Latest Cybersecurity News and Articles


Russian Hackers Target Ukraine with Disinformation and Credential-Harvesting Attacks

21 February 2024
Cybersecurity researchers have unearthed a new influence operation targeting Ukraine that leverages spam emails to propagate war-related disinformation. The activity has been linked to Russia-aligned threat actors by Slovak cybersecurity company ESET, which also identified a spear-phishing campaign aimed at a Ukrainian defense company in October 2023 and a European Union agency in November 2023

VMware Alert: Uninstall EAP Now - Critical Flaw Puts Active Directory at Risk

21 February 2024
VMware is urging users to uninstall the deprecated Enhanced Authentication Plugin (EAP) following the discovery of a critical security flaw. Tracked as CVE-2024-22245 (CVSS score: 9.6), the vulnerability has been described as an arbitrary authentication relay bug. "A malicious actor could trick a target domain user with EAP installed in their web browser into requesting and relaying

Feds Seize LockBit Ransomware Websites, Offer Decryption Tools, Troll Affiliates

20 February 2024
U.S. and U.K. authorities have seized the darknet websites run by LockBit, a prolific and destructive ransomware group that has claimed more than 2,000 victims worldwide and extorted over $120 million in payments. Instead of listing data stolen from ransomware victims who didn't pay, LockBit's victim shaming website now offers free recovery tools, as well as news about arrests and criminal charges involving LockBit affiliates.

A penny per email could curb our enormous data use | Letters

20 February 2024
A penny per email could curb our enormous data use | Letters Mike McClelland proposes a 1p charge for messages in response to an article on the downside of Ireland’s datacentre boom. Plus a letter from Sue Stephenson The long read (Power grab: the hidden costs of Ireland’s datacentre boom, 15 February) highlights the enormous cost in terms of energy consumption and carbon emissions of our collective love affair with the seemingly free ability to send emails, text and WhatsApp messages every minute of the day. There is an enormous cost to us all in terms of data storage – a fact of which we are barely cognisant.Think how much money could be raised to counter the impact on our environment if we all paid just one penny for each digital message we blithely send. And tuppence if there is an attachment, and thruppence if it includes a digital photo of the meal you ate at a restaurant last night. Continue reading...

Industrial sector ransomware attacks increased by 50% in 2023

20 February 2024
Industrial cybersecurity was analyzed in a recent report by Dragos Inc, finding that ransomware attacks increased 50% over the last year.

New Migo Malware Targeting Redis Servers for Cryptocurrency Mining

20 February 2024
A novel malware campaign has been observed targeting Redis servers for initial access with the ultimate goal of mining cryptocurrency on compromised Linux hosts. "This particular campaign involves the use of a number of novel system weakening techniques against the data store itself," Cado security researcher Matt Muir said in a technical report. The cryptojacking attack is facilitated

Critical Flaws Found in ConnectWise ScreenConnect Software

20 February 2024
ConnectWise has released software updates to address two critical security flaws in its ScreenConnect remote desktop and access software. The vulnerabilities could allow remote code execution and unauthorized access to restricted directories.

Report: Malicious emails bypassing secure email gateways rose by 105%

20 February 2024
The report uncovers the latest information in email security and malicious email threats, emphasizing emerging techniques that security leaders must defend against. 

NCSC statement on law enforcement's disruption of LockBit ransomware operation

20 February 2024
The National Crime Agency (NCA) has announced that it is conducting a months-long campaign with international partners to disrupt the threat posed by the LockBit ransomware operation.

Over 28,500 Exchange Servers Vulnerable to Actively Exploited Bug

20 February 2024
The CVE-2024-21410 vulnerability allows remote unauthenticated actors to perform NTLM relay attacks, potentially leading to unauthorized access to confidential data and network exploitation.

Several Ukrainian Media Outlets Attacked by Russian Hackers

20 February 2024
Ukrainian authorities and cybersecurity agencies attributed the attack to Russian threat actors and described it as part of Russia's "information warfare" against Ukraine.

North Korean Hackers Linked to Defense Sector Supply-Chain Attack

20 February 2024
The German federal intelligence agency and South Korea's National Intelligence Service have issued a joint advisory warning about ongoing cyber-espionage operations targeting the global defense sector on behalf of North Korea.

Wyze Camera Breach Let 13,000 Strangers Look into Other People’s Homes

20 February 2024
The breach resulted from a system overload caused by incorrect mapping of device IDs, which was attributed to a third-party caching client library recently integrated into Wyze's system.

UK and FBI take over ransomware group’s website

20 February 2024
UK and FBI take over ransomware group’s website UK agency says they have ‘hacked the hackers’ and will help LockBit victims decrypt their systemsA massive law enforcement operation has seized the “command and control” infrastructure for international ransomware group LockBit, the UK’s National Crime Agency (NCA) revealed on Tuesday, and will repurpose the technology to expose the group’s operations to the world.The joint operation, between the NCA, the FBI, Europol and a coalition of international police agencies, was first revealed with a post on LockBit’s own website, which read: “This site is now under the control of the National Crime Agency of the UK, working in close cooperation with the FBI and the international law enforcement taskforce Operation Cronos.” Continue reading...

US adversaries employ generative AI in attempted cyberattack

20 February 2024
A recent report reveals how cyberattacks utilizing AI technology were carried out by state adversaries, highlighting the global threat landscape and importance of cybersecurity vigilance. 

LockBit Ransomware Operation Shut Down; Criminals Arrested; Decryption Keys Released

20 February 2024
The U.K. National Crime Agency (NCA) on Tuesday confirmed that it obtained LockBit's source code as well as intelligence pertaining to its activities and their affiliates as part of a dedicated task force called Operation Cronos. "Some of the data on LockBit's systems belonged to victims who had paid a ransom to the threat actors, evidencing that even when a ransom is paid, it does not

NCSC statement on law enforcement's disruption of lockbit ransomware operation

20 February 2024
The National Crime Agency (NCA) has announced that it is conducting a months-long campaign with international partners to disrupt the threat posed by the Lockbit ransomware operation.

New Malicious PyPI Packages Caught Using Covert Side-Loading Tactics

20 February 2024
Cybersecurity researchers have discovered two malicious packages on the Python Package Index (PyPI) repository that were found leveraging a technique called DLL side-loading to circumvent detection by security software and run malicious code. The packages, named NP6HelperHttptest and NP6HelperHttper, were each downloaded 537 and 166 times, respectively,

NCSC statement on law enforcement's distribution of lockbit ransomware operation

20 February 2024
The National Crime Agency (NCA) has announced that it is conducting a months-long campaign with international partners to disrupt the threat posed by the Lockbit ransomware operation.

Hackers Exploit Critical RCE Flaw in Bricks WordPress Site Builder

20 February 2024
The vulnerability, tracked as CVE-2024-25600, was discovered by a researcher named 'snicco' and a fix became available on February 13 with the release of version 1.9.6.1.