Latest Cybersecurity News and Articles


Patchwork Using Romance Scam Lures to Infect Android Devices with VajraSpy Malware

05 February 2024
The threat actor known as Patchwork likely used romance scam lures to trap victims in Pakistan and India, and infect their Android devices with a remote access trojan called VajraSpy. Slovak cybersecurity firm ESET said it uncovered 12 espionage apps, six of which were available for download from the official Google Play Store and were collectively downloaded more than 1,400 times between

Over 25$ Million Lost in Deepfake Conference Call Scam at Hong Kong Office of Multinational Firm

05 February 2024
The scammers digitally recreated the company's chief financial officer and other employees in a convincing video conference call to trick the victim into making money transfers.

New Mispadu Banking Trojan Exploits Windows SmartScreen Flaw

05 February 2024
The Windows SmartScreen vulnerability CVE-2023-36025 allows threat actors to bypass warnings and execute malicious payloads using crafted .url files, posing a significant security risk to Windows users.

DDoS Attack Power Skyrockets to 1.6 Tbps

05 February 2024
The second half of 2023 saw a significant increase in the scale and sophistication of DDoS attacks, with the maximum attack power rising to 1.6 Tbps, according to data by Gcore.

Report: Civil Society in Jordan Under Assault by NSO's Pegasus Spyware

05 February 2024
An investigation revealed widespread use of Pegasus spyware on the phones of journalists, human rights advocates, and lawyers in Jordan, suggesting a targeted surveillance campaign by Jordanian authorities.

Hands-On Review: SASE-based XDR from Cato Networks

05 February 2024
Companies are engaged in a seemingly endless cat-and-mouse game when it comes to cybersecurity and cyber threats. As organizations put up one defensive block after another, malicious actors kick their game up a notch to get around those blocks. Part of the challenge is to coordinate the defensive abilities of disparate security tools, even as organizations have limited resources and a dearth of

Combined Security Practices Changing the Game for Risk Management

05 February 2024
A significant challenge within cyber security at present is that there are a lot of risk management platforms available in the market, but only some deal with cyber risks in a very good way. The majority will shout alerts at the customer as and when they become apparent and cause great stress in the process. The issue being that by using a reactive, rather than proactive approach, many risks

More Ransomware Victims are Declining to Pay Extortionists

05 February 2024
The decline in the number of ransomware victims paying a ransom is attributed to better business resilience, assistance from the FBI, and the realization that paying for intangible promises is not effective.

China-Linked Hackers Primed to Attack US Critical Infrastructure, FBI Director Says

05 February 2024
The Cybersecurity and Infrastructure Security Agency (CISA) has observed an evolving threat from China-linked hackers infiltrating U.S. critical infrastructure, aiming to induce societal panic and chaos.

Lurie Children’s Hospital in Chicago Took Systems Offline After Cyberattack

05 February 2024
Some internal services at the hospital, such as internet, email, and access to medical platforms, have been affected, resulting in delays for scheduled procedures and test results.

Accenture and Tenchi Security Unite to Fortify Supply Chain Security

05 February 2024
This strategic partnership will involve integrating Tenchi's SaaS platform into Accenture's managed security services to enhance defenses against supply chain security threats.

Detecting and Mitigating the “Greatness” Phishing Kit Threat

05 February 2024
The "Greatness" phishing tool poses a significant threat to Microsoft 365 accounts and has the capability to outmaneuver multi-factor authentication, increasing the potential for cybercrime.

Oasis Security Leaves Stealth With $40M to Lock down the Wild West of Non-Human Identity Management

05 February 2024
Oasis Security, a startup from Israel, has developed a three-part system to address the challenges of non-human identity management, including discovery, resolution, and automation.

Update: DOJ Charges Trio in SIM-Swap Scheme Potentially Linked to $400 Million FTX Crypto Heist

05 February 2024
The trio obtained personal information from around 50 individuals and used it to access authentication codes for financial accounts, including those of FTX, resulting in the transfer of over $400 million in digital assets.

Pegasus Spyware Targeted iPhones of Journalists and Activists in Jordan

05 February 2024
The iPhones belonging to nearly three dozen journalists, activists, human rights lawyers, and civil society members in Jordan have been targeted with NSO Group's Pegasus spyware, according to joint findings from Access Now and the Citizen Lab. Nine of the 35 individuals have been publicly confirmed as targeted, out of whom had their devices compromised with the mercenary

Update: Secret Service Recovers Nearly $3 Million Stolen From North Carolina Housing Authority in BEC Scam

05 February 2024
The scam involved a request to update payment information for a private company contracting with the agency, resulting in the transfer of funds to an illegitimate account.

New Mispadu Banking Trojan Exploiting Windows SmartScreen Flaw

04 February 2024
The threat actors behind the Mispadu banking Trojan have become the latest to exploit a now-patched Windows SmartScreen security bypass flaw to compromise users in Mexico. The attacks entail a new variant of the malware that was first observed in 2019, Palo Alto Networks Unit 42 said in a report published last week. Propagated via phishing mails, Mispadu is a Delphi-based information stealer

Iran-Linked Hackers Claim Attack on Albania’s Institute of Statistics

03 February 2024
The hackers claimed to have accessed over 100 terabytes of Albania’s geographic information system and population data, although the institute denied that recent census data was compromised.

South African Railways Lost Over $1M in Phishing Scam

03 February 2024
The Passenger Rail Agency of South Africa (PRASA) reported a loss of 30.6 million rand due to a phishing scam, with only half of the stolen money recovered. Insider threats, such as ghost email accounts, are suspected.

U.S. Sanctions 6 Iranian Officials for Critical Infrastructure Cyber Attacks

03 February 2024
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) announced sanctions against six officials associated with the Iranian intelligence agency for attacking critical infrastructure entities in the U.S. and other countries. The officials include Hamid Reza Lashgarian, Mahdi Lashgarian, Hamid Homayunfal, Milad Mansuri, Mohammad Bagher Shirinkar, and Reza Mohammad Amin