Latest Cybersecurity News and Articles
10 January 2024
A new Mirai-based botnet called NoaBot is being used by threat actors as part of a crypto mining campaign since the beginning of 2023.
“The capabilities of the new botnet, NoaBot, include a wormable self-spreader and an SSH key backdoor to download and execute additional binaries or spread itself to new victims,” Akamai security researcher Stiv Kupchik said in a report shared with The
10 January 2024
In episode 19 of The Cybersecurity and Geopolitical Discussion, our trio of hosts examine how compelling world events could impact global security.
10 January 2024
The leaked data includes the personal information of over 41 million Hathway customers, but analysis suggests that the actual number of impacted accounts is around 4 million.
10 January 2024
The round was led by Glilot Capital Partners, with participation from existing investors. The company plans to use the funds to introduce new data-driven innovations in the GRC landscape and expand into markets across the US, EMEA, and APAC regions.
10 January 2024
The private data of hundreds of millions of Brazilian individuals, including full names, dates of birth, and CPF numbers, were publicly accessible, putting them at risk of identity theft and cybercrimes.
10 January 2024
The rebel groups' focus on tackling the scam industry is likely an attempt to gain favor with China, as many of its citizens have been targeted by these scams run from Mynamar.
10 January 2024
A California man who lost $100,000 in a 2021 SIM-swapping attack is suing the unknown holder of a cryptocurrency wallet that harbors his stolen funds. The case is thought to be first in which a federal court has recognized the… Read More »
10 January 2024
This incident highlights the ongoing cyberwar between Ukraine and Russia, with Ukrainian hackers allegedly cooperating with security services to target Russian organizations.
10 January 2024
Effective data security incident response requires building trust and clear role definition within the company and with external partners. Practicing decision-making with limited information is key to maintaining calm during cybersecurity crises.
10 January 2024
Pikabot, a loader malware similar to Qakbot, has been actively used in phishing campaigns by the Water Curupira threat actor, possibly as a replacement for Qakbot after its takedown.
10 January 2024
The integration of Authomize's cross-cloud identity capabilities into Delinea's platform will enable customers to detect and mitigate active identity threats across various applications and infrastructure.
10 January 2024
Organizations hit by ransomware face uncertainty regarding the deletion of stolen data, leading to a new form of extortion where a fake security researcher offers to hack into the ransomware group's server infrastructure for a fee.
10 January 2024
IT professionals have developed a sophisticated understanding of the enterprise attack surface – what it is, how to quantify it and how to manage it.
The process is simple: begin by thoroughly assessing the attack surface, encompassing the entire IT environment. Identify all potential entry and exit points where unauthorized access could occur. Strengthen these vulnerable points using
10 January 2024
The incident highlights concerns over the security of the SEC's social media accounts and the need for better protections against market manipulation through false tweets.
10 January 2024
The British Library has refuted reports that the recovery costs for its recent ransomware attack will reach nearly $9 million. The library said that the final costs are still unconfirmed and no additional funding bids have been made.
10 January 2024
A decryptor for the Tortilla variant of the Babuk ransomware has been released by Cisco Talos, allowing victims targeted by the malware to regain access to their files.
The cybersecurity firm said the threat intelligence it shared with Dutch law enforcement authorities made it possible to arrest the threat actor behind the operations.
The encryption key has also been shared with Avast,
10 January 2024
One of the vulnerabilities affects Apache Superset, a data visualization software, and allows remote code execution. The other vulnerabilities impact Adobe ColdFusion, Apple products, D-Link DSL-2750B devices, and Joomla.
10 January 2024
Microsoft's January 2024 Patch Tuesday includes security updates for 49 flaws and 12 remote code execution vulnerabilities. Two critical vulnerabilities were fixed, including a Windows Kerberos Security Feature Bypass and a Hyper-V RCE.
10 January 2024
Users are recommended to switch to the mobile versions available on iOS and Google Play. The decision to sunset the desktop app is part of Twilio's effort to focus on areas with higher demand.
10 January 2024
The vulnerability, CVE-2023-51448, requires an authenticated attacker with specific permissions or the exploitation of another vulnerability to access and exploit the Cacti database.