Latest Cybersecurity News and Articles


TrickBot Developer Pleads Guilty in US Court

04 December 2023
A Russian national, Vladimir Dunaev, has pleaded guilty for his involvement in developing TrickBot malware, which targeted hospitals and healthcare centers with ransomware attacks during the COVID-19 pandemic.

Over 20,000 Vulnerable Microsoft Exchange Servers Exposed to Attacks

04 December 2023
Over 30,000 servers have reached the end-of-life stage, with many still vulnerable to critical security issues. Some of these vulnerabilities can lead to remote code execution.

LogoFAIL: UEFI Vulnerabilities Expose Devices to Stealth Malware Attacks

04 December 2023
The Unified Extensible Firmware Interface (UEFI) code from various independent firmware/BIOS vendors (IBVs) has been found vulnerable to potential attacks through high-impact flaws in image parsing libraries embedded into the firmware. The shortcomings, collectively labeled LogoFAIL by Binarly, "can be used by threat actors to deliver a malicious payload and bypass Secure Boot, Intel

DJvu ransomware Latest Variant Xaro Emerges in the Threat Landscape

04 December 2023
A variant of the DJvu ransomware, named Xaro, has been identified in a campaign that leverages cracked software for distribution. Xaro is spread through an archive file masquerading as legitimate freeware. Organizations are advised to whitelist apps or sites to stay safe.

Microsoft Warns of Malvertising Scheme Spreading CACTUS Ransomware

03 December 2023
Microsoft has warned of a new wave of CACTUS ransomware attacks that leverage malvertising lures to deploy DanaBot as an initial access vector. The DanaBot infections led to "hands-on-keyboard activity by ransomware operator Storm-0216 (Twisted Spider, UNC2198), culminating in the deployment of CACTUS ransomware," the Microsoft Threat Intelligence team said in a series of posts on X (

NCSC statement following exploitation of Unitronics programmable logic controllers

02 December 2023
NCSC supports mitigation advice in advisory regarding exploitation of Unitronics programmable logic controllers used in the water sector and across a range of other industries.

Agent Racoon Backdoor Targets Organizations in Middle East, Africa, and U.S.

02 December 2023
Organizations in the Middle East, Africa, and the U.S. have been targeted by an unknown threat actor to distribute a new backdoor called Agent Racoon. "This malware family is written using the .NET framework and leverages the domain name service (DNS) protocol to create a covert channel and provide different backdoor functionalities," Palo Alto Networks Unit 42 researcher Chema Garcia 

North Korea's Lazarus Group Rakes in $3 Billion from Cryptocurrency Hacks

02 December 2023
The Lazarus Group, linked to North Korea, has exploited decentralized finance (DeFi) protocols to steal cryptocurrency and launder funds, contributing to the rise of DeFi hacking in 2022.

Russian Hacker Vladimir Dunaev Convicted for Creating TrickBot Malware

02 December 2023
A Russian national has been found guilty in connection with his role in developing and deploying a malware known as TrickBot, the U.S. Department of Justice (DoJ) announced. Vladimir Dunaev, 40, was arrested in South Korea in September 2021 and extradited to the U.S. a month later. "Dunaev developed browser modifications and malicious tools that aided in credential harvesting and data

60 US Credit Unions Offline After Cloud Ransomware Infection

02 December 2023
The affected IT provider, Ongoing Operations, was infiltrated through the Citrix Bleed vulnerability, emphasizing the importance of robust cybersecurity measures and patching vulnerabilities promptly.

Expert Warns of Turtle macOS Ransomware

02 December 2023
While the Turtle ransomware may not pose a significant risk to macOS users currently, its existence highlights the ongoing efforts by ransomware authors to target Apple devices.

Surgical Practice Notifying 437,400 Patients of Data Theft

02 December 2023
Proliance Surgeons, a large Seattle-based surgical group, suffered a ransomware attack and data theft, potentially compromising the personal information of nearly 437,400 individuals.

Update: 23andMe Says Hackers Accessed ‘Significant Number’ of Files About Users’ Ancestry

01 December 2023
Genetic testing company 23andMe experienced a data breach, with hackers accessing around 14,000 customer accounts and potentially compromising the personal information of other users connected to those accounts.

FTC creates compulsory process for legal issues involving AI

01 December 2023
The Federal Trade Commission (FTC) approved a compulsory process regarding fraud investigations involving artificial intelligence (AI).

US Government Sanctions North Korea’s Kimsuky Hacking Group

01 December 2023
Kimsuky is known for its aggressive social engineering tactics and targets governments, nuclear organizations, and foreign relations entities to gather intelligence for North Korea's interests.

XDSpy Hackers Attack Military-Industrial Companies in Russia

01 December 2023
XDSpy has a history of targeting Russia's government, military, financial institutions, as well as energy, research, and mining companies, demonstrating a focus on strategic organizations in Eastern Europe.

Simple Hacking Technique can Extract ChatGPT Training Data

01 December 2023
Researchers from Google DeepMind, Cornell University, and other institutions have discovered that the popular AI chatbot ChatGPT is susceptible to leaking data when prompted to repeat certain words.

Anna Mercardo Clark hired as Chief Information Security Officer at Phillips Lytle

01 December 2023
Anna Mercado Clark has been hired as the first Phillips Lytle CISO. Clark has worked in data privacy and cybersecurity for the company for 12 years.

Anna Mercardo Clark hired as Chief Information Security Officer at Phyllis Lytle

01 December 2023
Anna Mercado Clark has been hired as the first Phillips Lytle CISO. Clark has worked in data privacy and cybersecurity for the company for 12 years.

BlueVoyant Raises $140M, Buys Resilience Firm Conquest Cyber

01 December 2023
The integration of BlueVoyant and Conquest Cyber will provide customers with more self-service capabilities and autonomous operations through the use of AI, machine learning, and virtual data lakes.