Latest Cybersecurity News and Articles


Three Tips to Protect Your Secrets from AI Accidents

26 February 2024
Last year, the Open Worldwide Application Security Project (OWASP) published multiple versions of the "OWASP Top 10 For Large Language Models," reaching a 1.0 document in August and a 1.1 document in October. These documents not only demonstrate the rapidly evolving nature of Large Language Models, but the evolving ways in which they can be attacked and defended. We're going to talk in this

HHS Reaches Second-Ever Ransomware Settlement

26 February 2024
The U.S. Department of Health and Human Services (HHS) reached a settlement with Green Ridge Behavioral Health after a ransomware attack exposed the health information of over 14,000 individuals.

Banking Trojans Target Latin America and Europe Through Google Cloud Run

26 February 2024
Cybersecurity researchers are warning about a spike in email phishing campaigns that are weaponizing the Google Cloud Run service to deliver various banking trojans such as Astaroth (aka Guildma), Mekotio, and Ousaban (aka Javali) to targets across Latin America (LATAM) and Europe. "The infection chains associated with these malware families feature the use of malicious

Russian-Aligned Network Doppelgänger Targets German Elections

26 February 2024
The campaign involves a substantial network of social media accounts, sophisticated infrastructure, and tactics to evade detection, posing a challenge to combat such influence operations.

Cybersecurity Fears Drive a Return to On-Premise Infrastructure From Cloud Computing

26 February 2024
According to Citrix, 42% of organizations surveyed in the US are considering or already have moved at least half of their cloud-based workloads back to on-premises infrastructures, a phenomenon known as cloud repatriation.

UK and allies expose evolving tactics of Russian cyber actors

26 February 2024
New advisory reveals evolving tactics used by Russian state-linked cyber actors as more organisations move to cloud-based infrastructure.

UK and allies expose evolving tactics of Russian cyber actors

26 February 2024
New advisory reveals evolving tactics used by Russian state-linked cyber actors as more organisations move to cloud-based infrastructure.

Malawi Immigration Department Halts Services Amid Cyberattack

26 February 2024
The Malawi government has suspended passport issuance for two weeks due to a ransomware attack on the immigration service's network. President Lazarus Chakwera stated that the hackers are demanding a ransom, but the government refuses to pay.

Apple Unveils PQ3 Protocol - Post-Quantum Encryption for iMessage

26 February 2024
The protocol combines Kyber and ECC, aims to mitigate the impact of key compromises, and will be integrated into Apple's iOS, iPadOS, macOS, and watchOS in the next update.

Dormant PyPI Package Compromised to Spread Nova Sentinel Malware

26 February 2024
The attacker stripped the package of its original content, leaving only an __init__.py and example.py file, and introduced an executable named "Updater_1.4.4_x64.exe" to launch the Nova Sentinel malware.

Businesses Increase Cybersecurity as Budgets Surge in 2024

26 February 2024
Cloud security and incident response are top priorities, attracting 47% of additional cybersecurity spending, followed by areas such as MSSP outsourcing, identity management, and security awareness training, according to Infosecurity Europe.

Update: Sony Subsidiary Insomniac Games Alerts Employees Hit by Ransomware Data Breach

26 February 2024
The leaked files include personal information of employees, former employees, and independent contractors, as well as sensitive internal documents, and only 98% of the stolen data has been leaked so far.

A New Age of Hacktivism

26 February 2024
Some countries experience disproportionate hacktivist attacks based on their aid to Ukraine, shedding light on the complexities of political motivations in cyber warfare.

Hackers Steal Nearly $10 Million From Axie Infinity Co-Founder’s Personal Accounts

26 February 2024
The theft, attributed to a "wallet compromise," did not affect the validation or operations of the Ronin chain or Sky Mavis, but highlighted the vulnerability of personal cryptocurrency wallets.

LockBit Ransomware Group Resurfaces After Law Enforcement Takedown

25 February 2024
The threat actors behind the LockBit ransomware operation have resurfaced on the dark web using new infrastructure, days after an international law enforcement exercise seized control of its servers. To that end, the notorious group has moved its data leak portal to a new .onion address on the TOR network, listing 12 new victims as of writing. The administrator behind LockBit, in a&

FBI’s LockBit Takedown Postponed a Ticking Time Bomb in Fulton County, Ga.

25 February 2024
The FBI's takedown of the LockBit ransomware group last week came as LockBit was preparing to release sensitive data stolen from government computer systems in Fulton County, Ga. But LockBit is now regrouping, and the gang says it will publish the stolen Fulton County data on March 2 unless paid a ransom. LockBit claims the cache includes documents tied to the county's ongoing criminal prosecution of former President Trump, but court watchers say teaser documents published by the crime gang suggest a total leak of the Fulton County data could put lives at risk and jeopardize a number of other criminal trials.

Authorities Claim LockBit Admin "LockBitSupp" Has Engaged with Law Enforcement

25 February 2024
LockBitSupp, the individual(s) behind the persona representing the LockBit ransomware service on cybercrime forums such as Exploit and XSS, "has engaged with law enforcement," authorities said. The development comes following the takedown of the prolific ransomware-as-a-service (RaaS) operation as part of a coordinated international operation codenamed Cronos. Over 14,000 rogue

Microsoft Expands Free Logging Capabilities for all U.S. Federal Agencies

24 February 2024
Microsoft has expanded free logging capabilities to all U.S. federal agencies using Microsoft Purview Audit irrespective of the license tier, more than six months after a China-linked cyber espionage campaign targeting two dozen organizations came to light. "Microsoft will automatically enable the logs in customer accounts and increase the default log retention period from 90 days to 180 days,"

President Biden's Executive Order Seeks to Bolster Port Cybersecurity

24 February 2024
The White House issued an executive order to improve maritime port security, including bolstering cybersecurity policies and investing in infrastructure, while addressing concerns about Chinese-owned cranes' potential cybersecurity threats.

Australia: Second Accidental Data Leak in Four Months ‘Regrettable’, Finance Department Says

24 February 2024
The Australian government has experienced a significant increase in data breaches, with human error being the leading cause, highlighting the need for improved detection and response systems.