Latest Cybersecurity News and Articles


Delta Dental of California Data Breach Exposed Info of Seven Million People

16 December 2023
Delta Dental of California and its affiliates have suffered a data breach, affecting almost seven million patients. The breach occurred through a vulnerability in the MOVEit Transfer software, allowing unauthorized access by threat actors.

PikaBot Distributed via Malicious Search Ads

16 December 2023
Threat actors are bypassing Google's security measures and using fingerprinting techniques to ensure successful execution of malicious downloads, pointing to a potential "malvertising as a service" model.

New NKAbuse Malware Exploits NKN Blockchain Tech for DDoS Attacks

16 December 2023
Researchers have discovered a new multi-platform threat called NKAbuse that uses a decentralized network connectivity protocol called NKN to communicate. NKAbuse leverages blockchain technology to conduct DDoS attacks and function as an implant.

Microsoft Warns of Storm-0539: The Rising Threat Behind Holiday Gift Card Frauds

16 December 2023
Microsoft is warning of an uptick in malicious activity from an emerging threat cluster it's tracking as Storm-0539 for orchestrating gift card fraud and theft via highly sophisticated email and SMS phishing attacks against retail entities during the holiday shopping season. The goal of the attacks is to propagate booby-trapped links that direct victims to adversary-in-the-middle (AiTM

UTSA names David Brown as next NSCC executive director

15 December 2023
The University of Texas at San Antonio has announced David Brown as the new executive director of its National Security Collaboration Center (NSCC) and professor of practice.

Researchers Detect Undocumented 8220 Gang Activities

15 December 2023
The 8220 gang, a Chinese-origin threat actor, continues to target Windows and Linux web servers with cryptojacking malware using evolving tactics and known vulnerabilities.

Ledger dApp Supply Chain Attack Steals $600K From Crypto Wallets

15 December 2023
Ledger users are advised to avoid using web3 dApps following a supply chain attack on the Ledger dApp Connect Kit library, which resulted in the theft of $600,000 worth of crypto and NFTs.

ALPHV Ransomware Gang Returns, Sorta

15 December 2023
The ALPHV ransomware gang is facing technical difficulties, with their leak site showing only one victim and negotiation links not working, potentially leaving them without payment.

Ten New Android Banking Trojans Targeted 985 Bank Apps in 2023

15 December 2023
The emergence of ten new Android banking malware families in 2023 highlights the increasing sophistication and capabilities of these trojans, including automated transfer systems, social engineering tactics, and live screen-sharing capabilities.

Data of Over a Million Users of the Crypto Exchange GokuMarket Exposed

15 December 2023
The centralized crypto exchange GokuMarket, owned by ByteX, left an open instance, exposing sensitive user data, including IP addresses, email addresses, encrypted passwords, and crypto wallet addresses.

New KV-Botnet Targeting Cisco, DrayTek, and Fortinet Devices for Stealthy Attacks

15 December 2023
A new botnet consisting of firewalls and routers from Cisco, DrayTek, Fortinet, and NETGEAR is being used as a covert data transfer network for advanced persistent threat actors, including the China-linked threat actor called Volt Typhoon. Dubbed KV-botnet by the Black Lotus Labs team at Lumen Technologies, the malicious network is an amalgamation of two complementary activity

BianLian, White Rabbit, and Mario Ransomware Gangs Spotted in a Joint Extortion Campaign

15 December 2023
The ransomware gangs utilized a "password spraying" attack and compromised email accounts through Business Email Compromise (BEC) to anonymously deliver ransom payment demands and complicate investigations.

Four Charged in Connection With $80m Pig Butchering Scheme

15 December 2023
The fraudsters used shell companies and bank accounts to launder the proceeds of pig butchering scams, where victims were lured into cryptocurrency investment schemes and deceived into transferring funds to the scammers.

New Pierogi++ Malware by Gaza Cyber Gang Targeting Palestinian Entities

15 December 2023
The discovery of the new updated Pierogi++ malware suggests that the group is continuously refining its tactics and tools to maintain persistent access to targeted networks.

Crypto Hardware Wallet Ledger's Supply Chain Breach Results in $600,000 Theft

15 December 2023
Crypto hardware wallet maker Ledger published a new version of its "@ledgerhq/connect-kit" npm module after unidentified threat actors pushed malicious code that led to the theft of more than $600,000 in virtual assets. The compromise was the result of a former employee falling victim to a phishing attack, the company said in a statement. This allowed the attackers to gain

UK Plans Tough New Security Rules for Datacenters

15 December 2023
Under the current proposals, datacenter providers would have a “duty to take appropriate and proportionate technical and organizational measures” to manage security and resilience risk.

80% predict burnout will have significant effect on businesses

15 December 2023
The global perma-crisis is set to continue to take its toll in 2024, as extreme weather events continue to impact organizations and global instability deepens. 

Kraft Heinz Reviewing Claims of Cyberattack but Internal Systems ‘Operating Normally’

15 December 2023
Kraft Heinz is investigating claims of a data breach by the Snatch ransomware gang, but currently sees no evidence of a broader attack or adverse effects on its internal systems.

Dental Plan Administrator Fined $400K for Phishing Breach

15 December 2023
The settlement requires the company to implement data retention policies, use multifactor authentication, encrypt private information, and have a Chief Information Security Officer (CISO) reporting to the CEO regularly.

Iranian State-Sponsored OilRig Group Deploys Three New Malware Downloaders

15 December 2023
The downloaders named ODAgent, OilCheck, and OilBooster, along with an updated version of SampleCheck5000, were used to blend with authentic network traffic and cover up the group's attack infrastructure.