Latest Cybersecurity News and Articles


The Definitive Enterprise Browser Buyer's Guide

02 January 2024
Security stakeholders have come to realize that the prominent role the browser has in the modern corporate environment requires a re-evaluation of how it is managed and protected. While not long-ago web-borne risks were still addressed by a patchwork of endpoint, network, and cloud solutions, it is now clear that the partial protection these solutions provided is no longer sufficient. Therefore,

Google Settles $5 Billion Privacy Lawsuit Over Tracking Users in 'Incognito Mode'

02 January 2024
Google has agreed to settle a lawsuit filed in June 2020 that alleged that the company misled users by tracking their surfing activity who thought that their internet use remained private when using the “incognito” or “private” mode on web browsers. The class-action lawsuit sought at least $5 billion in damages. The settlement terms were not disclosed. The plaintiffs had

Palo Alto Networks Closes Talon Cyber Security Acquisition

02 January 2024
The integration of Talon's Enterprise Browser with Prisma SASE will provide enhanced data protection for users across all applications and devices, addressing the security risks posed by web browsing on unmanaged devices.

Clash of Clans Gamers at Risk While Using Third-Party App

02 January 2024
A third-party app called Clash Base Designer Easy Copy, which is used by Clash of Clans players to create custom base layouts, exposed its Firebase database and user-sensitive information. The app has over 100,000 downloads on the Google Play store.

Hospitals Ask Courts to Force Cloud Storage Firm to Return Stolen Data

02 January 2024
Two New York hospitals are seeking a court order to retrieve stolen data stored on a cloud storage company's servers after a ransomware attack. The stolen data includes sensitive information such as patients' personal and health information.

Cybercriminals Launched ‘Leaksmas’ Event in the Dark Web Exposing Massive Volumes of Leaked PII and Compromised Data

02 January 2024
On Christmas Eve, multiple threat actors released substantial data leaks, potentially causing significant financial damage and adverse effects such as identity theft and fraud globally.

Misconfigurations in Google Kubernetes Engine (GKE) Lead to a Privilege Escalation Exploit Chain

02 January 2024
A dual privilege escalation chain in Google Kubernetes Engine (GKE) and Anthos Service Mesh (ASM) allowed attackers to gain complete control over Kubernetes clusters, highlighting the importance of regular updates and proactive security measures.

New JinxLoader Targeting Users with Formbook and XLoader Malware

02 January 2024
The malware is distributed through phishing emails impersonating Abu Dhabi National Oil Company (ADNOC) and drops the JinxLoader executable upon opening password-protected RAR archive attachments.

Hackers break into Victorian court recordings database

01 January 2024
Hackers break into Victorian court recordings database Court Service Victoria says it will notify those captured on recordings of hearings of the breachVictoria’s court system has been hit by a cyber-attack, with hackers accessing several weeks of recorded court and tribunal hearings.Court Services Victoria (CSV) was first made aware of the attack on 21 December but it is believed the audio-visual technology network was first compromised on 1 November. Continue reading...

New Variant of DLL Search Order Hijacking Bypasses Windows 10 and 11 Protections

01 January 2024
Security researchers have detailed a new variant of a dynamic link library (DLL) search order hijacking technique that could be used by threat actors to bypass security mechanisms and achieve execution of malicious code on systems running Microsoft Windows 10 and Windows 11. The approach "leverages executables commonly found in the trusted WinSxS folder and exploits them via the classic DLL

New Terrapin Flaw Could Let Attackers Downgrade SSH Protocol Security

01 January 2024
Security researchers from Ruhr University Bochum have discovered a vulnerability in the Secure Shell (SSH) cryptographic network protocol that could allow an attacker to downgrade the connection's security by breaking the integrity of the secure channel. Called Terrapin (CVE-2023-48795, CVSS score: 5.9), the exploit has been described as the "first ever practically exploitable prefix

New JinxLoader Targeting Users with Formbook and XLoader Malware

01 January 2024
A new Go-based malware loader called JinxLoader is being used by threat actors to deliver next-stage payloads such as Formbook and its successor XLoader. The disclosure comes from cybersecurity firms Palo Alto Networks Unit 42 and Symantec, both of which highlighted multi-step attack sequences that led to the deployment of JinxLoader through phishing attacks. "The

Beware: Scam-as-a-Service Aiding Cybercriminals in Crypto Wallet-Draining Attacks

30 December 2023
Cybersecurity researchers are warning about an increase in phishing attacks that are capable of draining cryptocurrency wallets. "These threats are unique in their approach, targeting a wide range of blockchain networks, from Ethereum and Binance Smart Chain to Polygon, Avalanche, and almost 20 other networks by using a crypto wallet-draining technique," Check Point researchers Oded Vanunu,

Info-Stealing Malware Now Includes Google Session Hijacking

30 December 2023
Multiple malware-as-a-service info stealers now have the ability to manipulate authentication tokens to gain persistent access to a victim's Google account, even after the user has reset their password.

Kimsuky Hackers Deploying AppleSeed, Meterpreter, and TinyNuke in Latest Attacks

29 December 2023
The North Korean Kimsuky APT has recently been observed using a new variant called AlphaSeed, written in Golang, which uses chromedp for communication with the command-and-control server.

Happy 14th Birthday, KrebsOnSecurity!

29 December 2023
KrebsOnSecurity celebrates its 14th year of existence today! I promised myself this post wouldn't devolve into yet another Cybersecurity Year in Review. Nor do I wish to hold forth about whatever cyber horrors may await us in 2024. But I do want to thank you all for your continued readership, encouragement and support, without which I could not do what I do.

DataNet Systems suffers data breach

29 December 2023
DataNet Systems gas announced that the company experienced a data breach affecting District of Columbia (D.C.) voters, including email addresses.

Albanian Parliament and One Albania Telecom Hit by Cyber Attacks

29 December 2023
The Assembly of the Republic of Albania and telecom company One Albania have been targeted by cyber attacks, the country’s National Authority for Electronic Certification and Cyber Security (AKCESK) revealed this week. “These infrastructures, under the legislation in force, are not currently classified as critical or important information infrastructure,” AKCESK said. One Albania, which has

Computer Systems at Massachusetts-Based Anna Jaques Hospital Compromised After Cyberattack

29 December 2023
Anna Jaques Hospital's health record system was shut down due to a cyberattack, causing delays in receiving services and diverting ambulance arrivals. The hospital is working with cybersecurity professionals to investigate the attack.

New data reveals the states at highest risk of cybercrime

29 December 2023
According to new data, residents of Nevada face a greater susceptibility to cyberattacks compared to those in all other states.