Latest Cybersecurity News and Articles
15 December 2023
Approval phishing scams have been used to steal at least $1bn in crypto since May 2021, as per a new report by Chainalysis. This technique, frequently used by romance scammers, is estimated to have led to losses of at least $374m so far in 2023.
15 December 2023
Web Application Security consists of a myriad of security controls that ensure that a web application:
Functions as expected.
Cannot be exploited to operate out of bounds.
Cannot initiate operations that it is not supposed to do.
Web Applications have become ubiquitous after the expansion of Web 2.0, which Social Media Platforms, E-Commerce websites, and email clients saturating the internet
15 December 2023
Multiple security vulnerabilities have been discovered in the open-source Netgate pfSense firewall solution called pfSense that could be chained by an attacker to execute arbitrary commands on susceptible appliances.
The issues relate to two reflected cross-site scripting (XSS) bugs and one command injection flaw, according to new findings from Sonar.
"Security inside a local network is often
15 December 2023
The attackers have gained access to sensitive data, including employee records, law enforcement videos, emails, and confidential documents. The City of Defiance has not yet responded to the incident.
15 December 2023
Threat actors are increasingly using vulnerability exploitation instead of phishing emails to compromise victims with ransomware, according to insurance company Corvus Insurance.
15 December 2023
Despite increased monitoring, getting supply chain vendors to address security issues in a timely manner remains a challenge, with only 19% of respondents actively working with their suppliers to remediate issues, according to BlueVoyant.
15 December 2023
The Russia-based actor is targeting organisations and individuals in the UK and other geographical areas of interest.
15 December 2023
Despite a patch being issued, the exploitation of CitrixBleed has continued, highlighting the challenges of vendor security management and the need for organizations to take immediate action to mitigate the vulnerability.
15 December 2023
The IT network of New York-based health providers, including HealthAlliance Hospital, Margaretville Hospital, and Mountainside Residential Care Center, was breached for nearly two months, resulting in the compromise of patient data.
15 December 2023
The Federal Communications Commission (FCC) has updated its data breach rules for the first time in 16 years. The new rules expand the definition of a breach and specify who should be notified.
15 December 2023
Karakurt uses various tactics to steal data and extort victims for ransom. They contact victims' employees, business partners, and clients to pressure them into paying the ransom.
15 December 2023
Wyoming LLCs are being implicated in high-profile hacking activities, attracting cybercriminals due to the state's easy registration process for anonymous shell companies.
15 December 2023
MITRE has launched EMB3D, a new threat model framework to help defenders protect operational technology and industrial control systems by mapping cyber threats with vulnerabilities and flaws.
15 December 2023
Google on Thursday announced that it will start testing a new feature called "Tracking Protection" starting January 4, 2024, to 1% of Chrome users as part of its efforts to deprecate third-party cookies in the web browser.
The setting is designed to limit "cross-site tracking by restricting website access to third-party cookies by default," Anthony Chavez, vice president of Privacy
15 December 2023
The hackers accessed an off-site data center used for human resources services, compromising personal information such as names, social security numbers, salary details, and banking information.
15 December 2023
A novel multi-platform threat called NKAbuse has been discovered using a decentralized, peer-to-peer network connectivity protocol known as NKN (short for New Kind of Network) as a communications channel.
"The malware utilizes NKN technology for data exchange between peers, functioning as a potent implant, and equipped with both flooder and backdoor capabilities," Russian
14 December 2023
The Federal Communications Commission (FCC) has officially adopted changes to data breach notification rules for communication companies.
14 December 2023
Cybersecurity in the workplace was analyzed in a report, where 66% of respondents flagged completing daily tasks as more crucial than cybersecurity.
14 December 2023
On Dec. 18, 2013, KrebsOnSecurity broke the news that U.S. retail giant Target was battling a wide-ranging computer intrusion that compromised more than 40 million customer payment cards over the previous month. The malware used in the Target breach included the text string "Rescator," which also was the handle chosen by the cybercriminal who was selling all of the cards stolen from Target customers. Ten years later, KrebsOnSecurity has uncovered new clues about the real-life identity of Rescator.
14 December 2023
Google is using Clang sanitizers to enhance the security of the cellular baseband in Android. The sanitizers, including IntSan and BoundSan, detect and prevent vulnerabilities in program execution.