Latest Cybersecurity News and Articles


UK: Cambridge Hospitals Admit Two Excel-Based Data Breaches

07 December 2023
A Cambridge NHS trust has admitted to two historic data breaches, involving the accidental disclosure of patient data while responding to Freedom of Information requests.

Dangerous Vulnerability in Fleet Management Software Seemingly Ignored by Vendor

07 December 2023
The vulnerability, which impacts the Syrus4 IoT gateway made by Digital Communications Technologies (DCT), gives hackers access to the software and commands used to manage thousands of vehicles.

Groveport Madison School District Servers Hacked by Ransomware Group

07 December 2023
The BlackSuit ransomware group was able to hack into two servers belonging to the school district, impacting Windows devices, file services, printers, and copiers. Phones were not impacted.

New SLAM Attack Steals Sensitive Data From AMD, Future Intel CPUs

07 December 2023
The SLAM attack exploits hardware features in upcoming CPUs from Intel, AMD, and Arm to obtain the root password hash from kernel memory, highlighting potential security vulnerabilities.

47% of organizations monitored supply chain risks monthly or more

07 December 2023
According to a report, there was a 26% increase in supply chain breaches in 2022 and 9% of organizations are working with suppliers to fix them.

Millions of Patient Scans and Health Records Spilling Online Thanks to Decades-Old DICOM Bug

07 December 2023
Over 3,800 PACS servers across 110 countries are unintentionally exposing the private data of 16 million patients, including names, addresses, and even Social Security numbers.

Apple and Some Linux Distros are Open to Bluetooth Attack

07 December 2023
A Bluetooth authentication bypass vulnerability, tracked as CVE-2023-45866, allows attackers to connect to Apple, Android, and Linux devices and inject keystrokes to run arbitrary commands.

Microsoft Warns of COLDRIVER's Evolving Evading and Credential-Stealing Tactics

07 December 2023
The threat actor known as COLDRIVER has continued to engage in credential theft activities against entities that are of strategic interests to Russia while simultaneously improving its detection evasion capabilities. The Microsoft Threat Intelligence team is tracking under the cluster as Star Blizzard (formerly SEABORGIUM). It's also called Blue Callisto, BlueCharlie (or TAG-53),

TA422’s Dedicated Exploitation Loop—the Same Week After Week

07 December 2023
Russian APT group TA422 has been actively exploiting patched vulnerabilities to target government, aerospace, education, finance, manufacturing, and technology sectors in Europe and North America.

Report: LockBit Remains Top Global Ransomware Threat

07 December 2023
Researchers at ZeroFox found that LockBit was leveraged in more than a quarter of global ransomware and digital extortion (R&DE) attacks in the seven quarters analyzed from January 2022 to September 2023.

Schools in Maine, Indiana and Georgia Contend Ransomware Attacks

07 December 2023
The Henry County Schools district in Georgia and the Hermon School Department in Maine are among the latest victims, with the former experiencing a ransomware attack and the latter having outdated software vulnerabilities exploited.

Microsoft Will Offer Extended Security Updates for Windows 10

07 December 2023
Microsoft will offer Extended Security Updates (ESU) for Windows 10 users after the end of support, but they will have to pay for them. ESUs will provide critical security updates but not new features or design changes.

Nissan Investigates Cyberattack Involving its Systems in Australia and New Zealand

07 December 2023
Nissan's warning to customers to remain vigilant suggests a potential data breach may have occurred, highlighting the ongoing threat to personal information in the automotive industry.

Report shows rise in threat actors exploiting remote access software

07 December 2023
A new report shows increasing instances of remote access software abuse and the rise of cyber adversaries using password-stealers.

CISA Performance Goals Program Trims Exploited CVEs

07 December 2023
Since the release of the CPG program, organizations enrolled in CISA's vulnerability scanning service have reduced their average number of known exploited vulnerabilities by about 20%.

Threat Actors can Leverage AWS STS to Infiltrate Cloud Accounts

07 December 2023
According to the experts, to mitigate AWS token abuse, organizations should log CloudTrail event data, detect role-chaining events and MFA abuse, and rotate long-term IAM user access keys.

Deutsche Wohnen Ruling Set to Drive Up GDPR Fines

07 December 2023
The ruling establishes that a lack of knowledge by management is not a defense, and organizations can be fined based on their own turnover and the turnover of their parent company.

New Bluetooth Flaw Let Hackers Take Over Android, Linux, macOS, and iOS Devices

07 December 2023
A critical Bluetooth security flaw could be exploited by threat actors to take control of Android, Linux, macOS and iOS devices. Tracked as CVE-2023-45866, the issue relates to a case of authentication bypass that enables attackers to connect to susceptible devices and inject keystrokes to achieve code execution as the victim. "Multiple Bluetooth stacks have authentication bypass

New Stealthy 'Krasue' Linux Trojan Targeting Telecom Firms in Thailand

07 December 2023
The deployment vector of Krasue is still unknown, but it is suspected to exploit vulnerabilities, use credential brute-force attacks, or be downloaded as part of a fake software package.

Hacking the Human Mind: Exploiting Vulnerabilities in the 'First Line of Cyber Defense'

07 December 2023
Humans are complex beings with consciousness, emotions, and the capacity to act based on thoughts. In the ever-evolving realm of cybersecurity, humans consistently remain primary targets for attackers. Over the years, these attackers have developed their expertise in exploiting various human qualities, sharpening their skills to manipulate biases and emotional triggers with the objective of