Latest Cybersecurity News and Articles


Atlassian Releases Critical Software Fixes to Prevent Remote Code Execution

06 December 2023
Atlassian has released software fixes for four critical vulnerabilities (CVE-2022-1471, CVE-2023-22522, CVE-2023-22523, CVE-2023-22524), including a deserialization flaw and remote code execution vulnerabilities in multiple products.

Multiple NFT Collections at Risk by Flaw in Open-Source Library

06 December 2023
A vulnerability in an open-source library used in Web3 smart contracts has been discovered, affecting multiple NFT collections, including Coinbase. Thirdweb has provided mitigations for the impacted contracts and urged owners to take action.

Atlassian Releases Critical Software Fixes to Prevent Remote Code Execution

06 December 2023
Atlassian has released software fixes to address four critical flaws in its software that, if successfully exploited, could result in remote code execution. The list of vulnerabilities is below - CVE-2022-1471 (CVSS score: 9.8) - Deserialization vulnerability in SnakeYAML library that can lead to remote code execution in multiple products CVE-2023-22522 (CVSS score

Russia's AI-Powered Disinformation Operation Targeting Ukraine, U.S., and Germany

06 December 2023
While the reach of the campaign appears to be limited, it highlights the enduring and adaptable nature of Russian information warfare and the need for proactive threat sharing to disrupt such operations.

Federal Agency Breached Through Adobe ColdFusion Vulnerability

06 December 2023
The compromised agency was running outdated versions of the software, indicating the need for federal agencies to prioritize cybersecurity measures such as event logging and timely remediation.

Vast Parcel Delivery Phishing Campaign Discovered

06 December 2023
A new phishing campaign has been discovered that targets individuals with messages about failed deliveries or late payments from major shipping companies. It also involves the use of fake websites that mimic popular brands and postal services.

Qualcomm Releases Details on Chip Vulnerabilities Exploited in Targeted Attacks

06 December 2023
Chipmaker Qualcomm has released more information about three high-severity security flaws that it said came under "limited, targeted exploitation" back in October 2023. The vulnerabilities are as follows - CVE-2023-33063 (CVSS score: 7.8) - Memory corruption in DSP Services during a remote call from HLOS to DSP. CVE-2023-33106 (CVSS score: 8.4) - Memory corruption in

Life insurance company announces data breach through MOVEit

05 December 2023
Pan-American Life Insurance Group (PALIG) announced that consumer data, including biometric data, was compromised through the MOVEit cyberattack. 

95% of executives say AI initiatives will fail without training

05 December 2023
Organization's readiness for AI was analyzed in a recent report by Pluralsight, finding that employee's AI confidence and experience don't match.

15,000 Go Module Repositories on GitHub Vulnerable to Repojacking Attack

05 December 2023
Go modules are particularly susceptible to repojacking due to their decentralized nature, and popular repository namespace retirement countermeasures are not effective in preventing all instances of this attack.

Florida Water Agency Latest to Confirm Cyber Incident as Feds Warn of Nation-State Attacks

05 December 2023
The St. Johns River Water Management District in Florida has confirmed that it responded to a cyberattack last week, amid warnings from top cybersecurity agencies about foreign attacks on water utilities.

Russia's AI-Powered Disinformation Operation Targeting Ukraine, US, and Germany

05 December 2023
The Russia-linked influence operation called Doppelganger has targeted Ukrainian, U.S., and German audiences through a combination of inauthentic news sites and social media accounts. These campaigns are designed to amplify content designed to undermine Ukraine as well as propagate anti-LGBTQ+ sentiment, U.S. military competence, and Germany's economic and social issues, according to a new

Warning for iPhone Users: Experts Warn of Sneaky Fake Lockdown Mode Attack

05 December 2023
A new "post-exploitation tampering technique" can be abused by malicious actors to visually deceive a target into believing that their Apple iPhone is running in Lockdown Mode when it's actually not and carry out covert attacks. The novel, detailed by Jamf Threat Labs in a report shared with The Hacker News, "shows that if a hacker has already infiltrated your device, they can cause

75% of sports-related passwords are reused across accounts

05 December 2023
According to a recent Bitwarden report, 33% of Americans have used a sports-themed password and 75% have reused their sports password across accounts.

Iran-Linked Hackers Claim to Leak Troves of Documents From Israeli Hospital

05 December 2023
A hacker group allegedly linked to Iran, known as Malek Team, has claimed responsibility for a cyberattack on an Israeli hospital, resulting in the leak of thousands of medical records, including those of Israeli soldiers.

Report shows physical security market embracing cloud & hybrid solutions

05 December 2023
A new report shows 44% of end users say more than 25% of their physical security setups are now either in the cloud or use a combination of cloud and on-premises solutions.

International Dog Breeding Organization WALA Exposes 25GB of Pet Owners' Data

05 December 2023
The breach exposes the global customer base of WALA to potential threats like phishing attacks and financial scams, emphasizing the need for affected parties to monitor their financial accounts and implement additional security measures.

OPM Launches Cyber Rotational Program for Feds

05 December 2023
The OPM has launched a new Federal Rotational Cyber Workforce Program, allowing cybersecurity employees in the federal government to apply for rotational opportunities at other agencies to enhance their skills and defend against evolving threats.

Russian APT28 Hackers Exploiting Outlook Bug to Hijack Exchange Accounts

05 December 2023
Microsoft warned that the Russian state-sponsored hacker group APT28 is actively exploiting vulnerabilities in Outlook, WinRAR, and Windows MSHTML to hijack Microsoft Exchange accounts and steal sensitive information.

Generative AI Security: Preventing Microsoft Copilot Data Exposure

05 December 2023
Microsoft Copilot has been called one of the most powerful productivity tools on the planet. Copilot is an AI assistant that lives inside each of your Microsoft 365 apps — Word, Excel, PowerPoint, Teams, Outlook, and so on. Microsoft's dream is to take the drudgery out of daily work and let humans focus on being creative problem-solvers. What makes Copilot a different beast than ChatGPT and