Latest Cybersecurity News and Articles


Unmasking the Dark Side of Low-Code/No-Code Applications

18 December 2023
Low-code/no-code (LCNC) and robotic process automation (RPA) have gained immense popularity, but how secure are they? Is your security team paying enough attention in an era of rapid digital transformation, where business users are empowered to create applications swiftly using platforms like Microsoft PowerApps, UiPath, ServiceNow, Mendix, and OutSystems? The simple truth is often swept under

WordPress Hosting Service Kinsta Targeted by Google Phishing Ads

18 December 2023
Users are advised to be vigilant and only access the official kinsta.com or my.kinsta.com websites, enable two-factor authentication, and disregard any suspicious emails or messages claiming to be from Kinsta.

UK's cultural institutions gather for summit on the cyber threat

18 December 2023
Organisations across the UK’s culture sectors have been coached on how to reduce the risk of falling victim to cyber criminals.

Rhadamanthys Stealer Malware Evolves With More Powerful Features

18 December 2023
The malware targets email, FTP, and online banking credentials. The latest version includes a new plugin system for customization, a "Data Spy" plugin for capturing RDP login credentials, and improvements in stealing data from browsers.

Four Apprehended by Indian Authorities in ICMR Data Breach Impacting 800 Million People

18 December 2023
The suspects not only leaked data from the ICMR, but also claimed to have pilfered information from the FBI and Pakistan's CNIC, highlighting the extent of their illegal activities.

QakBot Malware Resurfaces with New Tactics, Targeting the Hospitality Industry

18 December 2023
A new wave of phishing messages distributing the QakBot malware has been observed, more than three months after a law enforcement effort saw its infrastructure dismantled by infiltrating its command-and-control (C2) network. Microsoft, which made the discovery, described it as a low-volume campaign that began on December 11, 2023, and targeted the hospitality industry. "Targets

Malvertising Campaign by UNC2975 Found Distributing Backdoors

18 December 2023
A threat actor known as UNC2975 has been using malicious advertisements to distribute malware since 2021. They create fake websites related to topics like unclaimed money and astrology to trick users into visiting them.

UK's cultural institutions gather for summit on the cyber threat

18 December 2023
Organisations across the UK’s culture sectors have been coached on how to reduce the risk of falling victim to cyber criminals.

UK: Corringham School Apologizes After Sharing Personal Pupil Data

18 December 2023
Ortu Gable Hall School in Essex mistakenly sent an email to parents containing the personal data of 69 pupils who were being disciplined for bad behavior, leading to an apology from the school.

10,000 People’s Data Stolen in Genetic Testing Company Asper Biogene Leak

18 December 2023
Personal and health data belonging to approximately 10,000 people has been illegally downloaded from Asper Biogene's database, making it the biggest data leak recorded in Estonia so far.

Google's New Tracking Protection in Chrome Blocks Third-Party Cookies

18 December 2023
Google will begin testing a new feature called "Tracking Protection" in January 2024 for 1% of Chrome users. The feature aims to restrict third-party cookies by default, limiting cross-site tracking.

Newfound School District Still Working to Recover Data After Cyberattack

18 December 2023
Newfound Area School District in Bristol, New Hampshire, is recovering from a recent cyber breach that was described as a ransomware attack. The attack locked users out of the system, but no financial demand was made.

Employee Files Compromised After Ransomware Attack on Campbell County School District

18 December 2023
The Campbell County School District announced Thursday that it was recently the target of a ransomware incident that allowed an unauthorized person to gain access to employee files.

CISA Urges Manufacturers Eliminate Default Passwords to Thwart Cyber Threats

18 December 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is urging manufacturers to get rid of default passwords on internet-exposed systems altogether, citing severe risks that could be exploited by malicious actors to gain initial access to, and move laterally within, organizations. In an alert published last week, the agency called out Iranian threat actors affiliated with

MongoDB Suffers Security Breach, Exposing Customer Data

16 December 2023
MongoDB on Saturday disclosed it's actively investigating a security incident that has led to unauthorized access to "certain" corporate systems, resulting in the exposure of customer account metadata and contact information. The American database software company said it first detected anomalous activity on December 13, 2023, and that it immediately activated its incident response

Central Bank of Lesotho Facing Outages After Cyberattack

16 December 2023
The ongoing downtime of the National Payments System has made it impossible for local banks in Lesotho to honor inter-bank transactions, requiring alternative measures to facilitate payments.

China's MIIT Introduces Color-Coded Action Plan for Data Security Incidents

16 December 2023
China's Ministry of Industry and Information Technology (MIIT) on Friday unveiled draft proposals detailing its plans to tackle data security events in the country using a color-coded system. The effort is designed to "improve the comprehensive response capacity for data security incidents, to ensure timely and effective control, mitigation and elimination of hazards and losses caused

Ontario Public Library Shuts Down Most Services Due to Cyberattack

16 December 2023
The attack on the library, along with recent ransomware incidents at other major libraries, underscores the need for improved cybersecurity measures and data protection in the library sector.

Delta Dental of California Data Breach Exposed Info of Seven Million People

16 December 2023
Delta Dental of California and its affiliates have suffered a data breach, affecting almost seven million patients. The breach occurred through a vulnerability in the MOVEit Transfer software, allowing unauthorized access by threat actors.

PikaBot Distributed via Malicious Search Ads

16 December 2023
Threat actors are bypassing Google's security measures and using fingerprinting techniques to ensure successful execution of malicious downloads, pointing to a potential "malvertising as a service" model.