Latest Cybersecurity News and Articles


Protect AI Acquires Laiyer AI to Better Secure AI Models

01 February 2024
The acquisition will enable organizations to benefit from Laiyer AI's LLM Guard software, which detects, redacts, and sanitizes inputs and outputs from LLMs with lower latency, while also supporting open source contributions.

Does CVSS 4.0 Solve the Exploitability Problem?

01 February 2024
The new system introduces changes such as splitting attack complexity into two parameters and categorizing user interaction into three levels, offering a more nuanced and comprehensive assessment of vulnerabilities.

Arrests in $400M SIM-Swap Tied to Heist at FTX?

01 February 2024
Three Americans were charged this week with stealing more than $400 million in a November 2022 SIM-swapping attack. The U.S. government did not name the victim organization, but there is every indication that the money was stolen from the now-defunct cryptocurrency exchange FTX, which had just filed for bankruptcy on that same day.

Europcar Denies Data Breach of 50 Million Users, Says Data is Fake

01 February 2024
Security researchers suggest that the fake data may not have been generated using artificial intelligence, as claimed, but rather through existing projects that can create realistic-looking data.

Incognia Raises $31M in Series B Funding

01 February 2024
Incognia, a San Jose-based company specializing in location identity solutions, has raised $31M in Series B funding led by Bessemer Venture Partners, with participation from FJ Labs and existing investors.

Zero-Day Vulnerability can Blind Defenses Relying on Windows Event Logs

01 February 2024
The vulnerability can be leveraged by an attacker with local network access, and until Microsoft issues a patch, users can implement micropatches provided by Acros to mitigate the risk.

Aim Security Raises $10M for its GenAI Security Platform

01 February 2024
Tel Aviv-based Aim Security has raised $10 million in seed funding for its new GenAI security platform, led by YL Ventures and including participation from Cyber Club London and angel investors.

Exploit Released for Android Local Elevation Flaw Impacting Seven OEMs

01 February 2024
A local privilege elevation flaw (CVE-2023-45779) affecting several Android OEMs was discovered and addressed in the December 2023 security update, highlighting weaknesses in APEX module signing using test keys.

US Charges Two More Suspects With DraftKings Account Hacks

01 February 2024
The defendants used credential stuffing techniques to compromise accounts, sell access to them, and devised a method for buyers to withdraw funds, resulting in millions of dollars in illicit gains.

Global Affairs Canada Hit by Cyberattack, Shuts Down Computer Systems to Fix

01 February 2024
The Foreign Ministry of Canada has been hit by a cyberattack, leading to the closure of remote access to its network. Hackers gained access to personal data, and experts suspect a foreign country, possibly Russia or China, to be behind the attack.

Hackers Obtain Confidential Information on Romanian Officials After Cyberattack at Parliament

01 February 2024
Hackers breached the Romanian Chamber of Deputies' database and obtained confidential information, including the prime minister's identity documents and medical analyses. They threatened to release the data unless they received a ransom of $34,000.

FritzFrog Returns with Log4Shell and PwnKit, Spreading Malware Inside Your Network

01 February 2024
The threat actor behind a peer-to-peer (P2P) botnet known as FritzFrog has made a return with a new variant that leverages the Log4Shell vulnerability to propagate internally within an already compromised network. "The vulnerability is exploited in a brute-force manner that attempts to target as many vulnerable Java applications as possible," web infrastructure and security

Pentagon Investigating Theft of Sensitive Files by Ransomware Group

01 February 2024
The Department of Defense is investigating claims by the ransomware group ALPHV that they have stolen sensitive data related to the U.S. military, including information from the Defense Counterintelligence and Security Agency.

Italian Data Protection Watchdog Accuses ChatGPT of Privacy Violations

01 February 2024
The Italian data protection authority has notified OpenAI, the maker of ChatGPT, of potential violations of the EU's GDPR privacy laws. The issues include collecting personal data, age protections, and potential exposure of sensitive information.

The Rise of Python-Scripted Ransomware

01 February 2024
The ransomware, named "grinchv3," self-copies itself to the startup folder for persistence, encrypts user data using the Fernet symmetric key encryption algorithm, and adds a pop-up message after encryption.

Update: Johnson Controls Reports $27M Hit From Ransomware Attack

01 February 2024
The company's ongoing investigation and remediation efforts are focused on containing the unauthorized activity and assessing the impact on data, with no observed evidence of impact on its digital products and solutions.

HeadCrab 2.0 Goes Fileless, Targeting Redis Servers for Crypto Mining

01 February 2024
The new version, HeadCrab 2.0, employs advanced evasion techniques and uses the Redis MGET command for command-and-control communications, making it more difficult to detect.

71% of businesses haven’t incorporated AI into physical security

01 February 2024
A new report reveals that 71% of businesses surveyed have not integrated artificial intelligence (AI) into their security strategy while 23% don’t know if they’re using AI.

Exposed Docker APIs Under Attack in 'Commando Cat' Cryptojacking Campaign

01 February 2024
Exposed Docker API endpoints over the internet are under assault from a sophisticated cryptojacking campaign called Commando Cat. "The campaign deploys a benign container generated using the Commando project," Cado security researchers Nate Bill and Matt Muir said in a new report published today. "The attacker escapes this container and runs multiple payloads on the

Women in Security nominations close in one month

01 February 2024
There is one month left to nominate colleagues and peers for Security magazine's Women in Security award program by the March 1 deadline.