Latest Cybersecurity News and Articles


Update: Estes Refuses to Pay Off Ransomware Crew, Says Data Stolen

04 January 2024
The company chose not to pay the ransom demanded by the hackers, aligning with the FBI's recommendation, but the specific details of the attack and the stolen data remain undisclosed.

Three Malicious PyPI Packages Found Targeting Linux Systems with Crypto Miners

04 January 2024
The packages were named modularseven, driftme, and catme and received a total of 431 downloads before being removed. The packages contained a CoinMiner executable that was deployed on the affected devices.

Cloud-Native Cybersecurity Startup Aqua Security Raises $60M and Remains a Unicorn

04 January 2024
The Series E funding round was led by Evolution Equity Partners, with participation from existing investors Lightspeed Venture Partners, Insight Partners, and StepStone Group.

Three Ways To Supercharge Your Software Supply Chain Security

04 January 2024
Section four of the "Executive Order on Improving the Nation’s Cybersecurity" introduced a lot of people in tech to the concept of a “Software Supply Chain” and securing it. If you make software and ever hope to sell it to one or more federal agencies, you have to pay attention to this. Even if you never plan to sell to a government, understanding your Software Supply Chain and

UAC-0050 Group Using New Phishing Tactics to Distribute Remcos RAT

04 January 2024
The malware is being distributed through LNK files that collect information about antivirus products and execute an HTML application. This leads to the download of two files from a remote server, which establish persistence and launch the Remcos RAT.

LastPass Now Requires 12-Character Master Passwords for Better Security

04 January 2024
LastPass, a popular password management solution, is now requiring customers to use complex master passwords with a minimum of 12 characters to enhance account security. Previously, users had the option to use weaker passwords.

Hacker Hijacks Orange Spain RIPE Account to Cause BGP Havoc

04 January 2024
The hacker changed the AS number associated with Orange Spain's IP addresses and enabled an invalid RPKI configuration, causing the IP addresses to no longer be announced properly.

Beware: 3 Malicious PyPI Packages Found Targeting Linux with Crypto Miners

04 January 2024
Three new malicious packages have been discovered in the Python Package Index (PyPI) open-source repository with capabilities to deploy a cryptocurrency miner on affected Linux devices. The three harmful packages, named modularseven, driftme, and catme, attracted a total of 431 downloads over the past month before they were taken down. “These packages, upon initial use, deploy a CoinMiner

FTC Soliciting Contest Submissions to Help Tackle Voice Cloning Technology

04 January 2024
The FTC is seeking multidisciplinary approaches to prevent unauthorized use of voice cloning, improve real-time detection, and provide consumers with tools to identify cloned voices in audio clips.

Consumers Prepared to Ditch Brands After Cybersecurity Issues

04 January 2024
In 2023, businesses have been hit with 800,000 cyberattacks, over 60,000 of which were DDoS attacks and 4,000 falling victim to ransomware, according to a report by Vercara.

Ukraine Says Russia Hacked Web Cameras to Spy on Targets in Kyiv

04 January 2024
Ukraine's security officers have discovered that Russian intelligence hacked into surveillance cameras in Kyiv to gain remote access and stream sensitive footage, potentially aiding in missile strikes against the city.

Nigerian Hacker Arrested for Stealing $7.5M From US Charities

04 January 2024
The fraud scheme involved unauthorized access to email accounts, impersonating employees, and tricking one charity into transferring funds to accounts controlled by the attacker.

New Open-Source Tool for Investigating Google Drive File Stream’s Disk Forensic Artifacts

04 January 2024
DriveFS Sleuth automates the investigation of Google Drive File Stream disk artifacts. The tool can parse the disk artifacts and build a filesystem tree-like structure enumerating the synchronized files along with their respective properties.

Atos Confirms Talks of Cyber Sell-off to Airbus are Underway

04 January 2024
Airbus is expected to offer between €1.5 to 1.8 billion (~$1.64 to 1.97 billion) for Atos' Big Data & Security division, in line with its goal of growing its cybersecurity arm and enhancing its defense and security portfolio.

UAC-0050 Group Using New Phishing Tactics to Distribute Remcos RAT

04 January 2024
The threat actor known as UAC-0050 is leveraging phishing attacks to distribute Remcos RAT using new strategies to evade detection from security software. "The group's weapon of choice is Remcos RAT, a notorious malware for remote surveillance and control, which has been at the forefront of its espionage arsenal," Uptycs security researchers Karthick Kumar and Shilpesh Trivedi said in

Update: Nearly 11 Million SSH Servers Vulnerable to New Terrapin Attacks

04 January 2024
Attackers need to be in an adversary-in-the-middle position to intercept and modify the handshake exchange, making network compromise a key factor in executing the Terrapin attack.

Mandiant’s Account on X Hacked to Push Cryptocurrency Scam

04 January 2024
The Twitter account of cybersecurity firm Mandiant, which is owned by Google, was hacked and used to promote a cryptocurrency scam. The attacker impersonated the Phantom crypto wallet and shared a fake website offering free tokens.

Mandiant's Twitter Account Restored After Six-Hour Crypto Scam Hack

04 January 2024
American cybersecurity firm and Google Cloud subsidiary Mandiant had its X (formerly Twitter) account compromised for more than six hours by an unknown attacker to propagate a cryptocurrency scam. As of writing, the account has been restored on the social media platform. It's currently not clear how the account was breached. But the hacked Mandiant account was initially renamed to "@

‘Large-Scale’ Cyberattack Hits French Township, All Local Services Down

03 January 2024
The mayor of Pays Fouesnantais, a township in France, announced that the municipality has been hit by a large-scale cyberattack, causing all community services to be taken down.

European parking app announces data breach

03 January 2024
Cyberattacks, data breaches and newly exploited vulnerabilities across the globe were analyzed in a recent report by Check Point Research.