Latest Cybersecurity News and Articles


Four-Year Campaign Backdoored Iphones Using Undocumented Hardware Function

28 December 2023
The secret hardware function targeted by the attackers allowed them to bypass advanced memory protections, enabling post-exploitation techniques and compromising system integrity.

Three Main Tactics Attackers Use to Bypass MFA

28 December 2023
SE Labs has warned that multi-factor authentication (MFA) is not foolproof and can be bypassed by attackers using old-school methods such as social engineering, malware, and phishing.

Panasonic Discloses Data Breach After December 2022 Cyberattack

28 December 2023
The breached information includes names, contact details, dates of birth, medical and health insurance information, financial account numbers, employment status, and government identifiers.

How to Incorporate Human-Centric Security

28 December 2023
Companies need to shift their focus from solely addressing threats to proactively mitigating risks by analyzing behaviors and implementing insider risk management solutions.

Essential DDoS Statistics for Understanding Attack Impact

28 December 2023
DDoS attacks have significant consequences, including financial losses, compromised data, and erosion of customer trust. Global events like the Russia-Ukraine war and NATO bids have fueled recent DDoS attack growth.

Critical Zero-Day in Apache OfBiz ERP System Exposes Businesses to Attack

28 December 2023
The flaw, tracked as CVE-2023-51467, is a result of an incomplete patch for another critical vulnerability (CVE-2023-49070) and allows attackers to achieve a simple Server-Side Request Forgery (SSRF) to access unauthorized internal resources.

Troves of Iranian Hacked Insurance Customer Data on Sale

28 December 2023
The breach was confirmed by the Iranian Leakage Tracking System, and the targeted company, Fanavaran, has since blocked access to its website in the aftermath of the incident.

New Rugmi Malware Loader Surges with Hundreds of Daily Detections

28 December 2023
A new malware loader is being used by threat actors to deliver a wide range of information stealers such as Lumma Stealer (aka LummaC2), Vidar, RecordBreaker (aka Raccoon Stealer V2), and Rescoms. Cybersecurity firm ESET is tracking the trojan under the name Win/TrojanDownloader.Rugmi. "This malware is a loader with three types of components: a downloader that downloads an

Integris Health Patients Get Extortion Emails After Cyberattack

27 December 2023
Integris Health, Oklahoma's largest healthcare network, suffered a cyberattack resulting in the theft of patient data, and now patients are receiving blackmail emails threatening to sell their data if they don't pay an extortion demand.

Corewell Health Suffers Third-Party Data Breach Impacting Over One Million Patients

27 December 2023
HealthEC, a population health management platform that provides services to Corewell Health, is the company involved in the breach, which may have compromised sensitive data such as names, addresses, SSNs, and medical records.

Mallox Ransomware Found Evading AMSI Detection Using New PowerShell Script

27 December 2023
The PowerShell script uses a technique developed by a researcher in 2022, which involves patching the Windows Defender registered DLL for AMSI with a shellcode to overwrite the function that scans PowerShell scripts.

Yakult Australia Confirms ‘Cyber Incident’ After 95 GB Data Leak

27 December 2023
The cybercrime group, DragonForce, has claimed responsibility for the attack and has leaked 95 GB of data belonging to the company. Yakult Australia is currently investigating the incident with the help of cybersecurity experts.

Critical Zero-Day in Apache OfBiz ERP System Exposes Businesses to Attack

27 December 2023
A new zero-day security flaw has been discovered in the Apache OfBiz, an open-source Enterprise Resource Planning (ERP) system that could be exploited to bypass authentication protections. The vulnerability, tracked as CVE-2023-51467, resides in the login functionality and is the result of an incomplete patch for another critical vulnerability (CVE-2023-49070, CVSS score: 9.8) that was

CyberAv3ngers Offers 1TB of Alleged Israeli Electricity Data for 5 BTC

27 December 2023
The hacker group CyberAv3ngers claims to have obtained and is selling 1TB of data from Israel's electricity infrastructure. They posted a message on a platform offering the data for sale. The Israel Electric Corporation (IEC) has not yet responded.

Fidelity National Financial Subsidiary Says 1.3 Million Affected by November Cyberattack

27 December 2023
The cyberattack on Fidelity National Financial was claimed by the AlphV/Blackcat ransomware gang, causing disruption to hundreds of home purchases and leading to the seizure of the gang's leak site by law enforcement agencies.

Kazakhstan to Extradite Russian Hacker to Moscow

27 December 2023
A Russian man accused by the United States of trafficking in a hacked database of online credentials will apparently evade American courts after the Russian government said it had succeeded in extraditing him.

Barracuda Networks Grapples with Two Zero-Day Vulnerabilities in ESG Devices

27 December 2023
Barracuda Networks has discovered two zero-day vulnerabilities, known as CVE-2023-7102 and CVE-2023-7101, in its Barracuda Email Security Gateway Appliance (ESG) devices.

GitHub Warns Users to Enable 2FA Before Upcoming Deadline

27 December 2023
GitHub is warning users that they must enable 2FA on their accounts or face limited functionality on the site. This requirement applies to users contributing code on GitHub and is aimed at protecting accounts from breaches and code alterations.

Rhysida Ransomware Group Hacked Abdali Hospital in Jordan

27 December 2023
The Rhysida ransomware group has claimed responsibility for hacking Abdali Hospital in Jordan. The group has published proof of the hack, including stolen documents, and is now auctioning off the sensitive data for 10 BTC.

Chinese Hackers Exploited New Zero-Day in Barracuda's ESG Appliances

27 December 2023
Barracuda has revealed that Chinese threat actors exploited a new zero-day in its Email Security Gateway (ESG) appliances to deploy backdoor on a "limited number" of devices. Tracked as CVE-2023-7102, the issue relates to a case of arbitrary code execution that resides within a third-party and open-source library Spreadsheet::ParseExcel that's used by the Amavis scanner within the