Latest Cybersecurity News and Articles


Report: Two Million Brits Victims of Financial Identity Fraud

07 February 2024
Nearly two million people in the UK may have had their identity stolen and used by fraudsters to open a financial account in 2023, according to FICO’s new Fraud, Identity and Digital Banking Report.

Critical Shim Bug Impacts Every Linux Bootloader Signed in the Past Decade

07 February 2024
The maintainers of 'shim' released version 15.8 to address six vulnerabilities, with the most critical one (CVE-2023-40547) potentially leading to remote code execution and Secure Boot bypass.

Are Cybersecurity Performance Measures Realistic?

07 February 2024
The GAO urged the White House to establish performance measures for federal cybersecurity initiatives, but the ONCD pushed back, citing the difficulty of developing outcome-oriented measures and estimating implementation costs.

Critical Bugs in Canon Printers Allow Code Execution, DDoS

07 February 2024
Canon has patched critical buffer-overflow bugs in its printers that could allow attackers to remotely perform denial of service or execute arbitrary code, emphasizing the importance of promptly updating firmware.

After FBI Takedown, KV-Botnet Operators Shift Tactics in Attempt to Bounce Back

07 February 2024
The threat actors behind the KV-botnet made "behavioral changes" to the malicious network as U.S. law enforcement began issuing commands to neutralize the activity. KV-botnet is the name given to a network of compromised small office and home office (SOHO) routers and firewall devices across the world, with one specific cluster acting as a covert data transfer system for other Chinese

Three Ways to Achieve Crypto Agility in a Post-Quantum World

07 February 2024
Crypto agility, including the ability to rapidly switch between certificate authorities and encryption standards, is essential for securing digital infrastructure in today's automated operational environment.

Google Open Sources AI-Boosted Fuzzing Framework

07 February 2024
The framework has successfully identified vulnerabilities in C/C++ projects, including two in cJSON and libplist, which might have remained undiscovered without the use of large language models.

New Vulnerabilities in Azure HDInsight Could Have Led to Privilege Escalations and Denial of Service

07 February 2024
These vulnerabilities could have allowed attackers to gain cluster administrator privileges, disrupt operations, and negatively impact the availability and reliability of the affected systems.

Critical Bootloader Vulnerability in Shim Impacts Nearly All Linux Distros

07 February 2024
The maintainers of shim have released version 15.8 to address six security flaws, including a critical bug that could pave the way for remote code execution under specific circumstances. Tracked as CVE-2023-40547 (CVSS score: 9.8), the vulnerability could be exploited to achieve a Secure Boot bypass. Bill Demirkapi of the Microsoft Security Response Center (MSRC) has been&

John Godfrey announced as Kansas Chief Information Security Officer

07 February 2024
Governor Laura Kelly recently announced that John Godfrey is the new Chief Information Security Officer (CISO) for the State of Kansas. 

Paying Ransoms is Becoming a Cost of Doing Business for Many

07 February 2024
Companies are bracing for a significant increase in cyber threats in 2024, with 96% of respondents expecting the threat of cyberattacks to their industry to rise, and 71% predicting an increase of more than 50%, according to Cohesity.

Hackers can Use Generative AI to Manipulate Live Conversations

07 February 2024
IBM researchers demonstrated a technique to intercept live conversations and replace keywords based on the context, allowing for the manipulation of information, financial fraud, and even real-time changes to news broadcasts and political speeches.

Linux Foundation Announces Post-Quantum Cryptography Alliance

07 February 2024
The Post-Quantum Cryptography Alliance aims to drive the adoption of post-quantum cryptography to address security risks posed by quantum computing, with support from industry leaders like Google, IBM, Amazon Web Services, and Cisco.

Business, Technology Groups Back SolarWinds Motion to Dismiss SEC Charges

07 February 2024
The U.S. Chamber of Commerce and the Business Roundtable argue that the SEC has expanded its interpretation of internal accounting controls provisions beyond Congress's original intent.

Spoutible API Exposed Encrypted Password Reset Tokens, 2FA Secrets of Users

07 February 2024
The social media platform Spoutible had a publicly exposed API that allowed hackers to scrape sensitive user information, including hashed passwords, authentication seeds, and password reset tokens.

ZeroFox to go private in $350M acquisition by Haveli Investments

07 February 2024
The acquisition, which has been approved by ZeroFox's Board of Directors, is expected to close in the first half of 2024. After the acquisition, ZeroFox will transition from a public entity to a privately held company.

Data Breach at French Healthcare Services Firm Viamedis Puts Millions at Risk

07 February 2024
Viamedis, a French healthcare services firm, suffered a cyberattack exposing the sensitive data of policyholders and healthcare professionals, leading to disruptions in healthcare services.

Attack Surface Management Platform Ionix Adds Another $15M to its $27M Series A Round

07 February 2024
Ionix (formerly Cyberpion) secured an additional $15 million in funding, bringing its total funding to $50.3 million. The company offers a platform to help enterprises manage their security posture and software supply chain across various platforms.

New Webinar: 5 Steps to vCISO Success for MSPs and MSSPs

07 February 2024
2024 will be the year of the vCISO. An incredible 45% of MSPs and MSSPs are planning to start offering vCISO services in 2024. As an MSP/MSSP providing vCISO services, you own the organization’s cybersecurity infrastructure and strategy. But you also need to position yourself as a reliable decision-maker, navigating professional responsibilities, business needs and leadership

UK and France Assemble Diplomats for International Agreement on Spyware

07 February 2024
The United Kingdom and France are co-hosting a diplomatic conference in London to address the proliferation of commercial cyber intrusion tools. The conference will include 35 nations, big tech leaders, legal experts, and human rights defenders.