Latest Cybersecurity News and Articles


Cyber Risk Strategies in Hot Seat as SEC Rules Go Live

21 December 2023
Companies are reassessing their incident response plans and determining the materiality of cyber incidents. The SEC aims to improve companies' preparedness to mitigate breaches and attacks.

Indian Tech Giant HCL Investigating Ransomware Attack

21 December 2023
HCL Technologies has reported a ransomware attack on one of its projects in an isolated cloud environment. The company stated that the incident has had no impact on its overall network and that cybersecurity and data protection are top priorities.

Fake Delivery Websites Surge By 34% in December

21 December 2023
These scammers create fake delivery notification sites that mimic legitimate postal operators and use official names, logos, and typosquatted URLs to appear more convincing.

Russian Water Utility Rosvodokanal Hit by Disruptive Cyberattack From Blackjack Group

21 December 2023
This attack was seen as retaliation for an earlier cyberattack on Kyivstar, a phone company in Ukraine, which was attributed to Russian hackers. There are suspicions that the Security Service of Ukraine (SBU) may have played a role in the attack.

Subdominator: Open-Source Tool for Detecting Subdomain Takeovers

21 December 2023
Subdominator is a highly accurate and fast open-source tool for identifying subdomain takeovers, offering significant improvements over existing tools in terms of fingerprint accuracy and count, nested DNS support, and alternate DNS record matching.

New Phishing Attack Steals Instagram Backup Codes to Bypass 2FA Protection

21 December 2023
The campaign sends phishing emails pretending to be from Meta, Instagram's parent company, claiming that the recipient's account has been restricted due to copyright infringement.

AI’s Efficacy is Constrained in Cybersecurity, but Limitless in Cybercrime

21 December 2023
The use of AI in cybersecurity has created a cycle where both cyber professionals and cybercriminals employ AI to enhance their tools and techniques. However, there are limitations and trust issues with AI security solutions.

Fake F5 Vulnerability 'Update' Delivers Data Wiper to Israeli Victims

21 December 2023
The attacker takes advantage of a vulnerability in F5's BIG-IP and tricks recipients into downloading a file that is supposed to be an update for the vulnerability. However, the file actually contains a wiper that deletes F5 servers.

EMBA: Open-Source Security Analyzer for Embedded Devices

21 December 2023
The tool extracts firmware, conducts static and dynamic analysis, and generates web-based reports. Some unique features include enhanced firmware extraction, UEFI analysis, AI support, firmware diffing mechanisms, and user mode emulation.

New JavaScript Malware Targeted 50,000+ Users at Dozens of Banks Worldwide

21 December 2023
A new piece of JavaScript malware has been observed attempting to steal users' online banking account credentials as part of a campaign that has targeted more than 40 financial institutions across the world. The activity cluster, which employs JavaScript web injections, is estimated to have led to at least 50,000 infected user sessions spanning North America, South America, Europe, and Japan.

Data Leak Exposes User Information From Car-Sharing Service Blink Mobility

21 December 2023
The leaked information, including phone numbers, email addresses, encrypted passwords, and vehicle rental details, could be exploited by cybercriminals for financial gain and fraudulent activities.

Healthcare Software Provider Suffers Data Breach Impacting 2.7 Million Patients

21 December 2023
The attack occurred on September 28 and resulted in data being stolen before the hackers encrypted company systems. The breach impacted patients associated with ESO's customers, including hospitals and clinics in the US.

Data Leak at Real Estate Wealth Network Exposes 1.5 Billion Ownership Records

21 December 2023
The leaked data, which included information on property history, tax records, and mortgage details, could be exploited by threat actors for social engineering and financial fraud.

Cost of a Data Breach Report 2023: Insights, Mitigators and Best Practices

21 December 2023
John Hanley of IBM Security shares 4 key findings from the highly acclaimed annual Cost of a Data Breach Report 2023 What is the IBM Cost of a Data Breach Report? The IBM Cost of a Data Breach Report is an annual report that provides organizations with quantifiable information about the financial impacts of breaches. With this data, they can make data driven decisions about how they implement

German Authorities Dismantle Dark Web Hub 'Kingdom Market' in Global Operation

21 December 2023
German law enforcement has announced the disruption of a dark web platform called Kingdom Market that specialized in the sales of narcotics and malware to "tens of thousands of users." The exercise, which involved collaboration from authorities from the U.S., Switzerland, Moldova, and Ukraine, began on December 16, 2023, the Federal Criminal Police Office (BKA) said. Kingdom

Indian Banking Customers Targeted by Phishing Campaign Distributing Trojan as Fake Verification Tool

21 December 2023
The trojan is distributed through WhatsApp messages, prompting users to download an APK for a mandatory verification procedure. Once installed, it collects personal and financial information and intercepts SMS messages to steal verification codes.

German Police Seized the Dark Web Marketplace Kingdom Market

21 December 2023
The German police, along with international law enforcement agencies, have seized the dark web marketplace Kingdom Market, which offered drugs, malware, stolen data, and forged documents.

Crypto Scammers Abuse Twitter ‘Feature’ to Impersonate High-Profile Accounts

21 December 2023
The scam tweets often appear to be from well-known crypto accounts like Binance and Ethereum, but they lead to unrelated users promoting fake giveaways, wallet-draining websites, and pump-and-dump schemes.

The Impact of Prompt Injection in LLM Agents

21 December 2023
Prompt injection poses a significant threat to LLM integrity, especially when LLM-powered agents interact with external systems, and safeguarding their operations requires meticulous attention to confidentiality levels and access controls.

Mozilla Patches Firefox Vulnerability Allowing Remote Code Execution, Sandbox Escape

21 December 2023
The security updates for Firefox 121 include patches for critical vulnerabilities like a heap buffer overflow bug in WebGL and a side-channel attack vulnerability in Network Security Services (NSS) NIST curves.