Latest Cybersecurity News and Articles
01 February 2024
Faction is an open-source solution designed to streamline penetration testing report generation and assessment collaboration, aiming to save time, reduce stress, and improve information security workflows.
01 February 2024
The proposed regulation would impose compliance costs on IaaS providers, including data retention and record-keeping requirements, potentially costing up to $170 million annually for affected companies.
01 February 2024
The leak included passports, player contracts, and personal data, potentially affecting every Australian football fan. Cybersecurity experts believe the breach was likely due to human error, and the FA is investigating the matter.
01 February 2024
The U.S. government on Wednesday said it took steps to neutralize a botnet comprising hundreds of U.S.-based small office and home office (SOHO) routers hijacked by a China-linked state-sponsored threat actor called Volt Typhoon and blunt the impact posed by the hacking campaign.
The existence of the botnet, dubbed KV-botnet, was first disclosed by the Black Lotus Labs team at
01 February 2024
The U.S. government has observed a decrease in scam-oriented international robocalls reaching Americans, indicating improved efforts by telecom gateway providers to block fraudulent voice-call spamming.
01 February 2024
Cybersecurity researchers have detailed an updated version of the malware HeadCrab that's known to target Redis database servers across the world since early September 2021.
The development, which comes exactly a year after the malware was first publicly disclosed by Aqua, is a sign that the financially-motivated threat actor behind the campaign is actively adapting and
01 February 2024
How’s your vulnerability management program doing? Is it effective? A success? Let’s be honest, without the right metrics or analytics, how can you tell how well you’re doing, progressing, or if you’re getting ROI? If you’re not measuring, how do you know it’s working?
And even if you are measuring, faulty reporting or focusing on the wrong metrics can create blind spots and make it harder to
01 February 2024
Chris Larsen's personal XRP accounts were compromised, but Ripple was not impacted. The fraudulent activity was quickly detected, and the affected address was frozen with the help of other exchanges.
01 February 2024
While the financial impact on Progress Software from the MOVEit zero-day vulnerability has been minimal so far, the firm is still dealing with 118 class-action lawsuits and formal government investigations, including subpoenas from the SEC and FTC.
01 February 2024
Ivanti has discovered two new vulnerabilities in its Policy Secure and Connect Secure VPN products, impacting U.S. government and other industries. One is an unauthorized access issue, while the other allows privilege escalation.
01 February 2024
According to Corvus, the number of active ransomware groups grew by 34% between Q1 and Q4 2023, linked to the fracturing of well-known ransomware groups that leaked their proprietary encryptors.
01 February 2024
Vulnerabilities in container engine components, dubbed "Leaky Vessels," pose a serious threat by allowing attackers to break out of containers and execute malicious actions on the underlying host system.
01 February 2024
The expanding supply chain vulnerabilities and digital transformation are increasing the risk of data breaches in 2024. Threat actors may target rare earth material supply chains and leverage small-scale data manipulation for major impact.
01 February 2024

Findings suggest Jordan is relying on cyberweapon to quash dissent and its use is ‘staggeringly widespread’About three dozen journalists, lawyers and human rights workers in Jordan have been targeted by authorities using powerful spyware made by Israel’s NSO Group amid a broad crackdown on press freedoms and political participation, according to a report by the lobbying group Access Now.The information suggests the Jordanian government has used the Israeli cyberweapon against members of civil society, including at least one American citizen living in Jordan, between 2019 and September 2023. Continue reading...
01 February 2024
The flaw allows attackers with arbitrary read and write capability to bypass Pointer Authentication, and it's recommended that Federal Civilian Executive Branch (FCEB) agencies apply the fixes by February 21, 2024.
01 February 2024
The lawsuit from the New York Attorney General claims that the bank lacks sufficient security measures to prevent unauthorized transfers and fails to respond effectively when red flags are raised.
01 February 2024
The threat actors behind the Nitrogen campaign prefer hosting their payloads on compromised WordPress sites and have a known connection to ransomware, making it a serious threat to businesses.
01 February 2024
The Grandoreiro malware can track keyboard inputs, simulate mouse activity, and initiate communication with criminals’ servers, making it a potent threat to banking activities.
01 February 2024
Google-owned Mandiant said it identified new malware employed by a China-nexus espionage threat actor known as UNC5221 and other threat groups during post-exploitation activity targeting Ivanti Connect Secure VPN and Policy Secure devices.
This includes custom web shells such as BUSHWALK, CHAINLINE, FRAMESTING, and a variant of LIGHTWIRE.
"CHAINLINE is a Python web shell backdoor that is
01 February 2024
The Network Contagion Research Institute (NCRI) has found that teenagers from Western English-speaking countries are increasingly targeted by financial sextortion attacks conducted by Nigeria-based cybercriminals, known as 'Yahoo Boys.'