Latest Cybersecurity News and Articles


Russia-Aligned Hackers Target European and Iranian Embassies in New Espionage Campaign

19 February 2024
A Russia-linked hacking group, Winter Vivern, exploited a vulnerability in the Roundcube webmail server to spy on government and military agencies in Europe and Iranian embassies in Russia, indicating a significant cybersecurity threat.

Meta Warns of 8 Spyware Firms Targeting iOS, Android, and Windows Devices

19 February 2024
Meta Platforms said it took a series of steps to curtail malicious activity from eight different firms based in Italy, Spain, and the United Arab Emirates (U.A.E.) operating in the surveillance-for-hire industry. The findings are part of its Adversarial Threat Report for the fourth quarter of 2023. The spyware targeted iOS, Android, and Windows devices. "Their various malware included

Hackers Claim Data Breach at Staffing Giant Robert Half, Sell Sensitive Data

19 February 2024
The stolen data includes confidential records, employee documents, customer information, and configuration settings related to services such as OpenAI and Twilio, posing a significant threat to the company and its clients.

Joint Cyber Defense Collaborative announces its priorities for 2024

19 February 2024
The 2024 priorities of the Joint Cyber Defense Collaborative aim to secure against immediate and evolving cyber risks. 

Ukrainian Extradited to US Over Alleged Raccoon Stealer Ties

19 February 2024
Mark Sokolovsky, a Ukrainian national, has been extradited to the United States to face criminal charges related to his involvement in the Raccoon info stealer malware-as-a-service operation.

Iranian Hackers Target Middle East Policy Experts with New BASICSTAR Backdoor

19 February 2024
Charming Kitten's phishing attacks involve social engineering tactics, compromised email accounts, and the distribution of various backdoors, demonstrating their commitment to surveillance and malware deployment.

How to Achieve the Best Risk-Based Alerting (Bye-Bye SIEM)

19 February 2024
Did you know that Network Detection and Response (NDR) has become the most effective technology to detect cyber threats? In contrast to SIEM, NDR offers adaptive cybersecurity with reduced false alerts and efficient threat response. Are you aware of Network Detection and Response (NDR) and how it’s become the most effective technology to detect cyber threats?  NDR massively

RCE Vulnerabilities Fixed in Solarwinds Enterprise Solutions

19 February 2024
SolarWinds has patched critical vulnerabilities in its Access Rights Manager (ARM) and (Orion) Platform that could allow attackers to execute code, emphasizing the importance of promptly updating to the fixed versions.

Anatsa Android Trojan Bypasses Google Play Security, Expands Reach to New Countries

19 February 2024
The Android banking trojan known as Anatsa has expanded its focus to include Slovakia, Slovenia, and Czechia as part of a new campaign observed in November 2023. "Some of the droppers in the campaign successfully exploited the accessibility service, despite Google Play's enhanced detection and protection mechanisms," ThreatFabric said in a report shared with The Hacker News.

Massive Utility Scam Campaign Spreads via Online Ads

19 February 2024
Scammers create multiple fraudulent domains and use scare tactics to pressure victims into making hasty decisions, such as disclosing personal details or making immediate payments.

New MonikerLink Flaw Exposes Outlook Users to Data Theft and Malware

19 February 2024
The #MonikerLink vulnerability in Microsoft Outlook has a critical severity rating of 9.8 out of 10 and allows threat actors to execute arbitrary code with minimal user interaction, posing a significant security risk.

Update: ALPHV Ransomware Claims loanDepot, Prudential Financial Breaches

19 February 2024
The ALPHV/Blackcat ransomware gang has claimed responsibility for breaching the networks of Prudential Financial and loanDepot, leading to significant data theft and potential cybersecurity risks for millions of individuals.

ESET Fixed High-Severity Local Privilege Escalation Bug in Windows Products

19 February 2024
ESET addressed a high-severity vulnerability (CVE-2024-0353) in its Windows security products allowing attackers to delete files without proper permission, potentially escalating their privileges.

Russian-Linked Hackers Breach 80+ Organizations via Roundcube Flaws

19 February 2024
Threat actors operating with interests aligned to Belarus and Russia have been linked to a new cyber espionage campaign that likely exploited cross-site scripting (XSS) vulnerabilities in Roundcube webmail servers to target over 80 organizations. These entities are primarily located in Georgia, Poland, and Ukraine, according to Recorded Future, which attributed the intrusion set to a threat

Iranian Hackers Target Middle East Policy Experts with New BASICSTAR Backdoor

18 February 2024
The Iranian-origin threat actor known as Charming Kitten has been linked to a new set of attacks aimed at Middle East policy experts with a new backdoor called BASICSTAR by creating a fake webinar portal. Charming Kitten, also called APT35, CharmingCypress, Mint Sandstorm, TA453, and Yellow Garuda, has a history of orchestrating a wide range of social engineering campaigns that cast a

FBI's Most-Wanted Zeus and IcedID Malware Mastermind Pleads Guilty

18 February 2024
A Ukrainian national has pleaded guilty in the U.S. to his role in two different malware schemes, Zeus and IcedID, between May 2009 and February 2021. Vyacheslav Igorevich Penchukov (aka Vyacheslav Igoravich Andreev, father, and tank), 37, was arrested by Swiss authorities in October 2022 and extradited to the U.S. last year. He was added to the FBI's most-wanted list in 2012. The U.S.

How Businesses Can Safeguard Their Communication Channels Against Hackers

17 February 2024
Efficient communication is a cornerstone of business success. Internally, making sure your team communicates seamlessly helps you avoid friction losses, misunderstandings, delays, and overlaps. Externally, frustration-free customer communication is directly correlated to a positive customer experience and higher satisfaction.  However, business communication channels are also a major target

Alpha Ransomware Emerges From NetWalker Ashes

17 February 2024
The Alpha ransomware operation appears to be linked to the previously inactive NetWalker ransomware, suggesting a potential revival or acquisition of the original payload.

Google Open Sources Magika: AI-Powered File Identification Tool

17 February 2024
Google has announced that it's open-sourcing Magika, an artificial intelligence (AI)-powered tool to identify file types, to help defenders accurately detect binary and textual file types. "Magika outperforms conventional file identification methods providing an overall 30% accuracy boost and up to 95% higher precision on traditionally hard to identify, but potentially problematic content

CISA Warns of Akira Ransomware Exploiting Cisco ASA/FTD Vulnerability

17 February 2024
The information disclosure vulnerability, known as CVE-2020-3259, is being exploited by the Akira ransomware group to compromise susceptible Cisco Anyconnect SSL VPN appliances.