Latest Cybersecurity News and Articles


The SEC Won't Let CISOs Be: Understanding New SaaS Cybersecurity Rules

31 January 2024
The SEC isn’t giving SaaS a free pass. Applicable public companies, known as “registrants,” are now subject to cyber incident disclosure and cybersecurity readiness requirements for data stored in SaaS systems, along with the 3rd and 4th party apps connected to them.  The new cybersecurity mandates make no distinction between data exposed in a breach that was stored on-premise, in the

Fulton County Cyberattack Brings Down Phones, Court Site and Tax Systems

31 January 2024
An ongoing cyberattack against Georgia’s Fulton County, which includes parts of Atlanta, has brought some of the government’s systems to a standstill, halting access to court filings, tax processing, and other services.

Online Ransomware Decryptor Helps Recover Partially Encrypted Files

31 January 2024
White Phoenix attempts to recover data through automated restoration methods and may help restore valuable files for ransomware victims, providing a potential option for those affected by certain ransomware strains.

Alpha Ransomware Group Launches Data Leak Site on the Dark Web

31 January 2024
The ransomware appends a random 8-character alphanumeric extension to encrypted files and its DLS, titled “MYDATA,” is considered unstable and frequently offline, indicating the group is still in the process of setting up operations.

New Glibc Flaw Grants Attackers Root Access on Major Linux Distros

31 January 2024
The __vsyslog_internal() function in glibc has also been found to contain two more flaws (CVE-2023-6779 and CVE-2023-6780) and a separate bug in the qsort() function, affecting all glibc versions since 1992.

Chinese Hackers Exploiting VPN Flaws to Deploy KrustyLoader Malware

31 January 2024
A pair of recently disclosed zero-day flaws in Ivanti Connect Secure (ICS) virtual private network (VPN) devices have been exploited to deliver a Rust-based payload called KrustyLoader that's used to drop the open-source Sliver adversary simulation tool. The security vulnerabilities, tracked as CVE-2023-46805 (CVSS score: 8.2) and CVE-2024-21887 (CVSS score: 9.1), could be abused

Critical Workspace Creation Flaw in GitLab Allows File Overwrite

31 January 2024
The latest update also addressed four medium-severity flaws, including issues related to regular expression denial-of-service, HTML injection, and disclosure of user's public email address via the tags RSS feed.

Israeli Government Says Smallest of SMBs Hit Hardest in Cyberattacks

31 January 2024
Businesses with five to 20 employees were the most impacted, especially those in the industrial sector. The field of commerce reported the fewest cyberattacks, with only 3% of businesses being affected.

China-Linked Hackers Target Myanmar's Top Ministries with Backdoor Blitz

31 January 2024
The Mustang Panda group utilized legitimate software and phishing emails to deploy malicious DLLs and backdoors, disguising command-and-control traffic as Microsoft update traffic.

New Glibc Flaw Grants Attackers Root Access on Major Linux Distros

31 January 2024
Malicious local attackers can obtain full root access on Linux machines by taking advantage of a newly disclosed security flaw in the GNU C library (aka glibc). Tracked as CVE-2023-6246, the heap-based buffer overflow vulnerability is rooted in glibc's __vsyslog_internal() function, which is used by syslog() and vsyslog() for system logging purposes. It's said to have been accidentally

OpenAI Says Mysterious Chat Histories Resulted From Account Takeover

31 January 2024
ChatGPT users' private conversations were leaked due to unauthorized logins from a different location, highlighting the need for better security measures such as 2FA and IP tracking.

Chloé Messdaghi appointed Head of Threat Intelligence at HiddenLayer

30 January 2024
Chloé Messdaghi has been appointed Head of Threat Intelligence at HiddenLayer. Messdaghi is focused on sharing the latest security for AI research.

Fla. Man Charged in SIM-Swapping Spree is Key Suspect in Hacker Groups Oktapus, Scattered Spider

30 January 2024
On Jan. 9, 2024, U.S. authorities arrested a 19-year-old Florida man charged with wire fraud, aggravated identity theft, and conspiring with others to use SIM-swapping to steal cryptocurrency. Sources close to the investigation tell KrebsOnSecurity the accused was a key member of a criminal hacking group blamed for a string of cyber intrusions at major U.S. technology companies during the summer of 2022.

2023 witnessed 68% more ransomware attacks than 2022

30 January 2024
According to a report, while Q4 ransomware attacks were down slightly from Q3 2023, ransomware activity for the year surpassed 2022 totals by 68%.

Brazilian Feds Dismantle Grandoreiro Banking Trojan, Arresting Top Operatives

30 January 2024
A Brazilian law enforcement operation has led to the arrest of several Brazilian operators in charge of the Grandoreiro malware. The Federal Police of Brazil said it served five temporary arrest warrants and 13 search and seizure warrants in the states of São Paulo, Santa Catarina, Pará, Goiás, and Mato Grosso. Slovak cybersecurity firm ESET, which provided additional

Threat Actors Selling 1.8TB Database of 750 Million Indian Mobile Users

30 January 2024
The compromised database is being sold on hacker forums, with two cybercrime groups offering the data for sale, highlighting the growing threat posed by emerging threat groups like CYBO CREW and its affiliates.

URGENT: Upgrade GitLab - Critical Workspace Creation Flaw Allows File Overwrite

30 January 2024
GitLab once again released fixes to address a critical security flaw in its Community Edition (CE) and Enterprise Edition (EE) that could be exploited to write arbitrary files while creating a workspace. Tracked as CVE-2024-0402, the vulnerability has a CVSS score of 9.9 out of a maximum of 10. "An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to

Hundreds of Network Operators’ Credentials Found Circulating in Dark Web

30 January 2024
A significant number of network administrators and IT personnel were found to have their credentials compromised, highlighting the vulnerability of staff involved in network engineering and IT management operations.

Dynatrace Acquires Runecast to Improve Cloud-Native Security

30 January 2024
Dynatrace's acquisition of Runecast will enhance its platform with AI-powered security posture management for proactive risk mitigation and real-time vulnerability assessments in hybrid and multicloud environments.

There was a 39% surge in data exfiltration cyberattacks in 2023

30 January 2024
According to a report, the number of organizations claiming to have been a victim of ransomware in the past 12 months more than doubled.