Latest Cybersecurity News and Articles


91% of organizations faced a software supply chain attack last year

13 February 2024
According to a recent cybersecurity report by Data Theorem, 91% of organizations experienced a software supply chain attack over the last year. 

Diving Into Glupteba's UEFI Bootkit

13 February 2024
The Pay-Per-Install (PPI) ecosystem, originally intended for distributing advertisements, has evolved into a profitable platform for spreading spyware and malware, including threats like Glupteba.

Notorious Bumblebee Malware Re-emerges with New Attack Methods

13 February 2024
The Bumblebee malware has re-emerged with a significantly different attack chain after a four-month absence, utilizing social engineering techniques and unique characteristics in its new campaign.

Glupteba Botnet Evades Detection with Undocumented UEFI Bootkit

13 February 2024
The Glupteba botnet has been found to incorporate a previously undocumented Unified Extensible Firmware Interface (UEFI) bootkit feature, adding another layer of sophistication and stealth to the malware. "This bootkit can intervene and control the [operating system] boot process, enabling Glupteba to hide itself and create a stealthy persistence that can be extremely difficult to

PikaBot Resurfaces with Streamlined Code and Deceptive Tactics

13 February 2024
The threat actors behind the PikaBot malware have made significant changes to the malware in what has been described as a case of "devolution." "Although it appears to be in a new development cycle and testing phase, the developers have reduced the complexity of the code by removing advanced obfuscation techniques and changing the network communications," Zscaler ThreatLabz researcher Nikolaos

LectureNotes Learning App breach affects over 2 million users

13 February 2024
Millions of users of the LectureNotes Learning App have had their sensitive information leaked in this data breach. 

Report: Over 1.76 billion phishing emails were sent in 2023

13 February 2024
A new report reveals that 2023 saw the highest amount of phishing emails sent globally. 

Jet Engine Dealer to Major Airlines Discloses ‘Unauthorized Activity’

13 February 2024
The Black Basta ransomware group claims to have stolen 910 GB of sensitive company data from Willis Lease Finance Corporation, including passport scans and personal information of staff and customers.

SiCat: Open-Source Exploit Finder

13 February 2024
The tool has key features such as an easy-to-understand code structure, reporting/output system in HTML and JSON formats, and the ability to run via Nmap scan results in XML format.

Bank of America Warns Customers of Data Breach After Vendor Hack

13 February 2024
The personal information of approximately 57,028 individuals was exposed, including names, addresses, social security numbers, and financial details. The breach was attributed to a cyberattack by the LockBit ransomware gang.

Midnight Blizzard and Cloudflare-Atlassian Cybersecurity Incidents: What to Know

13 February 2024
The Midnight Blizzard and Cloudflare-Atlassian cybersecurity incidents raised alarms about the vulnerabilities inherent in major SaaS platforms. These incidents illustrate the stakes involved in SaaS breaches — safeguarding the integrity of SaaS apps and their sensitive data is critical but is not easy. Common threat vectors such as sophisticated spear-phishing, misconfigurations and

Hackers Exploit Ivanti SSRF Flaw to Deploy New DSLog Backdoor

13 February 2024
The new DSLog backdoor allows threat actors to execute commands on compromised Ivanti servers remotely, and Orange Cyberdefense has confirmed its successful exploitation.

Update: Caravan Club Admits Members’ Personal Data Possibly Accessed

13 February 2024
Members are advised to be cautious of phishing attacks and to update their passwords as a precautionary measure, while the organization has taken steps to enhance cybersecurity in response to the incident.

Ransomware Tactics Evolve, Become Scrappier

13 February 2024
Ransomware attacks surged in 2023, with the United States accounting for almost half of all attacks according to Malwarebytes, and cybercriminals evolving their tactics to target a higher volume of victims simultaneously.

FCC Orders Telecom Carriers to Report PII Data Breaches Within 30 Days

13 February 2024
Major U.S. telecom carriers such as Verizon, T-Mobile, and AT&T have experienced significant data breaches in recent years, highlighting the crucial need for aligning FCC's data breach rules with federal and state laws applicable to other sectors.

Protecting Against AI-Enhanced Email Threats

13 February 2024
Combining traditional email security measures with AI-based solutions and empowering cybersecurity personnel with AI skills is crucial for organizations to defend against evolving cyber threats.

China Targets US Hacking Ops in Media Offensive

13 February 2024
The campaign involves collaboration between Chinese cybersecurity firms, government agencies, and state media to amplify allegations of hacking operations by the United States.

Bugcrowd Attains $102M Strategic Growth Funding Round

13 February 2024
Bugcrowd, which has already attracted $90 million in prior investments, plans to use the funds to enhance its bug bounty programs, vulnerability disclosure, and crowdsourced penetration testing.

CISA Warns of Roundcube Email Server Bug Now Exploited in Attacks

13 February 2024
The Roundcube email server vulnerability (CVE-2023-43770) is actively exploited in cross-site scripting (XSS) attacks, posing a significant risk to both federal agencies and private organizations worldwide.

Ivanti Vulnerability Exploited to Install 'DSLog' Backdoor on 670+ IT Infrastructures

13 February 2024
Threat actors are leveraging a recently disclosed security flaw impacting Ivanti Connect Secure, Policy Secure, and ZTA gateways to deploy a backdoor codenamed DSLog on susceptible devices. That's according to findings from Orange Cyberdefense, which said it observed the exploitation of CVE-2024-21893 within hours of the public release of the proof-the-concept (PoC) code.