Latest Cybersecurity News and Articles


81% of companies had malware, phishing and password attacks in 2023

12 December 2023
According to a recent report, 81% of organizations faced malware, phishing and password attacks last year which were mainly targeted at users.

Unveiling the Cyber Threats to Healthcare: Beyond the Myths

12 December 2023
Let's begin with a thought-provoking question: among a credit card number, a social security number, and an Electronic Health Record (EHR), which commands the highest price on a dark web forum?  Surprisingly, it's the EHR, and the difference is stark: according to a study, EHRs can sell for up to $1,000 each, compared to a mere $5 for a credit card number and $1 for a social

Russian APT28 Hackers Targeting 13 Nations in Ongoing Cyber Espionage Campaign

12 December 2023
The Russian APT28 threat actor, also known as ITG05, is using authentic documents related to the Israel-Hamas war as lures to deliver a custom backdoor called HeadLace against targeted entities in 13 countries, primarily in Europe.

Over 1,450 pfSense Servers Exposed to RCE Attacks via Bug Chain

12 December 2023
Around 1,450 instances of pfSense, an open-source firewall and router software, are vulnerable to command injection and cross-site scripting flaws. These flaws, if exploited together, could allow attackers to execute remote code on the system.

Threat Actor TA4557 Targets Recruiters With Malware

12 December 2023
The threat actor uses techniques such as sending URLs to fake resume websites or attachments containing instructions to visit the website, leading to the download of malicious files.

Russian APT28 Hackers Targeting 13 Nations in Ongoing Cyber Espionage Campaign

12 December 2023
The Russian nation-state threat actor known as APT28 has been observed making use of lures related to the ongoing Israel-Hamas war to facilitate the delivery of a custom backdoor called HeadLace. IBM X-Force is tracking the adversary under the name ITG05, which is also known as BlueDelta, Fancy Bear, Forest Blizzard (formerly Strontium), FROZENLAKE, Iron Twilight, Sednit, Sofacy, and

Gamers Warned of Potential CS2 Exploit That can Reveal IP Addresses

12 December 2023
The exploit, which is an XSS vulnerability, allows players to display GIFs using HTML code blocks in-game. This poses a potential security threat to players, as the exploit can access player IP addresses and potentially execute code on their PCs.

Long-Running Clearview AI Class Action Biometric Privacy Case Settles

12 December 2023
Clearview AI has reached a settlement in a class-action privacy lawsuit, which alleged that the company violated Illinois' Biometric Information Privacy Act (BIPA) by using online images without consent for its facial recognition technology.

Fake LinkedIn Profiles Target Saudi Workers for Information Leakage and Financial Fraud

12 December 2023
Researchers have discovered nearly a thousand fake profiles created with the intention of reaching out to companies in the Middle East. These profiles, often difficult to distinguish from real ones, have been successful in their campaigns.

Security Automation Gains Traction, Prompting a “Shift Everywhere” Philosophy

12 December 2023
According to Synopsys, the use of automated security technology is on the rise, as organizations increasingly embrace the "shift everywhere" philosophy to improve the effectiveness and reduce the cost of security activities.

50K WordPress Sites Exposed to RCE Attacks by Critical Bug in Backup Plugin

12 December 2023
The vulnerability, tracked as CVE-2023-6553, can be exploited by unauthenticated attackers without user interaction. Although a patch has been released, almost 50,000 WordPress websites still remain vulnerable to this critical security flaw.

Cybercriminals Continue Targeting Open Remote Access Products

12 December 2023
According to WatchGuard, cybercriminals are still primarily targeting open remote access products and using legitimate remote access tools to hide their malicious activities.

Nearly 130,000 Affected by Ransomware Attack on Cold Storage Company Americold

12 December 2023
The cyberattack resulted in the leak of sensitive data, including names, addresses, Social Security numbers, financial account information, and employment-related health insurance and medical information.

Non-Human Access is the Path of Least Resistance: A 2023 Recap

12 December 2023
2023 has seen its fair share of cyber attacks, however there’s one attack vector that proves to be more prominent than others - non-human access. With 11 high-profile attacks in 13 months and an ever-growing ungoverned attack surface, non-human identities are the new perimeter, and 2023 is only the beginning.  Why non-human access is a cybercriminal’s paradise  People always

Leader of Russian Hacktivist Group Killnet ‘Retires,’ Appoints New Head

12 December 2023
Killmilk, the leader of the pro-Russia hacktivist group Killnet, has announced his retirement. Killmilk, whose alleged identity was recently uncovered as Nikolai Serafimov, cited the toll of Russia's war in Ukraine as the reason for his departure.

Toyota Financial Services Discloses Data Breach Affecting German Customers

12 December 2023
Toyota Financial Services (TFS) has suffered a data breach, exposing sensitive personal and financial data. The breach affected German customers, with threat actors gaining access to names, addresses, contract information, and bank account details.

UK Police Return $10 Million in Bitcoin Stolen by Chronically-Ill Bed-Bound Thief

12 December 2023
Police in Lancashire, UK have returned around £8 million ($10 million) worth of bitcoin to a man whose cryptocurrency was stolen in 2017. Four people involved in the hack were sentenced earlier this year.

TV Service in UAE Hacked to Show Alleged Atrocities in Palestine

12 December 2023
Viewers saw a message from the hackers and then a fake news broadcast featuring AI-generated news anchor showing alleged atrocities committed by Israel. The incident is still being investigated, and it is unclear who is responsible.

New MrAnon Stealer Malware Targeting German Users via Booking-Themed Scam

12 December 2023
A phishing campaign has been observed delivering an information stealer malware called MrAnon Stealer to unsuspecting victims via seemingly benign booking-themed PDF lures. "This malware is a Python-based information stealer compressed with cx-Freeze to evade detection," Fortinet FortiGuard Labs researcher Cara Lin said. "MrAnon Stealer steals its victims' credentials, system

White House Wants to Set Minimum Cyber Standards for Hospitals, Healthcare

12 December 2023
The White House plans to collaborate with the Department of Health and Human Services to establish minimum cybersecurity standards to protect the healthcare sector from ransomware and other cyber threats.