Latest Cybersecurity News and Articles


Update: LockBit Claims November Attack on New Jersey Hospital That Disrupted Patient Care

09 January 2024
The attack caused network outages and disrupted patient care, resulting in canceled appointments and rescheduled surgeries. The LockBit ransomware gang has now threatened to leak 7TB of stolen data from the hospital.

Researchers Disclose New Lumma Stealer Campaign Distributed via YouTube

09 January 2024
FortiGuard Labs researchers discovered an attack campaign involving the Lumma Stealer malware spreading through hijacked YouTube channels. Threat actors compromise accounts, upload videos disguised as legitimate cracked software sharing, and redirect users to malicious URLs via installation guides. It is recommended to download apps/software from trusted sources.

Sensitive Files of Swiss Air Force Stolen in the Hack of Ultra Intelligence & Communications

09 January 2024
The breach, carried out by the BlackCat ransomware gang, resulted in the theft of around 30 gigabytes of sensitive data, including a contract between the Swiss Department of Defence and Ultra Intelligence & Communications for nearly $5 million.

Why Public Links Expose Your SaaS Attack Surface

09 January 2024
Collaboration is a powerful selling point for SaaS applications. Microsoft, Github, Miro, and others promote the collaborative nature of their software applications that allows users to do more. Links to files, repositories, and boards can be shared with anyone, anywhere. This encourages teamwork that helps create stronger campaigns and projects by encouraging collaboration among employees

Netgear, Hyundai Latest X Accounts Hacked To Push Crypto Drainers

09 January 2024
Hackers are increasingly targeting verified Twitter accounts of businesses and government organizations to promote cryptocurrency scams and steal assets from unsuspecting users.

Alert: New Vulnerabilities Discovered in QNAP and Kyocera Device Manager

09 January 2024
A security flaw has been disclosed in Kyocera’s Device Manager product that could be exploited by bad actors to carry out malicious activities on affected systems. "This vulnerability allows attackers to coerce authentication attempts to their own resources, such as a malicious SMB share, to capture or relay Active Directory hashed credentials if the ‘Restrict NTLM: Outgoing NTLM

Ransomware Attack on Toronto Zoo Had No Impact on Animal Wellbeing

09 January 2024
The Toronto Zoo's operations and animal well-being were not impacted by a recent ransomware attack on its systems. The zoo does not store credit card information but is investigating if the attack affected guest and donor records.

Bangladesh Official Alleges Cyberattack ‘From Ukraine and Germany’ Targeted Election

09 January 2024
The cyberattack may have been a distributed denial of service (DDoS) attack. Prior to the election, both political parties accused foreign states of attempting to influence the vote.

Deceptive Cracked Software Spreads Lumma Variant on YouTube

09 January 2024
A threat group is using YouTube channels to distribute a variant of Lumma Stealer, a malware that targets sensitive information, by uploading videos with malicious URLs disguised as cracked software installation guides.

Beware! YouTube Videos Promoting Cracked Software Distribute Lumma Stealer

09 January 2024
Threat actors are resorting to YouTube videos featuring content related to cracked software in order to entice users into downloading an information stealer malware called Lumma. “These YouTube videos typically feature content related to cracked applications, presenting users with similar installation guides and incorporating malicious URLs often shortened using services like TinyURL and Cuttly,

Colorado wellness company suffers data breach

08 January 2024
In July of 2023, Welltok was alerted to a data breach affected by MOVEit Transfer software, affecting health data and Social Security Numbers.

Meet Ika & Sal: The Bulletproof Hosting Duo from Hell

08 January 2024
In 2020, the United States brought charges against four men accused of building a bulletproof hosting empire that once dominated the Russian cybercrime industry and supported multiple organized cybercrime groups. All four pleaded guilty to conspiracy and racketeering charges. But there is a fascinating and untold backstory behind the two Russian men involved, who co-ran Russia's most popular spam forum for years.

Cyberattack Hits Maldives Government Websites

08 January 2024
Over the weekend, the Maldives government websites experienced a cyberattack, resulting in temporary unavailability of the President's office, Foreign Ministry, and Tourism Ministry websites.

68% of organizations face risks due to cybersecurity skills shortage

08 January 2024
 According to a recent cybersecurity report, the number of organizations confirming five or more breaches jumped by 53% between 2021 and 2022.

Security leaders weigh in on 23andme hack

08 January 2024
According to reports, the personal information of nearly 6.9 million users has been accessed by hackers of 23andMe. Security leaders discuss.

Update: Google Says Malware Abusing API Is Standard Token Theft, Not an API Issue

08 January 2024
Google downplays the severity of the issue, treating it as regular cookie theft and suggesting users log out of their Chrome browser to invalidate the stolen cookies and tokens.

NoName Group Claims DDoS Attacks on Ukrainian Government Sites

08 January 2024
The NoName group has reportedly targeted several Ukrainian government websites, including Accordbank, Zaporizhzhya Titanium-Magnesium Plant, and the State Tax Service. The group posted a list of their latest DDoS attack victims on the dark web.

Bots, Fraud Farms, and Cryptojacking Surge, Urgently Requiring Attention

08 January 2024
Cybercriminals are increasingly relying on ready-made bots and human fraud farms, which account for the majority of malicious website and app traffic, highlighting the need for robust defenses.

Canada: Personal and Pregnancy Details of Midwives of Windsor Clients was Breached

08 January 2024
The compromised data includes names, addresses, contact information, medical details, and health insurance information. The exact number of affected clients is unclear, and it is unknown if the information has been misused.

Syrian Hackers Distributing Stealthy C#-Based Silver RAT to Cybercriminals

08 January 2024
Threat actors operating under the name Anonymous Arabic have released a remote access trojan (RAT) called Silver RAT that’s equipped to bypass security software and stealthily launch hidden applications. “The developers operate on multiple hacker forums and social media platforms, showcasing an active and sophisticated presence,” cybersecurity firm Cyfirma said in a report