcement," authorities said.
The development comes following the takedown of the prolific ransomware-as-a-service (RaaS) operation as part of a coordinated international operation codenamed Cronos. Over 14,000 rogue
24 February 2024
Microsoft has expanded free logging capabilities to all U.S. federal agencies using Microsoft Purview Audit irrespective of the license tier, more than six months after a China-linked cyber espionage campaign targeting two dozen organizations came to light.
"Microsoft will automatically enable the logs in customer accounts and increase the default log retention period from 90 days to 180 days,"
24 February 2024
The White House issued an executive order to improve maritime port security, including bolstering cybersecurity policies and investing in infrastructure, while addressing concerns about Chinese-owned cranes' potential cybersecurity threats.
24 February 2024
The Australian government has experienced a significant increase in data breaches, with human error being the leading cause, highlighting the need for improved detection and response systems.