Latest Cybersecurity News and Articles


Update: October Cyberattack Leaked Data of 14.7 Million People, Mortgage Giant Mr. Cooper Says

19 December 2023
The accessed data included sensitive details such as names, addresses, phone numbers, Social Security numbers, and bank account numbers of individuals associated with mortgage loans serviced by Mr. Cooper.

8220 Gang Exploiting Oracle WebLogic Server Vulnerability to Spread Malware

19 December 2023
The threat actors associated with the 8220 Gang have been observed exploiting a high-severity flaw in Oracle WebLogic Server to propagate their malware. The security shortcoming is CVE-2020-14883 (CVSS score: 7.2), a remote code execution bug that could be exploited by authenticated attackers to take over susceptible servers. "This vulnerability allows remote authenticated

Double-Extortion Play Ransomware Strikes 300 Organizations Worldwide

19 December 2023
The threat actors behind the Play ransomware are estimated to have impacted approximately 300 entities as of October 2023, according to a new joint cybersecurity advisory from Australia and the U.S. "Play ransomware actors employ a double-extortion model, encrypting systems after exfiltrating data and have impacted a wide range of businesses and critical infrastructure organizations in North

Pro-China Influence Operation Gained YouTube Following, Researchers Find

18 December 2023
The campaign utilizes a network of at least 30 YouTube channels and employs tactics associated with both Russian and Chinese influence operations, including the use of artificially generated voices in videos.

ALPHV Second Most Prominent Ransomware Strain Before Reported Downtime

18 December 2023
ALPHV was the second-most leveraged ransomware strain in North America and Europe between January 2022 and October 2023, just before the reported takedown of the group’s website, according to ZeroFox research.

65% of organizations say ransomware concerns impact risk management

18 December 2023
Enterprise risk management in the financial sector was analyzed in a report where 65% of organizations say ransomware concerns impact risk management.

Microsoft Warns of Storm-0539: The Rising Threat Behind Holiday Gift Card Frauds

18 December 2023
Storm-0539 not only targets gift card-related services for fraud but also collects sensitive information, such as emails and network configurations, for follow-on attacks against the same organizations.

Beware: Experts Reveal New Details on Zero-Click Outlook RCE Exploits

18 December 2023
Technical details have emerged about two now-patched security flaws in Microsoft Windows that could be chained by threat actors to achieve remote code execution on the Outlook email service sans any user interaction. "An attacker on the internet can chain the vulnerabilities together to create a full, zero-click remote code execution (RCE) exploit against Outlook clients," Akamai security

UK National Grid Pulls Chinese Equipment Over Cybersecurity Concerns

18 December 2023
The contract with NR Electric UK, a subsidiary of China's Nari Technology, was terminated without reason given in April, highlighting growing concerns over Chinese involvement in critical infrastructure.

Ubiquiti Fixes Glitch That Exposed Private Video Streams to Other Customers

18 December 2023
The bug was caused by a misconfiguration during an upgrade to Ubiquiti's cloud infrastructure, resulting in 1,216 accounts being improperly associated with another group of 1,177 accounts.

Top 7 Trends Shaping SaaS Security in 2024

18 December 2023
Over the past few years, SaaS has developed into the backbone of corporate IT. Service businesses, such as medical practices, law firms, and financial services firms, are almost entirely SaaS based. Non-service businesses, including manufacturers and retailers, have about 70% of their software in the cloud.  These applications contain a wealth of data, from minimally sensitive general

Rhadamanthys Malware: Swiss Army Knife of Information Stealers Emerges

18 December 2023
The developers of the information stealer malware known as Rhadamanthys are actively iterating on its features, broadening its information-gathering capabilities and also incorporating a plugin system to make it more customizable. This approach not only transforms it into a threat capable of delivering "specific distributor needs," but also makes it more potent, Check Point said&

MongoDB Investigates Data Breach Impacting Customer Account Information

18 December 2023
The breach was detected on December 13, and the company is currently investigating the incident. MongoDB believes that customer data stored in their Atlas platform was not accessed, but customer account metadata and contact information were exposed.

InfectedSlurs Botnet Targets QNAP VioStor NVR Vulnerability

18 December 2023
Default admin credentials and outdated, unsupported networked systems are being exploited as routes for botnet infections, highlighting the importance of updating and securing legacy systems.

NY Engineer Pleads Guilty to Stealing Millions From Two Crypto Exchanges

18 December 2023
A former security engineer has pleaded guilty to hacking two decentralized cryptocurrency exchanges, resulting in the theft of over $12 million. The hacker exploited vulnerabilities in the smart contracts of the exchanges.

Four U.S. Nationals Charged in $80 Million Pig Butchering Crypto Scam

18 December 2023
Four U.S. nationals have been charged for participating in an illicit scheme that earned them more than $80 million via cryptocurrency investment scams. The defendants – Lu Zhang, 36, of Alhambra, California; Justin Walker, 31, of Cypress, California; Joseph Wong, 32, Rosemead, California; and Hailong Zhu, 40, Naperville, Illinois – have been charged with conspiracy to commit money laundering,

Qbot Malware Returns in Campaign Targeting Hospitality Industry

18 December 2023
The malware is being distributed through emails pretending to be from an IRS employee, with recipients unknowingly downloading the QakBot DLL when attempting to view a PDF attachment.

Fortifying Cyber Defenses: A Proactive Approach to Ransomware Resilience

18 December 2023
Investing in cutting-edge cybersecurity tools not only enhances defensive capabilities but also stimulates innovation and fosters public-private partnerships to strengthen the nation's cyber defenses.

Hunters International Ransomware Gang Claims to Have Hacked the Fred Hutch Cancer Center

18 December 2023
Patients have received email threats, stating that their personal information has been compromised. The center has taken impacted systems offline, notified law enforcement, and launched an investigation.

China's MIIT Introduces Color-Coded Action Plan for Data Security Incidents

18 December 2023
The new rules require affected companies to assess the severity of the incident and report it immediately to the local industry supervision department without omitting or concealing any facts.