Latest Cybersecurity News and Articles


Report: Approval Phishing Scams Drain $1bn of Cryptocurrency from Victims

15 December 2023
Approval phishing scams have been used to steal at least $1bn in crypto since May 2021, as per a new report by Chainalysis. This technique, frequently used by romance scammers, is estimated to have led to losses of at least $374m so far in 2023.

Bug or Feature? Hidden Web Application Vulnerabilities Uncovered

15 December 2023
Web Application Security consists of a myriad of security controls that ensure that a web application: Functions as expected. Cannot be exploited to operate out of bounds. Cannot initiate operations that it is not supposed to do. Web Applications have become ubiquitous after the expansion of Web 2.0, which Social Media Platforms, E-Commerce websites, and email clients saturating the internet

New Security Vulnerabilities Uncovered in pfSense Firewall Software - Patch Now

15 December 2023
Multiple security vulnerabilities have been discovered in the open-source Netgate pfSense firewall solution called pfSense that could be chained by an attacker to execute arbitrary commands on susceptible appliances. The issues relate to two reflected cross-site scripting (XSS) bugs and one command injection flaw, according to new findings from Sonar. "Security inside a local network is often

Knight Ransomware Group Strikes Ohio City of Defiance to Exfiltrate Data

15 December 2023
The attackers have gained access to sensitive data, including employee records, law enforcement videos, emails, and confidential documents. The City of Defiance has not yet responded to the incident.

Report: Vulnerabilities Now Top Initial Access Route For Ransomware

15 December 2023
Threat actors are increasingly using vulnerability exploitation instead of phishing emails to compromise victims with ransomware, according to insurance company Corvus Insurance.

Organizations Prefer a Combination of AI and Human Analysts to Monitor Their Digital Supply Chain

15 December 2023
Despite increased monitoring, getting supply chain vendors to address security issues in a timely manner remains a challenge, with only 19% of respondents actively working with their suppliers to remediate issues, according to BlueVoyant.

Russian FSB cyber actor Star Blizzard continues worldwide spear-phishing campaigns

15 December 2023
The Russia-based actor is targeting organisations and individuals in the UK and other geographical areas of interest.

CitrixBleed Isn’t Going Away: Security Experts Struggle to Control Critical Vulnerability

15 December 2023
Despite a patch being issued, the exploitation of CitrixBleed has continued, highlighting the challenges of vendor security management and the need for organizations to take immediate action to mitigate the vulnerability.

New York Hospitals’ Patient Data Impacted by Cyberattack

15 December 2023
The IT network of New York-based health providers, including HealthAlliance Hospital, Margaretville Hospital, and Mountainside Residential Care Center, was breached for nearly two months, resulting in the compromise of patient data.

FCC Updates Data Breach Rules, With Consumers in Mind

15 December 2023
The Federal Communications Commission (FCC) has updated its data breach rules for the first time in 16 years. The new rules expand the definition of a breach and specify who should be notified.

FBI, CISA, Treasury, and FinCEN Released Joint Advisory on Karakurt Data Extortion Group

15 December 2023
Karakurt uses various tactics to steal data and extort victims for ransom. They contact victims' employees, business partners, and clients to pressure them into paying the ransom.

'Virtual Wild, Wild West': Cybercriminals use Wyoming shell companies for global hacks

15 December 2023
Wyoming LLCs are being implicated in high-profile hacking activities, attracting cybercriminals due to the state's easy registration process for anonymous shell companies.

MITRE Launches Critical Infrastructure Threat Model Framework

15 December 2023
MITRE has launched EMB3D, a new threat model framework to help defenders protect operational technology and industrial control systems by mapping cyber threats with vulnerabilities and flaws.

Google's New Tracking Protection in Chrome Blocks Third-Party Cookies

15 December 2023
Google on Thursday announced that it will start testing a new feature called "Tracking Protection" starting January 4, 2024, to 1% of Chrome users as part of its efforts to deprecate third-party cookies in the web browser. The setting is designed to limit "cross-site tracking by restricting website access to third-party cookies by default," Anthony Chavez, vice president of Privacy

Update: More Than 45,000 Affected by Cyberattack on Idaho Nuclear Research Lab

15 December 2023
The hackers accessed an off-site data center used for human resources services, compromising personal information such as names, social security numbers, salary details, and banking information.

New NKAbuse Malware Exploits NKN Blockchain Tech for DDoS Attacks

15 December 2023
A novel multi-platform threat called NKAbuse has been discovered using a decentralized, peer-to-peer network connectivity protocol known as NKN (short for New Kind of Network) as a communications channel. "The malware utilizes NKN technology for data exchange between peers, functioning as a potent implant, and equipped with both flooder and backdoor capabilities," Russian

FCC updates data breach notification rules

14 December 2023
The Federal Communications Commission (FCC) has officially adopted changes to data breach notification rules for communication companies.

66% of employees prioritize daily tasks over cybersecurity

14 December 2023
Cybersecurity in the workplace was analyzed in a report, where 66% of respondents flagged completing daily tasks as more crucial than cybersecurity.

Ten Years Later, New Clues in the Target Breach

14 December 2023
On Dec. 18, 2013, KrebsOnSecurity broke the news that U.S. retail giant Target was battling a wide-ranging computer intrusion that compromised more than 40 million customer payment cards over the previous month. The malware used in the Target breach included the text string "Rescator," which also was the handle chosen by the cybercriminal who was selling all of the cards stolen from Target customers. Ten years later, KrebsOnSecurity has uncovered new clues about the real-life identity of Rescator.

Google Using Clang Sanitizers to Protect Android Against Cellular Baseband Vulnerabilities

14 December 2023
Google is using Clang sanitizers to enhance the security of the cellular baseband in Android. The sanitizers, including IntSan and BoundSan, detect and prevent vulnerabilities in program execution.