Latest Cybersecurity News and Articles


Android’s January 2024 Security Update Patches 58 Vulnerabilities

12 January 2024
Google has released patches for 58 vulnerabilities in the Android platform, including high-severity issues in the Framework and System components. Users are advised to update their devices promptly to protect against potential exploits.

Act Now: CISA Flags Active Exploitation of Microsoft SharePoint Vulnerability

12 January 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security vulnerability impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The issue, tracked as CVE-2023-29357 (CVSS score: 9.8), is a privilege escalation flaw that could be exploited by an attacker to gain

Cybercriminals target critical infrastructure in 2023 cyberattack

11 January 2024
According to a recent Forescout report, the second wave of 2023 Danish energy sector cyberattacks took advantage of unpatched firewalls.

71% of drivers consider buying older cars due to data privacy concerns

11 January 2024
Data privacy within the automotive industry was analyzed in a report, finding that 72% of drivers are uncomfortable automakers sharing their data.

Finland Warns of Akira Ransomware Wiping NAS and Tape Backup Devices

11 January 2024
The NCSC-FI has warned of increased Akira ransomware attacks in December. These attacks targeted companies in Finland and involved wiping backups, making it difficult for victims to recover their data without paying a ransom.

Exploitation of vulnerabilities affecting Ivanti Connect Secure and Ivanti Policy Secure

11 January 2024
Organisations are encouraged to take immediate action to mitigate vulnerabilities affecting Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS) gateways (CVE-2023-46805 and CVE-2024-21887), and follow the latest vendor advice.

New Python-based FBot Hacking Toolkit Aims at Cloud and SaaS Platforms

11 January 2024
A new Python-based hacking tool called FBot has been discovered, targeting web servers, cloud services, content management systems, and SaaS platforms like Amazon Web Services and Microsoft 365.

Chertoff Group Affiliate Completes Trustwave Acquisition

11 January 2024
MC2 Security Fund has completed its acquisition of Trustwave, a managed security services provider, expanding its reach and placing Trustwave in front of Chertoff Group customers in the commercial and public sectors.

Threat Actors Increasingly Abusing GitHub for Malicious Purposes

11 January 2024
The ubiquity of GitHub in information technology (IT) environments has made it a lucrative choice for threat actors to host and deliver malicious payloads and act as dead drop resolvers, command-and-control, and data exfiltration points. “Using GitHub services for malicious infrastructure allows adversaries to blend in with legitimate network traffic, often bypassing traditional security

Fallon Ambulance announces data breach affecting over 900,000 patients

11 January 2024
Fallon Ambulance, a medical transportation company based in Boston, is being investigated for a data breach including patient and employee data.

New PoC Exploit for Apache OfBiz Vulnerability Poses Risk to ERP Systems

11 January 2024
Cybersecurity researchers have developed a proof-of-concept (PoC) code that exploits a recently disclosed critical flaw in the Apache OfBiz open-source Enterprise Resource Planning (ERP) system to execute a memory-resident payload. The vulnerability in question is CVE-2023-51467 (CVSS score: 9.8), a bypass for another severe shortcoming in the same software (

New Python-based FBot Hacking Toolkit Aims at Cloud and SaaS Platforms

11 January 2024
A new Python-based hacking tool called FBot has been uncovered targeting web servers, cloud services, content management systems (CMS), and SaaS platforms such as Amazon Web Services (AWS), Microsoft 365, PayPal, Sendgrid, and Twilio. “Key features include credential harvesting for spamming attacks, AWS account hijacking tools, and functions to enable attacks against PayPal and various

UK: NCSC Publishes Practical Security Guidance for SMBs

11 January 2024
Smaller organizations are increasingly reliant on cloud and online services, making them vulnerable to cyber threats. The guide provides practical advice on choosing the right service, securing user accounts, and recovering from a cyberattack.

Black Basta-Affiliate Spreads Pikabot

11 January 2024
Threat group Water Curupira, known for its Cobalt Strike backdoors, recently transitioned to using Pikabot malware in phishing campaigns. Pikabot witnessed a surge in activity in Q4 2023, potentially serving as a replacement for Qakbot after its takedown. Users must exercise caution with email attachments and verify sender authenticity.

HMG Healthcare Discloses Data Breach Affecting 40 Affiliated Nursing Facilities

11 January 2024
The breach occurred in August 2023 when threat actors gained unauthorized access to a company server and stole unencrypted files containing medical records, personal information, and employment records.

French Hacker From ‘ShinyHunters’ Group Sentenced to Three Years in US Prison

11 January 2024
A 22-year-old French hacker has been sentenced to three years in U.S. federal prison for his involvement in the ShinyHunters hacking group and must pay $5 million in restitution.

Thousands of WordPress Sites with Popup Builder Plugin Compromised by Balada Injector

11 January 2024
A stored XSS flaw in the Popup Builder WordPress plugin has been exploited by the Balada Injector campaign. The campaign injects malicious code into websites using older versions of the plugin, with over 6,200 sites currently affected.

There is a Ransomware Armageddon Coming for Us All

11 January 2024
Generative AI will enable anyone to launch sophisticated phishing attacks that only Next-generation MFA devices can stop The least surprising headline from 2023 is that ransomware again set new records for a number of incidents and the damage inflicted. We saw new headlines every week, which included a who’s-who of big-name organizations. If MGM, Johnson Controls, Chlorox, Hanes Brands, Caesars

Atomic Stealer Gets an Upgrade - Targeting Mac Users with Encrypted Payload

11 January 2024
Cybersecurity researchers have identified an updated version of a macOS information stealer called Atomic (or AMOS), indicating that the threat actors behind the malware are actively enhancing its capabilities. "It looks like Atomic Stealer was updated around mid to late December 2023, where its developers introduced payload encryption in an effort to bypass detection rules,"

ExtraHop Raises $100M in Growth Capital

11 January 2024
Seattle-based company ExtraHop has raised $100 million in growth capital for its cloud-native network detection and response platform. The funding will be used to expand operations and business reach.