Latest Cybersecurity News and Articles


VoltSchemer Attacks Use Wireless Chargers to Inject Voice Commands, Fry Phones

21 February 2024
The attack takes advantage of security flaws in wireless charging systems, allowing attackers to manipulate the charger's voltage and interfere with the communication between the charger and the smartphone.

Astaroth, Mekotio, and Ousaban Abusing Google Cloud Run in LATAM-Focused Malware Campaigns

21 February 2024
Google Cloud Run is being exploited by threat actors to distribute banking trojans, with a significant increase in malicious email campaigns observed since September 2023 targeting victims in Latin America, Europe, and North America.

CVEs expected to increase 25% in 2024

21 February 2024
According to a recent cybersecurity report, the total number of common vulnerabilities and exposures (CVEs) is expected to increase by 25% in 2024.

Insider Steals 80,000 Email Addresses From UK District Councils

21 February 2024
A former council worker has been cautioned by police for taking 79,000 residents' email addresses from a database to promote a business unrelated to the council. Another database from Warwick District Council was also affected.

Report: Average breakout time for intrusive activity is 62 minutes

21 February 2024
Cyberattackers are getting past defenses quicker than they were in previous years, leaving security leaders with a small window of time to respond. 

Critical Infrastructure Vendor PSI Software Hit by Ransomware Attack

21 February 2024
PSI Software, a Germany-based critical infrastructure software vendor, suffered a ransomware attack, resulting in diminished capacity and shutting down of external connections and systems.

Mustang Panda Targets Asia with Advanced PlugX Variant DOPLUGS

21 February 2024
The China-linked threat actor known as Mustang Panda has targeted various Asian countries using a variant of the PlugX (aka Korplug) backdoor dubbed DOPLUGS. "The piece of customized PlugX malware is dissimilar to the general type of the PlugX malware that contains a completed backdoor command module, and that the former is only used for downloading the latter," Trend Micro researchers Sunny Lu

Chinese Hacking Contractor iSoon Leaks Internal Documents

21 February 2024
The company mainly works for the Ministry of Public Security, focusing on domestic security interests. The leaked documents show the use of hacking tools such as Winnti backdoor and PlugX remote access Trojan.

DC-Area School System Says Data of 100,000 People Affected in Ransomware Attack

21 February 2024
The Prince George's County Public Schools in the Washington, D.C. area experienced a ransomware attack, compromising the personal information of nearly 100,000 individuals, including names, financial account information, and Social Security Numbers.

6 Ways to Simplify SaaS Identity Governance

21 February 2024
With SaaS applications now making up the vast majority of technology used by employees in most organizations, tasks related to identity governance need to happen across a myriad of individual SaaS apps. This presents a huge challenge for centralized IT teams who are ultimately held responsible for managing and securing app access, but can’t possibly become experts in the nuances of the native

Clean Links and Sophisticated Scams Mark New Era in Email Attacks

21 February 2024
An analysis by VIPRE Security revealed that email attacks are on the rise, with an increase in malicious EML file attachments and social engineering attacks in the last quarter of 2023.

Charming Kitten Uses BASICSTAR Against Middle East Policy Experts

21 February 2024
Iranian-origin threat group Charming Kitten has launched an espionage campaign targeting Middle East policy experts using malware such as BASICSTAR and KORKULOADER, capable of executing remote commands and displaying decoy PDF files. Some phishing attacks dropped customized backdoors, POWERLESS for Windows and NokNok for macOS, based on the victim's operating system.

Cybersecurity for Healthcare—Diagnosing the Threat Landscape and Prescribing Solutions for Recovery

21 February 2024
On Thanksgiving Day 2023, while many Americans were celebrating, hospitals across the U.S. were doing quite the opposite. Systems were failing. Ambulances were diverted. Care was impaired. Hospitals in three states were hit by a ransomware attack, and in that moment, the real-world repercussions came to light—it wasn’t just computer networks that were brought to a halt, but actual patient

Hacker Arrested for Selling Bank Accounts of US, Canadian Users

21 February 2024
A 31-year-old Ukrainian cybercriminal was arrested for distributing trojanized software to gain access to American and Canadian users' bank accounts, selling the breached accounts on the dark web.

Iran and Hezbollah Hackers Launch Attacks to Influence Israel-Hamas Narrative

21 February 2024
Iranian and Hezbollah-backed hackers conducted cyber attacks to undermine public support for the Israel-Hamas war, using tactics such as destructive attacks, hack-and-leak operations, phishing campaigns, and information operations.

Permit.io Secures $8m in Series A for Revolutionary Authorization Service

21 February 2024
Permit.io, a provider of authorization-as-a-service solution has closed a successful $8m Series A funding round led by Scale Venture Partners and supported by other investors.

Israeli El Al Alleges Hackers Targeted Flights in Mid-Air Hijack Attempt

21 February 2024
The hackers tried to divert the planes, but the pilots detected the suspicious activity and took appropriate action to ensure the safety of the flights. This incident raises concerns about aircraft safety in the face of growing cybersecurity threats.

New 'VietCredCare' Stealer Targeting Facebook Advertisers in Vietnam

21 February 2024
Facebook advertisers in Vietnam are the target of a previously unknown information stealer dubbed VietCredCare at least since August 2022. The malware is “notable for its ability to automatically filter out Facebook session cookies and credentials stolen from compromised devices, and assess whether these accounts manage business profiles and if they maintain a positive Meta ad credit

Signal Introduces Usernames, Allowing Users to Keep Their Phone Numbers Private

21 February 2024
End-to-end encrypted (E2EE) messaging app Signal said it’s piloting a new feature that allows users to create unique usernames (not to be confused with profile names) and keep the phone numbers away from prying eyes. “If you use Signal, your phone number will no longer be visible to everyone you chat with by default,” Signal’s Randall Sarafa said. “People who have your number saved in their

LockBit Ransomware's Darknet Domains Seized in Global Law Enforcement Raid

21 February 2024
Law enforcement agencies from 11 countries, including the U.K. and the U.S., have collaborated in a joint effort, codenamed Operation Cronos, to seize multiple darknet domains operated by the ransomware group LockBit.