Latest Cybersecurity News and Articles


Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines

29 January 2024
Cybersecurity researchers have identified malicious packages on the open-source Python Package Index (PyPI) repository that deliver an information stealing malware called WhiteSnake Stealer on Windows systems. The malware-laced packages are named nigpal, figflix, telerer, seGMM, fbdebug, sGMM, myGens, NewGends, and TestLibs111. They have been uploaded by a threat actor named "WS." "These

Update: Nearly 800 GoAnywhere Instances are Unpatched, Exposed to Critical CVE

27 January 2024
The majority of GoAnywhere MFT admin interfaces running on default port settings are hosted in the U.S., with more than 3 in 5 publicly exposed instances hosted on cloud networks operated by Amazon, Microsoft, and Google.

Therapy Provider Notifying 4 Million Patients of PJ&A Hack

27 January 2024
The breach has impacted at least 14 million patients across various organizations. The hack prompted a warning from New York's attorney general about potential identity theft and fraud risks.

AllaKore RAT Malware Targeting Mexican Firms with Financial Fraud Tricks

27 January 2024
Mexican financial institutions are under the radar of a new spear-phishing campaign that delivers a modified version of an open-source remote access trojan called AllaKore RAT. The BlackBerry Research and Intelligence Team attributed the activity to an unknown Latin American-based financially motivated threat actor. The campaign has been active since at least 2021. "Lures use Mexican Social

Pegasus Spyware Targets Togolese Journalists' Mobile Devices

27 January 2024
The spyware intrusions occurred on the phones of multiple journalists, including the publisher of an independent weekly paper, raising concerns about press freedom and privacy violations in the country.

Update: Akira Ransomware Gang Says It Stole Passport Scans From Lush

27 January 2024
The Akira ransomware gang has claimed responsibility for a cybersecurity incident at a British bath bomb merchant. They have stolen 110 GB of data, including personal documents such as passport scans, from the global cosmetics giant.

Mexican Banks and Cryptocurrency Platforms Targeted With AllaKore RAT

26 January 2024
A financially motivated threat actor based in Latin America is targeting large Mexican companies with custom packaged installers delivering a modified version of AllaKore RAT for financial fraud.

Data Privacy Day 2024: Security leaders share AI concerns

26 January 2024
With the ever-changing threat landscape, Data Privacy Day looks a little different each year as technology such as artificial intelligence develops.

iPhone Apps Abuse iOS Push Notifications to Collect User Data

26 January 2024
Many apps abuse the background processing feature to transmit device data to their servers, potentially enabling fingerprinting and persistent tracking, which is strictly prohibited in iOS.

Microsoft Warns of Widening APT29 Espionage Attacks Targeting Global Firms

26 January 2024
The threat actor, known as APT29 or BlueBravo, uses diverse methods including compromised accounts, OAuth applications, and password spraying to gain and maintain access, making traditional indicators of compromise-based detection ineffective.

Who is Alleged Medibank Hacker Aleksandr Ermakov?

26 January 2024
Authorities in Australia, the United Kingdom and the United States this week levied financial sanctions against a Russian man accused of stealing data on nearly 10 million customers of the Australian health insurance giant Medibank. 33-year-old Aleksandr Ermakov allegedly stole and leaked the Medibank data while working with one of Russia's most destructive ransomware groups, but little more is shared about the accused. Here's a closer look at the activities of Mr. Ermakov's alleged hacker handles.

Abu Dhabi Investment Firm Warns About Scam Efforts

26 January 2024
The National Investor in Abu Dhabi has issued a warning about fraudulent investment schemes misusing its name, logo, and employees' identities to solicit personal and financial information.

Update: Hackers Stole Raw Genotype Data, Health Reports in 23andMe Data Breach

26 January 2024
The stolen data includes raw genotype data, health reports, and information from DNA Relatives and Family Tree profiles, potentially exposing personal and ancestral information of affected customers.

40% of litigators say data privacy disputes increased in 2023

26 January 2024
Growing cybersecurity and data privacy concerns have influenced recent litigation, according to a recent survey by Norton Rose Fulbright.

Feds Warn Healthcare Sector of ConnectWise ScreenConnect Threats

26 January 2024
Federal authorities warn that a self-hosted version of ConnectWise's ScreenConnect remote access tool was compromised at a large pharmacy services firm, posing a significant risk to other healthcare organizations.

Hackers Target WordPress Database Plugin Active on One Million Sites

26 January 2024
The vulnerability, tracked as CVE-2023-6933, allows unauthenticated attackers to inject a PHP object, potentially leading to code execution, data access, file manipulation, or denial of service.

Malicious Ads for Restricted Messaging Applications Target Chinese Users

26 January 2024
A campaign of malicious ads is targeting Chinese-speaking users with lures for popular messaging applications like Telegram and LINE, despite the fact that these apps are heavily restricted or banned in China.

Critical Cisco Flaw Lets Hackers Remotely Take Over Unified Comms Systems

26 January 2024
Admins are advised to implement access control lists (ACLs) as a mitigation strategy and evaluate their impact before deployment, while Cisco is not aware of any public announcements or malicious use of the vulnerability.

Pakistan-based Threat Actor Targets Indians with Fake Loan Android Application

26 January 2024
These actors create fake loan apps, obtain personal details through a KYC process, and then extort money by threatening to distribute manipulated photos. The apps exploit minimal permissions to avoid detection.

US Data Compromises Surged to Record High in 2023

26 January 2024
The number of data compromises in the U.S. reached a record high in 2023, impacting over 353 million victims, with a 78% increase from the previous year, according to the Identity Theft Resource Center’s annual data breach report.