Latest Cybersecurity News and Articles
18 January 2024
Attribute-based encryption (ABE) offers fine-grained access to data, revolutionizing data protection and access control. ABE has diverse real-world applications, from privacy protection in surveillance videos to securing electronic medical records.
18 January 2024
Continuous integration and continuous delivery (CI/CD) misconfigurations discovered in the open-source TensorFlow machine learning framework could have been exploited to orchestrate supply chain attacks.
The misconfigurations could be abused by an attacker to "conduct a supply chain compromise of TensorFlow releases on GitHub and PyPi by compromising TensorFlow's build agents via
18 January 2024
A security researcher Eaton Zveare discovered a misconfigured server belonging to Toyota Tsusho Insurance Broker India (TTIBI), which exposed over 650,000 Microsoft-hosted email messages.
18 January 2024
The U.S. Cybersecurity and Infrastructure Security Agency and the FBI are warning critical infrastructure owners about the potential security risks posed by Chinese-manufactured unmanned aircraft systems (UAS).
18 January 2024
The presence of spyware, such as Pegasus, Predator, and Reign, can be identified by examining the Shutdown.log file for anomalous log entries related to processes delaying the reboot.
18 January 2024
In today's digital landscape, traditional password-only authentication systems have proven to be vulnerable to a wide range of cyberattacks. To safeguard critical business resources, organizations are increasingly turning to multi-factor authentication (MFA) as a more robust security measure. MFA requires users to provide multiple authentication factors to verify their identity, providing an
18 January 2024
A massive data tranch containing nearly 71 million unique credentials, including 25 million previously unseen passwords, has been circulating on the internet for at least four months.
18 January 2024
The malware tools used by Bigpanzi, including 'pandoraspear' and 'pcdn,' enable the cybercriminals to hijack DNS settings, establish C2 communication, build a peer-to-peer CDN, and execute DDoS attacks on infected devices.
18 January 2024
The breach involved sensitive data such as financial details, SSNs, and health-related information. While there is no evidence of identity theft or financial fraud, the firm is taking precautionary measures and offering support to affected people.
18 January 2024
This nonbinding consortium aims to assist privacy investigators worldwide and facilitate seamless collaboration in law enforcement investigations and actions involving privacy and data security.
18 January 2024
The group's latest intrusion set involves using lures related to the Israel-Hamas war, sending malicious links disguised as innocuous emails, and utilizing breached accounts to build trust with targets.
18 January 2024
Multiple security vulnerabilities have been disclosed in the TCP/IP network protocol stack of an open-source reference implementation of the Unified Extensible Firmware Interface (UEFI) specification used widely in modern computers.
Collectively dubbed PixieFail by Quarkslab, the nine issues reside in the TianoCore EFI Development Kit II (EDK II) and could be exploited to
18 January 2024
The financial services industry has seen a significant increase in Vendor Email Compromise (VEC) and Business Email Compromise (BEC) attacks, with VEC attacks causing millions of dollars in losses.
18 January 2024
The malware used in the campaign, a variant of Go Stealer, targets browsers like Firefox, Chrome, Edge, and Brave, and uses Slack for data exfiltration to blend in with regular business traffic.
18 January 2024
The National Bank of Angola is trying to reassure the country that its financial system is secure following a cyberattack on January 6. No hacking group has taken credit for the incident.
18 January 2024
A cyberattack on the Canadian energy producer Clearview Resources Ltd resulted in a US$1.5 million financial loss. The attack involved the compromise of an internal email address, leading to the redirection of company funds to a third-party account.
17 January 2024
High-profile individuals working on Middle Eastern affairs at universities and research organizations in Belgium, France, Gaza, Israel, the U.K., and the U.S. have been targeted by an Iranian cyber espionage group called Mind Sandstorm since November 2023.
The threat actor "used bespoke phishing lures in an attempt to socially engineer targets into downloading malicious files," the
17 January 2024
The PoS terminals from PAX Technology, based on Android, are found to have several vulnerabilities that can be exploited to execute arbitrary code or commands, according to a report by STM Cyber.
17 January 2024
The rapper and social media personality Punchmade Dev is perhaps best known for his flashy videos singing the praises of a cybercrime lifestyle. With memorable hits such as "Internet Swiping" and "Million Dollar Criminal" earning millions of views, Punchmade has leveraged his considerable following to peddle tutorials on how to commit financial crimes online. But until recently, there wasn't much to support a conclusion that Punchmade was actually doing the cybercrime things he promotes in his songs.
17 January 2024
A Russian tech student faces treason charges for allegedly helping Ukrainian hackers carry out cyberattacks against Russia, revealing the ongoing cyberwar between the two countries.