Latest Cybersecurity News and Articles


Steam Drops Support for Windows 7 and 8.1 to Boost Security

03 January 2024
The end of support for these older Windows versions is due to the reliance on an embedded version of Google Chrome that no longer functions on them, as well as the need for Windows feature and security updates only available on Windows 10 and above.

Facts and Misconceptions About Cybersecurity Budgets

03 January 2024
Despite increased cybersecurity budgets, there is a need for a further rise in spending to effectively mitigate security risks. Economic volatility, a growing distributed workforce, and supply chain issues are key factors influencing spending.

DOJ Slams XCast with $10 Million Fine Over Massive Illegal Robocall Operation

03 January 2024
The U.S. Department of Justice (DoJ) on Tuesday said it reached a settlement with VoIP service provider XCast over allegations that it facilitated illegal telemarketing campaigns since at least January 2018, in contravention of the Telemarketing Sales Rule (TSR). In addition to prohibiting the company from violating the law, the stipulated order requires it to meet other compliance measures,

Update: After Ransomware Claims, Xerox Says Subsidiary Hit With Cyberattack

03 January 2024
Xerox stated that the incident had no impact on its corporate systems, operations, or data, but limited personal information in the XBS environment may have been affected.

Australian Court Service Hacked, Hearing Recordings at Risk

02 January 2024
The Court Services Victoria (CSV) took immediate action to isolate and disable the affected network, but recordings from November 1 to December 21, 2023, may have been accessed.

Android Game Developer’s Google Drive Misconfiguration Leaks Information on Nearly One Million Users

02 January 2024
A simple Google Drive configuration mistake by Japanese game developer Ateam resulted in the potential exposure of sensitive information for nearly one million individuals, highlighting the importance of properly securing cloud services.

New Black Basta Decryptor Exploits Ransomware Flaw to Recover Files

02 January 2024
While the decryptor only works on older versions of Black Basta and has been patched in newer attacks, it provides hope for victims who were affected between November 2022 and the recent bug fix.

Inc Ransom Ransomware Gang Claims to Have Breached Xerox Corp

02 January 2024
The Inc Ransom ransomware group has published several documents, including emails and an invoice, as proof of the hack. It is unclear how much data has been stolen from Xerox Corp.

New Variant of DLL Search Order Hijacking Bypasses Windows 10 and 11 Protections

02 January 2024
The technique leverages executables in the trusted WinSxS folder, making it possible to run nefarious code without elevated privileges and introduce potentially vulnerable binaries into the attack chain.

Bunker Hill Community College announces data breach

02 January 2024
Bunker Hill Community College (BHCC) in Boston, Massachusetts experienced a data breach in May 2023 that included Social Security Numbers.

Zeppelin2 Ransomware Builder for Sale on Dark Web

02 January 2024
A user on an underground forum is promoting the sale of Zeppelin2 ransomware, offering its source code and a cracked version of its builder tool. Zeppelin2 has been used since 2019, targeting various sectors including healthcare and technology.

Cactus Ransomware Gang Hit the Swedish Retail and Grocery Provider Coop

02 January 2024
The Cactus ransomware group has claimed to have hacked Coop, one of the largest retail and grocery providers in Sweden. They are threatening to release a large amount of personal information.

Hackers Attack UK’s Nuclear Waste Services Through LinkedIn

02 January 2024
The United Kingdom's Radioactive Waste Management (RWM) company recently experienced a cyberattack attempt through LinkedIn. Although the attack was unsuccessful, concerns have been raised about the security of critical nuclear infrastructure.

Malware Abuses Google OAuth Endpoint to ‘Revive’ Cookies, Hijack Accounts

02 January 2024
Multiple information-stealing malware families are exploiting an undocumented Google OAuth endpoint called "MultiLogin" to restore expired authentication cookies and gain unauthorized access to users' accounts.

Pro-Palestinian Operation Claims Dozens of Data Breaches Against Israeli Firms

02 January 2024
Pro-Palestinian hackers belonging to the group Cyber Toufan have successfully breached and leaked data from numerous Israeli entities, including foreign companies doing business with Israel.

Pentagon Reveals Updated Cost Estimates for CMMC Implementation

02 January 2024
The Pentagon has provided new cost estimates for implementing its Cybersecurity Maturity Model Certification program, with projected costs totaling around $4 billion for contractors and other non-government entities over a 20-year period.

Spotify Music Converter TuneFab Puts Users at Risk Due to Misconfigured MongoDB Instance

02 January 2024
TuneFab converter, a tool used to convert copyrighted music from streaming platforms, exposed over 151 million records of users' private data due to a misconfiguration on MongoDB.

Google Settles Lawsuit Over Tracking People in ‘Incognito Mode'

02 January 2024
Google has agreed to settle a $5 billion privacy lawsuit that accused the company of collecting personal data from users even when they were in "private browsing mode" on its Chrome browser.

New Version of Meduza Stealer Released in Dark Web

02 January 2024
This updated version of Meduza Stealer includes support for more software clients, an upgraded credit card grabber, and improved mechanisms for storing and extracting credentials and tokens.

The Definitive Enterprise Browser Buyer's Guide

02 January 2024
Security stakeholders have come to realize that the prominent role the browser has in the modern corporate environment requires a re-evaluation of how it is managed and protected. While not long-ago web-borne risks were still addressed by a patchwork of endpoint, network, and cloud solutions, it is now clear that the partial protection these solutions provided is no longer sufficient. Therefore,