Latest Cybersecurity News and Articles
22 December 2023
Researchers from Unit 42 have discovered that threat actors are using malicious JavaScript to steal sensitive information by exploiting popular survey sites, low-quality hosting, and web chat APIs.
22 December 2023
First American Financial Corporation, the second-largest title insurance company in the US, has experienced a cyberattack and has taken some systems offline to contain the impact.
22 December 2023
The Biden administration is pushing for secure-by-design principles to be embraced by the tech industry, aiming to make security a core feature of software development to prevent attacks exploiting vulnerabilities.
22 December 2023
A recent analysis discovered a malicious plugin injected into a WordPress/WooCommerce website that creates a fake administrator user and injects credit card skimming JavaScript into the checkout page.
22 December 2023
Isovalent has developed eBPF, an open-source technology that provides insight into the operating system layer, and Cilium, which offers visibility into cloud-native applications.
22 December 2023
St Vincent's, Australia's largest not-for-profit health and aged care provider, has confirmed that it has experienced a cyberattack and that hackers have stolen some of its data.
22 December 2023
The proposed changes to the Children's Online Privacy Protection Rule (COPPA) would hold service providers responsible for ensuring the safety of digital experiences for children, rather than relying solely on parents.
22 December 2023
A hospital near Kansas City, Missouri, is facing disruptions in patient care due to a cyberattack on its IT systems. Some patients had to be transferred to other hospitals, and the hospital is actively investigating the source of the disruption.
22 December 2023
Users should exercise caution when using third-party app stores or purchasing cheap devices from unknown brands, as they may be at a higher risk of malware and other security threats.
22 December 2023
Breaches of genomic data not only pose risks to individuals but also have implications for their families, while sharing such data is crucial for research and development in the biotechnology field.
22 December 2023
The threat actor known as UAC-0099 has been linked to continued attacks aimed at Ukraine, some of which leverage a high-severity flaw in the WinRAR software to deliver a malware strain called LONEPAGE.
"The threat actor targets Ukrainian employees working for companies outside of Ukraine," cybersecurity firm Deep Instinct said in a Thursday analysis.
UAC-0099 was first
22 December 2023
A bug on Yahoo's sports betting platform allowed users to cheat by placing bets after the games had already been decided, potentially impacting the outcome of survivor pools with real money involved.
22 December 2023
The ransomware group AlphV has re-emerged just hours after law enforcement agencies took down its infrastructure. The group claimed to have "unseized" its data leak site and updated information about new victims.
22 December 2023
Organizations in the Defense Industrial Base (DIB) sector are in the crosshairs of an Iranian threat actor as part of a campaign designed to deliver a never-before-seen backdoor called FalseFont.
The findings come from Microsoft, which is tracking the activity under its weather-themed moniker Peach Sandstorm (formerly Holmium), which is also known as APT33, Elfin, and Refined Kitten.
"
21 December 2023

Hospital and aged care operator says cyber-attack was first detected on Tuesday and is investigating what data has been accessedFollow our Australia news live blog for latest updatesSt Vincent’s – Australia’s largest not-for-profit health and aged care provider – has confirmed it has fallen victim to a cyber-attack and hackers have stolen some of its data.In a statement, St Vincent’s Health Australia confirmed it began responding to a cybersecurity incident on Tuesday. It discovered late on Thursday that data had been stolen. Continue reading...
21 December 2023
A new malware scam was discovered by ReasonLabs, affecting individuals attempting to download torrented versions of popular video games.
21 December 2023
Ivanti's Avalanche enterprise MDM solution has been found to have 13 critical security vulnerabilities, including buffer overflow weaknesses, that can be exploited by attackers to gain remote code execution on unpatched systems.
21 December 2023
A new analysis of the sophisticated commercial spyware called Predator has revealed that its ability to persist between reboots is offered as an "add-on feature" and that it depends on the licensing options opted by a customer.
"In 2021, Predator spyware couldn't survive a reboot on the infected Android system (it had it on iOS)," Cisco Talos researchers Mike Gentile, Asheer Malhotra, and Vitor
21 December 2023
Cybersecurity researchers have discovered an updated version of an Android banking malware called Chameleon that has expanded its targeting to include users in the U.K. and Italy.
"Representing a restructured and enhanced iteration of its predecessor, this evolved Chameleon variant excels in executing Device Takeover (DTO) using the accessibility service, all while expanding its targeted region,
21 December 2023
Google has released emergency updates to fix a zero-day vulnerability in the Chrome browser. The vulnerability, known as CVE-2023-7024, is a heap buffer overflow issue in WebRTC.