Latest Cybersecurity News and Articles


Data breach affects Michigan healthcare companies

04 December 2023
The Michigan Attorney General announced that Corewell Health suffered a data breach affecting Michigan residents, including Social Security numbers.

More Than 1,500 Hugging Face API Tokens Exposed, Major Projects Vulnerable

04 December 2023
The exposed API tokens had write permissions, allowing attackers to modify files in account repositories and potentially manipulate existing models, posing a significant threat to organizations and their applications.

UK schoolgirls secure victory as champions of NCSC cyber skills contest

04 December 2023
Teams of schoolgirls from across the UK have been crowned cyber security champions.

Depauw University Warns of Data Breach as Ransomware Attacks on Colleges Surge

04 December 2023
The attack on DePauw University was conducted by the Black Suit ransomware gang, highlighting the increasing trend of ransomware attacks targeting educational institutions.

New Variant of P2Pinfect Targets MIPS Devices Including Routers and IoT Devices

04 December 2023
The new variant includes updated evasion techniques, such as Virtual Machine detection, debugger detection, and anti-forensics measures on Linux hosts, making it more difficult for researchers to analyze.

New BLUFFS Bluetooth Attack Expose Devices to Adversary-in-the-Middle Attacks

04 December 2023
New research has unearthed multiple novel attacks that break Bluetooth Classic's forward secrecy and future secrecy guarantees, resulting in adversary-in-the-middle (AitM) scenarios between two already connected peers. The issues, collectively named BLUFFS, impact Bluetooth Core Specification 4.2 through 5.4. They are tracked under the identifier CVE-2023-24023 (CVSS score: 6.8)

Astrology Website WeMystic Exposes Over 13 Million User Records

04 December 2023
The astrology and spiritual content platform WeMystic exposed the sensitive data of its users, including names, email addresses, and dates of birth, due to an open and passwordless MongoDB database.

Make a Fresh Start for 2024: Clean Out Your User Inventory to Reduce SaaS Risk

04 December 2023
As work ebbs with the typical end-of-year slowdown, now is a good time to review user roles and privileges and remove anyone who shouldn’t have access as well as trim unnecessary permissions. In addition to saving some unnecessary license fees, a clean user inventory significantly enhances the security of your SaaS applications. From reducing risk to protecting against data leakage, here is how

Bridging the Gap Between Cloud vs On-Premise Security

04 December 2023
It is crucial to maintain unified visibility, control, and management across both cloud-based and on-premise security measures to bridge the gap and create a comprehensive and future-proof security stack.

New P2PInfect Botnet MIPS Variant Targeting Routers and IoT Devices

04 December 2023
Cybersecurity researchers have discovered a new variant of an emerging botnet called P2PInfect that's capable of targeting routers and IoT devices. The latest version, per Cado Security Labs, is compiled for Microprocessor without Interlocked Pipelined Stages (MIPS) architecture, broadening its capabilities and reach. "It's highly likely that by targeting MIPS, the P2PInfect developers

New Proxy Malware Targets Mac Users Through Pirated Software

04 December 2023
The proxy trojan connects to a command and control server via DNS-over-HTTPS and supports creating TCP or UDP connections, indicating a sophisticated and wide-ranging campaign targeting multiple systems.

Update: New Relic Admits Attack on Staging Systems, User Accounts

04 December 2023
Web tracking and analytics company New Relic has disclosed a cyberattack on its staging systems, which were compromised in mid-November by an unauthorized actor using stolen credentials and social engineering.

UK schoolgirls secure victory as champions of NCSC cyber skills contest

04 December 2023
Teams of schoolgirls from across the UK have been crowned cyber security champions.

NCSC launches Cyber Incident Exercising scheme

04 December 2023
New CIE assured providers give organisations support to create structured table-top or live-play cyber incident exercises.

The European Space Agency Explores Cybersecurity for Space Industry

04 December 2023
The European Space Agency is developing a Space Cybersecurity Operations Centre (C-SOC) to detect and respond to emerging cyberattacks on space system infrastructures and the space industry.

Linux Version of Qilin Ransomware Focuses on VMware ESXi

04 December 2023
The Linux encryptor includes extensive command-line options for customization, allowing threat actors to specify exclusion and encryption criteria, as well as configure virtual machines that should not be encrypted.

Account Takeover Attacks Use ScrubCrypt to Deploy RedLine Stealer Malware

04 December 2023
The initial stage of the infection involves a .bat file delivered through social engineering, containing a base64-encoded payload??. This leads to an obfuscated .NET executable file as the next infection stage??.

The Current State of Open RAN Security

04 December 2023
The Open Radio Access Network (ORAN) architecture, while providing standardized interfaces and protocols, is vulnerable to attacks through malicious xApps that can compromise the entire RAN Intelligent Controller (RIC) subsystem.

US Health Department Urges Hospitals to Patch Critical Citrix Bleed Bug

04 December 2023
The U.S. Department of Health and Human Services (HHS) has warned hospitals about the actively exploited Citrix Bleed vulnerability used by ransomware gangs to breach networks, emphasizing the urgent need for patching.

US Man Jailed Eight Years for SIM Swapping and Apple Support Impersonation

04 December 2023
The scams involved SIM swapping, social media account takeovers, Zelle payment fraud, and impersonating Apple Support personnel to steal money, NFTs, cryptocurrency, and other valuable digital property.