Latest Cybersecurity News and Articles


New Coyote Trojan Targets 61 Brazilian Banks with Nim-Powered Attack

09 February 2024
Sixty-one banking institutions, all of them originating from Brazil, are the target of a new banking trojan called Coyote. "This malware utilizes the Squirrel installer for distribution, leveraging Node.js and a relatively new multi-platform programming language called Nim as a loader to complete its infection," Russian cybersecurity firm Kaspersky said in a Thursday report. What

Report: Critical Manufacturing Vulnerabilities Surge 230% in Six Months

09 February 2024
A new report by Nozomi Networks highlighted an increasing threat to operational technology (OT) and Internet of Things (IoT) environments, with 885 new vulnerabilities disclosed in the second half of 2023.

Raspberry Robin Actors are Buying Exploits for Faster Attacks

09 February 2024
The group's access to exploits for vulnerabilities, such as CVE-2023-36802 and CVE-2023-29360, suggests ties to sophisticated developers and the purchase of external 64-bit executables rather than in-house development.

Security Compass Announces Acquisition of Kontra from ThriveDX

09 February 2024
The acquisition reflects Security Compass's commitment to providing top-tier cybersecurity training solutions and complements its existing offerings, including Application Security Training, SD Elements, and Just-In-Time Training.

Android XLoader Malware can Now Auto-Execute After Installation

09 February 2024
The XLoader Android malware, operated by the threat actor known as Roaming Mantis, has been found to automatically execute on infected devices without requiring user interaction.

Update: Anydesk Says Software ‘Safe to Use’ After Cyberattack

09 February 2024
The cyberattack on AnyDesk's servers in Spain and Portugal did not result in the compromise of user credentials, and the company has taken steps to mitigate the incident.

Emirates NBD Reportedly Involved in a Data Breach

09 February 2024
The criminal organization "Wail Crinal 213" claims to have accessed the bank's server and is allegedly selling sensitive customer data, including emails, usernames, account details, and more.

Ivanti Publishes Urgent Warning About New Vulnerability

09 February 2024
The software company Ivanti has discovered a new vulnerability, CVE-2024-22024, in its products that allows unauthorized access to restricted resources. Although there is no evidence of exploitation, users are urged to promptly patch their systems.

Wazuh in the Cloud Era: Navigating the Challenges of Cybersecurity

09 February 2024
Cloud computing has innovated how organizations operate and manage IT operations, such as data storage, application deployment, networking, and overall resource management. The cloud offers scalability, adaptability, and accessibility, enabling businesses to achieve sustainable growth. However, adopting cloud technologies into your infrastructure presents various cybersecurity risks and

ResumeLooters Steal Millions of Unique Emails from Multiple Sites

09 February 2024
ResumeLooters conducted a major cyber operation, compromising over 65 job search and retail websites across the Asia Pacific region and pilfering more than 2 million user records. The discovery of a new campaign serves as a reminder to secure databases and websites—which can be exploited by publicly available tools.

Stealthy Zardoor Backdoor Targets Saudi Islamic Charity Organizations

09 February 2024
An unnamed Islamic non-profit organization in Saudi Arabia has been targeted as part of a stealthy cyber espionage campaign designed to drop a previously undocumented backdoor called Zardoor. Cisco Talos, which discovered the activity in May 2023, said the campaign has likely persisted since at least March 2021, adding it has identified only one compromised target to date, although it's

Fortinet Warns of Critical FortiOS SSL VPN Vulnerability Under Active Exploitation

09 February 2024
Fortinet has disclosed a new critical security flaw in FortiOS SSL VPN that it said is likely being exploited in the wild. The vulnerability, CVE-2024-21762 (CVSS score: 9.6), allows for the execution of arbitrary code and commands. "A out-of-bounds write vulnerability [CWE-787] in FortiOS may allow a remote unauthenticated attacker to execute arbitrary code or command via specially

Warning: New Ivanti Auth Bypass Flaw Affects Connect Secure and ZTA Gateways

08 February 2024
Ivanti has alerted customers of yet another high-severity security flaw in its Connect Secure, Policy Secure, and ZTA gateway devices that could allow attackers to bypass authentication. The issue, tracked as CVE-2024-22024, is rated 8.3 out of 10 on the CVSS scoring system. "An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti

Report: Blocked IP addresses increased by 116.42%

08 February 2024
The number of blocked IP addresses suspected of malicious traffic such as DDoS attacks surged from 18.5 million to 40.15 million from Q2 to Q3.

Chinese State-Sponsored Actors Compromised and Maintained Persistent Access to U.S. Critical Infrastructure for Five Years

08 February 2024
Volt Typhoon's tactics involve extensive pre-compromise reconnaissance, targeting of public-facing network appliances, exploitation of vulnerabilities, and use of living off the land (LOTL) techniques to maintain long-term undiscovered persistence.

Device Authority Raises $7M in Series A Funding

08 February 2024
The company specializes in identity and access management for enterprise IoT ecosystems, offering solutions to reduce human error, accelerate incident response, and establish trust in connected environments.

Kimsuky APT Disguises as a Korean Company to Distribute Troll Stealer

08 February 2024
Troll Stealer's similarities to known malware families linked to Kimsuky, such as AppleSeed and AlphaSeed, raise concerns about the group's offensive cyber operations and its targeting of South Korean entities.

HijackLoader Expands Techniques to Improve Defense Evasion

08 February 2024
The HijackLoader sample exhibits complex multi-stage behavior, including process hollowing, transacted section hollowing, and user mode hook bypass using Heaven’s Gate, to inject and execute the final payload while evading detection.

Funerals Reportedly Canceled Due to Ransomware Attack on Austrian Town

08 February 2024
The municipality of Korneuburg in Austria was hit by a ransomware attack, leading to data encryption and the cancellation of funerals due to the inability to issue death certificates.

Chinese Hackers Operate Undetected in U.S. Critical Infrastructure for Half a Decade

08 February 2024
The U.S. government on Wednesday said the Chinese state-sponsored hacking group known as Volt Typhoon had been embedded into some critical infrastructure networks in the country for at least five years. Targets of the threat actor include communications, energy, transportation, and water and wastewater systems sectors in the U.S. and Guam. "Volt Typhoon's choice of targets and pattern