Latest Cybersecurity News and Articles


Ukraine’s Prisoners of War Agency Hit by Cyberattack

30 January 2024
Ukraine's Coordination Headquarters for Prisoners of War faced a DDoS attack, suspected to be linked to the recent crash of a Russian transport plane carrying Ukrainian prisoners and Russian servicemen.

Research shows cybercriminals’ motivation shifts to data exfiltration

30 January 2024
A new report shows ransomware attacks are increasing again and reveals a change in strategy among cybercriminals.

US Aid Office in Colombia Reports Its Facebook Page was Hacked

30 January 2024
The unauthorized access to the USAID Colombia Facebook page posed a potential risk, prompting the agency to actively work on restoring account security and investigating the extent of the breach.

China-Linked Hackers Target Myanmar's Top Ministries with Backdoor Blitz

30 January 2024
The China-based threat actor known as Mustang Panda is suspected to have targeted Myanmar's Ministry of Defence and Foreign Affairs as part of twin campaigns designed to deploy backdoors and remote access trojans. The findings come from CSIRT-CTI, which said the activities took place in November 2023 and January 2024 after artifacts in connection with the attacks were uploaded to the

Mistakenly Published Authentication Token Exposed Mercedes-Benz Source Code

30 January 2024
The exposure was discovered by RedHunt Labs, which found an employee's authentication token in a public GitHub repository. It could be used to access other private repositories containing cloud access keys, design documents, and source code.

Insurance Broker Notifying 1.5 Million of Health Information Hack

30 January 2024
Keenan & Associates, a California insurance broker, is notifying over 1.5 million individuals about a hacking incident in August 2023. The attack compromised personal and health information, including passport numbers and Social Security numbers.

Tech Support Scams Now Use Couriers to Collect Victims’ Money

30 January 2024
The FBI advises against sending gold or other precious metals to legitimate businesses or U.S. government organizations and provides tips to reduce the risk of falling victim to fraud attempts.

Cactus Ransomware Gang Claims the Schneider Electric Hack

30 January 2024
Schneider Electric suffered a data breach from a Cactus ransomware attack, impacting their Sustainability Business division and causing outages on the Resource Advisor cloud platform.

Top Security Posture Vulnerabilities Revealed

30 January 2024
Each New Year introduces a new set of challenges and opportunities for strengthening our cybersecurity posture. It's the nature of the field – the speed at which malicious actors carry out advanced persistent threats brings a constant, evolving battle for cyber resilience. The excitement in cybersecurity lies in this continuous adaptation and learning, always staying one step ahead of potential

Exploring Telegram’s Dark Markets, Breeding Ground for Modern Phishing Operations

30 January 2024
The phishing ecosystem has shifted from exclusive Dark web forums to public Telegram channels, making illicit tools and stolen data easily accessible to both seasoned cybercriminals and newcomers.

Italian Data Protection Watchdog Accuses ChatGPT of Privacy Violations

30 January 2024
Italy's data protection authority (DPA) has notified ChatGPT-maker OpenAI of supposedly violating privacy laws in the region. "The available evidence pointed to the existence of breaches of the provisions contained in the E.U. GDPR [General Data Protection Regulation]," the Garante per la protezione dei dati personali (aka the Garante) said in a statement on Monday. It also said it

New Jersey School District Shut Down by Cyberattack

30 January 2024
The district is working with cybersecurity experts to address the issue, and an investigation is ongoing. The district apologized for the inconvenience, and no further details about the nature of the attack have been released.

Juniper Networks Releases Urgent Junos OS Updates for High-Severity Flaws

30 January 2024
Juniper Networks has released out-of-band updates to address high-severity vulnerabilities in SRX Series and EX Series that could allow threat actors to take control of susceptible systems.

New ZLoader Malware Variant Surfaces with 64-bit Windows Compatibility

30 January 2024
Threat hunters have identified a new campaign that delivers the ZLoader malware, resurfacing nearly two years after the botnet's infrastructure was dismantled in April 2022. A new variant of the malware is said to have been in development since September 2023, Zscaler ThreatLabz said in an analysis published this month. "The new version of Zloader made significant changes to the loader

Ukraine’s Security Service Detains Member of Russian ‘Cyber Army’

30 January 2024
The suspect, a tech specialist from Kharkiv, was recruited by Russian intelligence and is accused of launching DDoS attacks against Ukrainian state websites and leaking strategic information to the Russian military.

Update: Ivanti Connect Secure Zero-Day Patches Delayed

30 January 2024
The vulnerabilities, CVE-2023-46805 and CVE-2024-21887, allow unauthenticated attackers to achieve remote code execution. More than 26,000 Connect Secure hosts were exposed to the public internet, with over 410 hosts compromised.

Longer Passwords Aren’t Safe From Intensive Cracking Efforts

30 January 2024
Hackers exploit weak passwords through dictionary attacks, brute force attacks, and mask attacks, highlighting the importance of strong and unique passwords for every account.

Kansas State, Clackamas Community College Respond to Cyberattacks

30 January 2024
Clackamas Community College experienced disruptions to online platforms and internal systems, leading to the cancellation of classes and financial aid disbursement delays.

Juniper Networks Releases Urgent Junos OS Updates for High-Severity Flaws

30 January 2024
Juniper Networks has released out-of-band updates to address high-severity flaws in SRX Series and EX Series that could be exploited by a threat actor to take control of susceptible systems. The vulnerabilities, tracked as CVE-2024-21619 and CVE-2024-21620, are rooted in the J-Web component and impact all versions of Junos OS. Two other shortcomings, CVE-2023-36846 and

Biden-⁠Harris announce key AI actions following landmark executive order

29 January 2024
Following an executive order aimed to manage the risk of artificial intelligence (AI), the Biden-Harris administration recently announced key AI actions.