Latest Cybersecurity News and Articles


MyEstatePoint Property Search Android App Leaks User Passwords, Email Addresses, and Phone Numbers

05 January 2024
The MyEstatePoint Property Search app, developed by NJ Technologies in India, left a publicly accessible MongoDB server containing sensitive information such as names, plain-text passwords, email addresses, phone numbers, and more.

San Bernardino Housing Authority Cyberattack Affected Nearly 19,000 People

05 January 2024
This incident highlights the ongoing vulnerability of housing authorities to cyberattacks, as seen in previous attacks on housing authorities in North Carolina, Los Angeles, Indianapolis, and Cleveland.

Orrick, Herrington & Sutcliffe Data Breach Exposes Information of Over 600,000 Individuals

05 January 2024
The stolen data included a wide range of information such as names, dates of birth, addresses, government-issued identification numbers, medical treatment details, insurance claims information, and credit/debit card numbers.

Exposed Secrets are Everywhere. Here's How to Tackle Them

05 January 2024
Picture this: you stumble upon a concealed secret within your company's source code. Instantly, a wave of panic hits as you grasp the possible consequences. This one hidden secret has the power to pave the way for unauthorized entry, data breaches, and a damaged reputation. Understanding the secret is just the beginning; swift and resolute action becomes imperative. However, lacking the

Orange Spain Faces BGP Traffic Hijack After RIPE Account Hacked by Malware

05 January 2024
Mobile network operator Orange Spain suffered an internet outage for several hours on January 3 after a threat actor used administrator credentials captured by means of stealer malware to hijack the border gateway protocol (BGP) traffic. "The Orange account in the IP network coordination center (RIPE) has suffered improper access that has affected the browsing of some of our customers," the

Security Vulnerabilities Addressed in Firefox 121

05 January 2024
Mozilla's latest release of Firefox 121 addresses critical vulnerabilities, including a heap buffer overflow bug and a vulnerability in rendering Network Security Services (NSS) NIST curves.

BreachForums Administrator Detained After Violating Parole

05 January 2024
The administrator of BreachForums, a notorious cybercrime haven, has been arrested for violating his parole by using a computer and VPN services without the required monitoring software.

Update: Russian Hackers Had Covert Access to Ukraine's Telecom Giant for Months

05 January 2024
A Russian hacking group called Solntsepyok claimed responsibility for the breach. Sandworm, known for orchestrating disruptive cyber attacks, has been linked to Solntsepyok.

Mimecast Acquires Human Risk Management Specialist Elevate Security

05 January 2024
The deal aims to enhance digital work environment protection by gaining insights into human behavior. Mimecast plans to integrate Elevate Security's technology into its own security offerings by midyear.

In Airtags Stalking Lawsuit, Federal Judge Says Apple Likely Negligent

05 January 2024
A federal judge in San Francisco has indicated that he is leaning towards denying Apple's motion to dismiss a class action lawsuit brought by stalking victims who claim that the company's AirTags tracking product enabled their abusers.

Ivanti Releases Patch for Critical Vulnerability in Endpoint Manager Solution

05 January 2024
Ivanti has released security updates to address a critical vulnerability in its Endpoint Manager solution. The flaw, known as CVE-2023-39336, allows attackers to execute remote code on susceptible servers.

Alert: Ivanti Releases Patch for Critical Vulnerability in Endpoint Manager Solution

05 January 2024
Ivanti has released security updates to address a critical flaw impacting its Endpoint Manager (EPM) solution that, if successfully exploited, could result in remote code execution (RCE) on susceptible servers. Tracked as CVE-2023-39336, the vulnerability has been rated 9.6 out of 10 on the CVSS scoring system. The shortcoming impacts EPM 2021 and EPM 2022 prior to SU5. “If exploited, an

Russian Hackers Had Covert Access to Ukraine's Telecom Giant for Months

05 January 2024
Ukrainian cybersecurity authorities have disclosed that the Russian state-sponsored threat actor known as Sandworm was inside telecom operator Kyivstar's systems at least since May 2023. The development was first reported by Reuters. The incident, described as a "powerful hacker attack," first came to light last month, knocking out access to mobile and internet services

New Bandook RAT Variant Resurfaces, Targeting Windows Machines

05 January 2024
A new variant of remote access trojan called Bandook has been observed being propagated via phishing attacks with an aim to infiltrate Windows machines, underscoring the continuous evolution of the malware. Fortinet FortiGuard Labs, which identified the activity in October 2023, said the malware is distributed via a PDF file that embeds a link to a password-protected .7z archive. “

Victoria court records exposed following cyberattack

04 January 2024
In December 2023, Court Services Victoria was alerted to a cybersecurity incident impacting Victoria's courts and tribunals, including recordings.

Data Breach at Healthcare Tech Firm Hits 4.5 Million Patients

04 January 2024
The breach impacted 17 healthcare service providers and state-level health systems, including Corewell Health, HonorHealth, and the State of Tennessee's Division of TennCare.

SentinelOne Acquires PingSafe to Expand Cloud Security Capabilities

04 January 2024
By integrating PingSafe's capabilities into SentinelOne's Singularity Platform, companies will have access to a unified, best-of-breed security platform for their entire cloud footprint.

Threat Actor Demands $1M for Remote Command Injection Vulnerability in Cisco ASA

04 January 2024
The sale of this vulnerability poses significant risks, including network disruption, data compromise, and financial and reputational damage for organizations reliant on Cisco ASA.

Update: Estes Refuses to Pay Off Ransomware Crew, Says Data Stolen

04 January 2024
The company chose not to pay the ransom demanded by the hackers, aligning with the FBI's recommendation, but the specific details of the attack and the stolen data remain undisclosed.

Three Malicious PyPI Packages Found Targeting Linux Systems with Crypto Miners

04 January 2024
The packages were named modularseven, driftme, and catme and received a total of 431 downloads before being removed. The packages contained a CoinMiner executable that was deployed on the affected devices.