Latest Cybersecurity News and Articles
03 January 2024
Cyberattacks, data breaches and newly exploited vulnerabilities across the globe were analyzed in a recent report by Check Point Research.
03 January 2024
A surge of fake or stolen Twitter Gold (now X Gold) accounts has been flooding both the surface web and the dark web over the past year, according to cybersecurity firm CloudSEK.
03 January 2024
Qualcomm has announced a critical vulnerability that could lead to remote attacks on devices using their chipsets. The flaw, tracked as CVE-2023-33025, involves a buffer overflow during VoLTE calls, allowing attackers to execute code remotely.
03 January 2024
With its second acquisition in two months, SonicWall aims to help enterprises with growing remote workforces through zero-trust network and security service edge offerings.
03 January 2024
The CISA has identified two recently patched vulnerabilities, one in Google Chrome and another in the open-source Perl library Spreadsheet::ParseExcel, that have been actively exploited and require immediate mitigation.
03 January 2024
The data breach, carried out by a threat actor named IntelBroker, has allegedly exposed sensitive details such as full names, emails, phone numbers, banking information, and more.
03 January 2024
In an ever-evolving digital age, how can CISOs prepare themselves and their employees? What should they take into consideration for the new year?
03 January 2024
Information stealing malware are actively taking advantage of an undocumented Google OAuth endpoint named MultiLogin to hijack user sessions and allow continuous access to Google services even after a password reset.
According to CloudSEK, the critical exploit facilitates session persistence and cookie generation, enabling threat actors to maintain access to a valid session in an
03 January 2024
Belarusian hacktivist group, the Cyber-Partisans, launched a cyberattack on the country's leading state-owned media outlet, wiping the main website servers and backups, as a retaliatory measure against President Lukashenko's propaganda campaign.
03 January 2024
Gallery Systems, a museum software provider, has revealed that it experienced a ransomware attack last week, leading to ongoing IT outages. The attack caused the company to take systems offline to prevent further encryption.
03 January 2024
Ransomware attacks in the US reached record levels in 2023, targeting hospitals, schools, government organizations, and private-sector businesses, costing victims an average of $1.5 million to rectify.
03 January 2024
Fallon Ambulance Services, a subsidiary of Transformative Healthcare, was targeted in a ransomware attack that exposed the personal information of nearly a million people. The attack occurred in February 2023 and was discovered in April 2023.
03 January 2024
The European Central Bank will conduct cyber stress tests on 109 banks in Europe to assess their resilience against cyberattacks. The tests will simulate disruptive cyberattacks and evaluate how the banks respond and recover.
03 January 2024
The stolen funds are believed to be linked to North Korean hacking groups, such as Lazarus, who use cryptocurrency cyberattacks to bypass international sanctions and finance their weapons development program.
03 January 2024
As technology adoption has shifted to be employee-led, just in time, and from any location or device, IT and security teams have found themselves contending with an ever-sprawling SaaS attack surface, much of which is often unknown or unmanaged. This greatly increases the risk of identity-based threats, and according to a recent report from CrowdStrike, 80% of breaches today use compromised
03 January 2024
A new exploitation technique called Simple Mail Transfer Protocol (SMTP) smuggling can be weaponized by threat actors to send spoofed emails with fake sender addresses while bypassing security measures.
"Threat actors could abuse vulnerable SMTP servers worldwide to send malicious emails from arbitrary email addresses, allowing targeted phishing attacks," Timo Longin, a senior security
03 January 2024
XCast transmitted billions of illegal robocalls to American consumers, using false affiliations with government agencies and misleading information to deceive victims into making purchases.
03 January 2024
NewYork-Presbyterian Hospital has been fined $300,000 by state regulators for privacy violations related to its use of tracking tools on its websites and patient portal. It violated HIPAA rules by sharing patient information with third parties.
03 January 2024
The hacker group, known as "irleaks," publicly disclosed the breach and claimed to have acquired a vast amount of data, including customer details, vendor records, payment information, device data, product orders, and more.
03 January 2024
BT has failed to meet the extended deadline to remove Huawei equipment from its core networks, with only 2G and 3G services still being served by non-compliant infrastructure.