Latest Cybersecurity News and Articles


There was a 151% increase in government vulnerability submissions

29 January 2024
According to a recent report, government industries saw a 151% increase in vulnerability submissions in 2023, making it the fastest growing sector.

Bastille Raises $44M Series C Investment Led by Goldman Sachs Asset Management

29 January 2024
Bastille Networks, Inc. has secured a $44 million Series C investment led by Growth Equity at Goldman Sachs Asset Management, with participation from existing investor Bessemer Venture Partners.

Data Theft Plaguing K-12 Schools After Holiday Season Attacks

29 January 2024
Ransomware attacks have affected schools like Ohio’s Groveport Madison Schools, causing disruptions to internet access and damage to devices, but efforts to restore systems and minimize data theft have been successful.

New Ransomware Gangs Rise Using Rust and Golang Programming Languages

29 January 2024
New ransomware families like Albabat, Kasseika, and Kuiper are gaining traction, with Kuiper being attributed to a threat actor named RobinHood and leveraging the concurrency-focused nature of Golang.

Researchers Uncover How Outlook Vulnerability Could Leak Your NTLM Passwords

29 January 2024
A now-patched security flaw in Microsoft Outlook could be exploited by threat actors to access NT LAN Manager (NTLM) v2 hashed passwords when opening a specially crafted file. The issue, tracked as CVE-2023-35636 (CVSS score: 6.5), was addressed by the tech giant as part of its Patch Tuesday updates for December 2023. "In an email attack scenario, an attacker could exploit the

A TrickBot malware developer sentenced to 64 months in prison

29 January 2024
Vladimir Dunaev was extradited to the US in October 2021 and pleaded guilty to charges related to computer fraud and identity theft. He developed malicious tools that aided in data theft and fraud, resulting in millions of dollars in losses.

Saudi Arabia Boosts Railway Cybersecurity

29 January 2024
The railway network, spanning 4,500 kilometers in Saudi Arabia, faces challenges in securing its legacy and modern technologies, especially with the introduction of IoT signaling and communication systems.

Update: In Major Lapse, Hacked Microsoft Test Account was Assigned Admin Privileges

29 January 2024
The hackers who recently broke into Microsoft’s network and monitored top executives’ email for two months did so by gaining access to an aging test account with administrative privileges, a major lapse on the company's part, a researcher said.

493 Companies Share Their SaaS Security Battles – Get Insights in this Webinar

29 January 2024
In today's digital world, security risks are more prevalent than ever, especially when it comes to Software as a Service (SaaS) applications. Did you know that an alarming 97% of companies face serious risks from unsecured SaaS applications?Moreover, about 20% of these organizations are struggling with internal data threats. These statistics aren't just numbers; they're a wake-up call. We're

Who is Alleged Medibank Hacker Aleksandr Ermakov?

29 January 2024
Aleksandr Ermakov, a Russian cybercriminal, has been sanctioned by Australia, the UK, and the US for his alleged involvement in the Medibank data breach and his ties to the REvil ransomware group.

Riding the AI Waves: The Rise of Artificial Intelligence to Combat Cyber Threats

29 January 2024
In nearly every segment of our lives, AI (artificial intelligence) now makes a significant impact: It can deliver better healthcare diagnoses and treatments; detect and reduce the risk of financial fraud; improve inventory management; and serve up the right recommendation for a streaming movie on Friday night. However, one can also make a strong case that some of AI’s most significant impacts

Albabat, Kasseika, Kuiper: New Ransomware Gangs Rise with Rust and Golang

29 January 2024
Cybersecurity researchers have detected in the wild yet another variant of the Phobos ransomware family known as Faust. Fortinet FortiGuard Labs, which detailed the latest iteration of the ransomware, said it's being propagated by means of an infection that delivers a Microsoft Excel document (.XLAM) containing a VBA script. "The attackers utilized the Gitea service to store several files

Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines

29 January 2024
These packages target Windows systems and Linux hosts, with the Windows payload being a variant of WhiteSnake malware capable of stealing information and executing commands.

Using Google Search to Find Software can be Risky

29 January 2024
Despite Google's efforts to enforce abuse policies and remove malicious ads, cybercrooks are finding new ways to evade detection and continue to lead users to malware-infected websites.

Update: Hack Wiped Two Petabytes of Data From Russian Research Center

29 January 2024
The Ukrainian Ministry of Defense's Main Intelligence Directorate claims that pro-Ukrainian hacktivists breached the Russian Center for Space Hydrometeorology, known as "Planeta," and wiped 2 petabytes of data.

Popular Washington, DC Latino Theater Whole Again After Hack Emptied Accounts

29 January 2024
Hackers stole over $250,000 from the GALA Hispanic Theatre in Washington, D.C. by compromising their bank account in a BEC attack. An accountant was locked out of the system after initiating a wire transfer, and the entire account was emptied.

ScarCruft Returns to Target High-Profile Experts in N.Korea

29 January 2024
SentinelLabs observed a campaign by ScarCruft actors targeting media organizations and high-profile experts in North Korean affairs. As part of the attack, the group impersonated a North Korea Research Institute member, used the RokRAT backdoor, and harvested threat intelligence from their targets. A modern-day TIP providing contextual and operational intelligence by automatically enriching, and correlating the IOCs, shall help organizations protect their network proactively.

Multiple PoC Exploits Released for Jenkins Flaw CVE-2024-23897

29 January 2024
With over 75,000 internet-facing instances of Jenkins vulnerable to exploitation, the availability of PoC exploits is likely to lead to widespread attacks by threat actors.

Another Phobos Ransomware Variant Launches Attack – FAUST

29 January 2024
The FAUST ransomware, a Phobos variant, employs a fileless attack to deploy shellcode, injects the final payload, and creates multiple threads for efficient execution while maintaining exclusion lists to avoid damaging the system.

NSA Admits Secretly Buying Your Internet Browsing Data without Warrants

29 January 2024
The U.S. National Security Agency (NSA) has admitted to buying internet browsing records from data brokers to identify the websites and apps Americans use that would otherwise require a court order, U.S. Senator Ron Wyden said last week. "The U.S. government should not be funding and legitimizing a shady industry whose flagrant violations of Americans' privacy are not just unethical, but illegal