Latest Cybersecurity News and Articles


Apple Issues Patch for Critical Zero-Day in iPhones, Macs - Update Now

23 January 2024
The vulnerability, tracked as CVE-2024-23222, is a type confusion bug in the WebKit browser engine that could lead to arbitrary code execution when processing malicious web content.

North Korean ScarCruft Attackers Gear Up to Target Cybersecurity Professionals

23 January 2024
The group is testing innovative infection routines that use technical threat research on another North Korean APT group, Kimsuky, as a lure, indicating a new approach to their cyberattacks.

New Method To Safeguard Against Mobile Account Takeovers

23 January 2024
The method involves modeling how account access changes as devices, SIM cards, or apps are disconnected from the account ecosystem, providing insights into complex hacking attacks.

Historic Data Leak Reveals 26 Billion Records From Tencent, Weibo, Twitter, Adobe, and Others

23 January 2024
The leaked information spans across various companies, organizations, and government agencies globally. The potential impact on consumers is significant, as the leaked data could be used for credential-stuffing attacks and spear-phishing.

"Activator" Alert: MacOS Malware Hides in Cracked Apps, Targeting Crypto Wallets

23 January 2024
Cracked software have been observed infecting Apple macOS users with a previously undocumented stealer malware capable of harvesting system information and cryptocurrency wallet data. Kaspersky, which identified the artifacts in the wild, said they are designed to target machines running macOS Ventura 13.6 and later, indicating the malware's ability to infect Macs on both Intel and

Lack of Understanding, Underfunding Threaten Data Privacy & Compliance

23 January 2024
A lack of understanding combined with budgetary squeezes are significant obstacles for organization's navigating data privacy and compliance with data protection laws, according to industry body ISACA.

NS-STEALER Uses Discord Bots to Exfiltrate Your Secrets from Popular Browsers

23 January 2024
The malware exfiltrates sensitive information including screenshots, cookies, autofill credentials, system info, installed programs, tokens, and sessions, and uploads the collected data to a Discord bot channel.

From Megabits to Terabits: Gcore Radar Warns of a New Era of DDoS Attacks

23 January 2024
As we enter 2024, Gcore has released its latest Gcore Radar report, a twice-annual publication in which the company releases internal analytics to track DDoS attacks. Gcore’s broad, internationally distributed network of scrubbing centers allows them to follow attack trends over time. Read on to learn about DDoS attack trends for Q3–Q4 of 2023, and what they mean for developing a robust

Israel, Czech Republic Reinforce Cyber Partnership Amid Hamas War

23 January 2024
The agreement will facilitate the sharing of information and experience between the Israel National Cyber Directorate and the Czech National Cyber and Information Security Agency, including the possibility of internships.

Trezor Support Site Breach Exposes Personal Data of 66,000 Customers

23 January 2024
While no evidence of compromised digital assets has been found, 66,000 users' names, usernames, and email addresses may have been exposed. Unfortunately, attackers have exploited this data to trick some users into giving away their recovery seeds.

Finland: Prosecutors Add to Evidence Against Alleged Vastaamo Hacker

23 January 2024
Prosecutors have traced the cryptocurrency wallet used for extortion to the bank account of Aleksanteri Kivimäki, the accused in the psychotherapy clinic data breach case.

BreachForums Founder Sentenced to 20 Years of Supervised Release, No Jail Time

23 January 2024
Conor Brian Fitzpatrick has been sentenced to time served and 20 years of supervised release for his role as the creator and administrator of BreachForums. Fitzpatrick, who went by the online alias "pompompurin," was arrested in March 2023 in New York and was subsequently charged with conspiracy to commit access device fraud and possession of child pornography. He was later released on a $

MavenGate Attack Could Let Hackers Hijack Java and Android via Abandoned Libraries

23 January 2024
The attack method involves exploiting vulnerabilities in default build configurations and targeting abandoned libraries in public repositories through domain name purchases, making it difficult to detect and prevent.

SEC Says X Account Hack was Due to SIM Swapping

23 January 2024
The Securities and Exchange Commission (SEC) experienced an account takeover on Twitter due to a SIM swap attack, where the unauthorized party gained control of the SEC's cell phone number.

~40,000 Attacks in 3 Days: Critical Confluence RCE Under Active Exploitation

23 January 2024
Malicious actors have begun to actively exploit a recently disclosed critical security flaw impacting Atlassian Confluence Data Center and Confluence Server, within three days of public disclosure. Tracked as CVE-2023-22527 (CVSS score: 10.0), the vulnerability impacts out-of-date versions of the software, allowing unauthenticated attackers to achieve remote code execution on susceptible

New Chae$ 4.1 Malware Hides in Driver Downloads

23 January 2024
The infection chain begins with deceptive emails and websites, ultimately leading to the activation of the Chae$ 4.1 malware, highlighting the importance of cautious online behavior.

Australia Sanctions Russian it Says Hacked Health Insurer

23 January 2024
Australia has used its significant cyber incidents sanctions regime for the first time against a Russian individual named Aleksandr Gennadievich Ermakov, who is linked to the 2022 cyber attack on health insurer Medibank Private.

Info Stealing Packages Hidden in PyPI

23 January 2024
Malicious Python packages on PyPI, such as nigpal, figflix, and seGMM, have been identified, with payloads designed to steal sensitive information from victims' devices, particularly targeting Windows users.

Thai Court Blocks 9near.org to Avoid Exposure of 55M Citizens

23 January 2024
The Criminal Court in Thailand has ordered the blocking of the website 9near.org, which claimed to have accessed the personal information of 55 million Thai citizens from vaccine registration records.

Bulletproof Hosting: A Critical Cybercriminal Service

23 January 2024
Bulletproof hosting (BPH) providers operate in a complex and persistent manner, making it challenging for defenders to permanently shut them down. Blocking BPH providers can effectively disrupt malicious activities early in the kill chain.