Latest Cybersecurity News and Articles
11 January 2024
The malware's obfuscation and custom code suggest mature threat actors, but the inclusion of childish elements complicates attribution, making it difficult to determine the exact nature of the operation.
11 January 2024
Enterprises must implement robust security measures throughout the AI application development lifecycle to mitigate vulnerabilities such as prompt and data leakage, including sandboxing, whitelisting, and careful vetting of plug-ins.
11 January 2024
The vulnerabilities, tracked as CVE-2023-846805 and CVE-2024-21887, were used in an attack last month to steal configuration data, modify files, and gain unauthorized access to systems.
11 January 2024
Threat actors are increasingly using annual responsibilities like open enrollment, 401k updates, and salary adjustments as lures to steal employee credentials through phishing emails.
11 January 2024
Atomic Stealer, a popular malware among criminals, has recently been updated with payload encryption to evade detection and has been distributed through malvertising campaigns and cracked software.
11 January 2024
The vulnerability, found in the software's web-based management interface, allows attackers to execute commands on the underlying operating system by uploading arbitrary files.
11 January 2024
The compromise of Mandiant's X (formerly Twitter) account last week was likely the result of a "brute-force password attack," attributing the hack to a drainer-as-a-service (DaaS) group.
"Normally, [two-factor authentication] would have mitigated this, but due to some team transitions and a change in X's 2FA policy, we were not adequately protected," the threat intelligence firm said
11 January 2024
A pair of zero-day flaws identified in Ivanti Connect Secure (ICS) and Policy Secure have been chained by suspected China-linked nation-state actors to breach less than 10 customers.
Cybersecurity firm Volexity, which identified the activity on the network of one of its customers in the second week of December 2023, attributed it to a hacking group it tracks under the name UTA0178
10 January 2024
Cisco has released software updates to address a critical security flaw impacting Unity Connection that could permit an adversary to execute arbitrary commands on the underlying system.
Tracked as CVE-2024-20272 (CVSS score: 7.3), the vulnerability is an arbitrary file upload bug residing in the web-based management interface and is the result of a lack of authentication in a specific
10 January 2024
The cybersecurity sector recorded 346 funding rounds and 91 mergers and acquisition (M&A) transactions in 2023, according to cyber recruitment firm Pinpoint Search Group.
10 January 2024
Several high-profile health data hacks, including those affecting medical transcription vendor Perry Johnson and Associates and hospital chain Prospect Medical Holdings, are resulting in growing lists of affected individuals and triggering lawsuits.
10 January 2024
According to a Mark43 report, 82% of first responders worry that their organization’s data could be stolen or fall victim to ransomware.
10 January 2024
Distributed denial of service (DDoS) attacks reached an all-time high in 2023, with a significant increase in the number and intensity of attacks, driven by the exploitation of vulnerabilities like the HTTP/2 Rapid Reset.
10 January 2024
Two Russian men, known as Icamis and Salomon, co-ran the top spam forum Spamdot and worked closely with dangerous cybercriminals, controlling botnets and harvesting passwords.
10 January 2024
Last week, Tigo Business, a division of Paraguay's largest mobile carrier, suffered a cyberattack that impacted their cloud and hosting services. While it did not confirm the attack, reports suggest that it was targeted by the Black Hunt ransomware.
10 January 2024
Jadee Hanson has been hired as CISO at Vanta. Hanson will oversee security, enterprise engineering, privacy and governance, risk and compliance.
10 January 2024
The US Department of Justice expects an increase in government disruption operations in cybersecurity in 2024, with a focus on dismantling cybercriminal infrastructure and targeting individuals and companies supporting cybercrime.
10 January 2024
The vulnerability permits any unauthenticated user to upload arbitrary files, including potentially malicious PHP files, which could lead to remote code execution on the affected system.
10 January 2024
The FTC's action against Outlogic marks the first-ever ban on the use and sale of sensitive location data, emphasizing the importance of limiting the tracking and use of personal information.
10 January 2024
A new Mirai-based botnet called NoaBot is being used by threat actors as part of a crypto mining campaign since the beginning of 2023.
“The capabilities of the new botnet, NoaBot, include a wormable self-spreader and an SSH key backdoor to download and execute additional binaries or spread itself to new victims,” Akamai security researcher Stiv Kupchik said in a report shared with The