Latest Cybersecurity News and Articles
15 January 2024
The ransomware industry surged in 2023 as it saw an alarming 55.5% increase in victims worldwide, reaching a staggering 4,368 cases.
Figure 1: Year over year victims per quarter
The rollercoaster ride from explosive growth in 2021 to a momentary dip in 2022 was just a teaser—2023 roared back with the same fervor as 2021, propelling existing groups and ushering in a wave of formidable
15 January 2024
Cybersecurity researchers have disclosed a security flaw in the Opera web browser for Microsoft Windows and Apple macOS that could be exploited to execute any file on the underlying operating system.
The remote code execution vulnerability has been codenamed MyFlaw by the Guardio Labs research team owing to the fact that it takes advantage of a feature called My Flow that makes it
15 January 2024
The Azorult malware, known for stealing sensitive data, has resurfaced with a sophisticated approach. It is distributed through malicious PDF files that contain a shortcut file.
15 January 2024
The environmental services industry experienced an alarming surge in HTTP-based DDoS attacks during COP 28, highlighting the increasing intersection between environmental issues and cyber security.
15 January 2024
Microsoft has announced that it will store all customer data in the European Union (EU) rather than transferring it abroad. This move is aimed at complying with varying privacy regulations across jurisdictions.
15 January 2024
Insider actions and human error account for the majority of data breaches in UK law firms, emphasizing the need for robust cybersecurity measures to protect sensitive information.
15 January 2024
The Beijing Wangshendongjian Judicial Appraisal Institute Institute's claim that AirDrop's anonymization techniques can be easily circumvented raises concerns about the vulnerability of user identities and the potential for surveillance.
15 January 2024
Amazon is challenging a significant privacy fine imposed by the Luxembourg data protection authority, accusing them of attacking the company based on unfounded allegations.
15 January 2024
The exposed data includes high-resolution passport images, travel visa certificates, and itinerary or ticket files, putting the affected individuals at risk of identity theft and fraud.
15 January 2024
The CISA's ICS advisories highlight high and critical severity vulnerabilities in products from companies like Rapid Software, Horner Automation, Schneider Electric, and Siemens.
15 January 2024
The FCC is requesting detailed information from auto manufacturers and wireless providers on how they support survivors, handle geolocation data, and comply with the Safe Connections Act.
15 January 2024
AgentTesla, also known as OriginLogger, is a prevalent commodity malware that steals sensitive information from Windows systems. It is commonly distributed via email attachments and has been a persistent threat since 2014.
15 January 2024
Funding shortfalls and aging IT infrastructure contribute to poor cybersecurity in the water and wastewater sector, which is operated mainly by municipal and county governments.
15 January 2024
A 29-year-old man in Ukraine was arrested for using hacked accounts to create 1 million virtual servers and mine $2 million in cryptocurrency, highlighting the growing threat of cryptojacking.
15 January 2024
Businesses and cybersecurity professionals must prioritize understanding the intricacies of identity and access management (IAM) in a cloud-dominated era to ensure a robust security posture.
15 January 2024
Multiple security vulnerabilities have been disclosed in Bosch BCC100 thermostats and Rexroth NXA015S-36V-B smart nutrunners that, if successfully exploited, could allow attackers to execute arbitrary code on affected systems.
Romanian cybersecurity firm Bitdefender, which discovered the flaw in Bosch BCC100 thermostats last August, said the issue could be weaponized by an attacker to
15 January 2024
Apple has released a firmware update for its Magic Keyboard to address a recently discovered vulnerability that allows an attacker with physical access to the keyboard to extract its Bluetooth pairing key and spy on Bluetooth traffic.
15 January 2024
Thousands of WordPress sites using a vulnerable version of the Popup Builder plugin have been compromised with a malware called Balada Injector.
First documented by Doctor Web in January 2023, the campaign takes place in a series of periodic attack waves, weaponizing security flaws WordPress plugins to inject backdoor designed to redirect visitors of infected sites to bogus tech
15 January 2024
The vulnerability, rated 9.8 on the CVSS scoring system, could allow an unauthenticated attacker to cause a Denial-of-Service (DoS) or execute remote code with root privileges.
15 January 2024
Multiple breaches have resulted in the leak of millions of voter records, including personally identifiable information, which could be used for targeted information warfare campaigns during the election and beyond.