Latest Cybersecurity News and Articles


CISA Performance Goals Program Trims Exploited CVEs

07 December 2023
Since the release of the CPG program, organizations enrolled in CISA's vulnerability scanning service have reduced their average number of known exploited vulnerabilities by about 20%.

Threat Actors can Leverage AWS STS to Infiltrate Cloud Accounts

07 December 2023
According to the experts, to mitigate AWS token abuse, organizations should log CloudTrail event data, detect role-chaining events and MFA abuse, and rotate long-term IAM user access keys.

Deutsche Wohnen Ruling Set to Drive Up GDPR Fines

07 December 2023
The ruling establishes that a lack of knowledge by management is not a defense, and organizations can be fined based on their own turnover and the turnover of their parent company.

New Bluetooth Flaw Let Hackers Take Over Android, Linux, macOS, and iOS Devices

07 December 2023
A critical Bluetooth security flaw could be exploited by threat actors to take control of Android, Linux, macOS and iOS devices. Tracked as CVE-2023-45866, the issue relates to a case of authentication bypass that enables attackers to connect to susceptible devices and inject keystrokes to achieve code execution as the victim. "Multiple Bluetooth stacks have authentication bypass

New Stealthy 'Krasue' Linux Trojan Targeting Telecom Firms in Thailand

07 December 2023
The deployment vector of Krasue is still unknown, but it is suspected to exploit vulnerabilities, use credential brute-force attacks, or be downloaded as part of a fake software package.

Hacking the Human Mind: Exploiting Vulnerabilities in the 'First Line of Cyber Defense'

07 December 2023
Humans are complex beings with consciousness, emotions, and the capacity to act based on thoughts. In the ever-evolving realm of cybersecurity, humans consistently remain primary targets for attackers. Over the years, these attackers have developed their expertise in exploiting various human qualities, sharpening their skills to manipulate biases and emotional triggers with the objective of

UK and allies expose Russian intelligence services for cyber campaign of attempted political interference

07 December 2023
The UK and allies call out the Russian Intelligence Services for a campaign of malicious cyber activity attempting to interfere in UK politics and democratic processes

UK and allies expose Russian intelligence services for cyber campaign of attempted political interference

07 December 2023
The UK and allies call out the Russian Intelligence Services for a campaign of malicious cyber activity attempting to interfere in UK politics and democratic processes

Russian FSB cyber actor Star Blizzard continues worldwide spear-phishing campaigns

07 December 2023
The Russia-based actor is targeting organisations and individuals in the UK and other geographical areas of interest.

Third-Party Breaches Shake the Foundations of the Energy Sector

07 December 2023
The energy industry's significance and interconnectedness make it a prime target for cyber threats, impacting not only financial losses but also manufacturing, healthcare, and transportation.

US Navy Contractor Austal USA Confirms Cyberattack After Data Leak

07 December 2023
The Hunters International ransomware group claimed responsibility for the breach and threatened to leak more stolen data, including compliance documents and engineering data.

Building a Robust Threat Intelligence with Wazuh

07 December 2023
Threat intelligence refers to gathering, processing, and analyzing cyber threats, along with proactive defensive measures aimed at strengthening security. It enables organizations to gain a comprehensive insight into historical, present, and anticipated threats, providing context about the constantly evolving threat landscape. Importance of threat intelligence in the cybersecurity ecosystem

GST Invoice Billing Inventory App Exposes Sensitive Data to Threat Actors

07 December 2023
The app, used by businesses for invoicing and financial management, had an open Firebase database containing user data such as phone numbers, emails, and addresses, as well as corporate data like names, invoice counts, and bank balances.

Governments May Spy on You by Requesting Push Notifications from Apple and Google

07 December 2023
Unspecified governments have demanded mobile push notification records from Apple and Google users to pursue people of interest, according to U.S. Senator Ron Wyden. "Push notifications are alerts sent by phone apps to users' smartphones," Wyden said. "These alerts pass through a digital post office run by the phone operating system provider -- overwhelmingly Apple or Google. Because of

Report: Challenging the ‘Good Enough’ Cybersecurity Mindset

07 December 2023
A recent survey by CompTIA found that many businesses believe their cybersecurity measures are "good enough," posing a challenge to their cybersecurity initiatives. Nearly 2 in 5 respondents cited this as a challenge.

Report: UK's Sellafield Nuclear Site Hacked by Groups Linked to Russia and China

07 December 2023
The breach was first detected in 2015, but it is still unclear if the malware has been fully eliminated. The compromised systems may have affected sensitive activities such as handling radioactive waste and monitoring for leaks or fires.

UK FCA Warns of Christmas Loan Fee Fraud Surge

07 December 2023
Scammers are exploiting the need for loans for Christmas spending, leading to a surge in loan fee fraud – a type of scam where victims are promised loans they never receive, whilst being tricked into paying an upfront charge as a ‘deposit’ or ‘fee.’

ENISA Publishes Threat Landscape Report on DoS Attacks

07 December 2023
The ENISA Threat Landscape for DoS Attacks report provides insights into the motivations, goals, and impacts of DoS attacks, highlighting the need for organizations to enhance their defenses and prepare prevention and remediation strategies.

Disney+ Cyber Scheme Exposes New Impersonation Attack Tactics

07 December 2023
In one recent case, attackers sent auto-generated emails with attached PDFs personalized with the recipient's name, detailing an inflated charge for a Disney+ subscription.

US Federal Agencies Miss Deadline for Incident Response Requirements

07 December 2023
A report by the US Government Accountability Office (GAO) has found that 20 US federal agencies have failed to meet the deadline for implementing incident response capabilities required by law.