Latest Cybersecurity News and Articles


Hackers Use new Tool Set in Targeted Attacks Against Middle East, Africa and the US

01 December 2023
A new set of tools, including a backdoor, a credential-stealing module, and a customized version of Mimikatz, has been used in targeted attacks against organizations in the Middle East, Africa, and the U.S.

Russian and Chinese Interference Networks are ‘Building Audiences’ Ahead of 2024, Warns Meta

01 December 2023
Meta has disrupted influence operations from China and Russia, highlighting the challenges posed by generative artificial intelligence and the use of perception hacking to sow doubt in democratic processes.

Update: MGM CFO Expects Insurance to Cover Cyberattack Costs

01 December 2023
The impact of the cyberattack on MGM Resorts was largely felt in September and has been mostly resolved by October, with the company reporting that business is back to normal.

Ukrainian Gets Eight-Year Sentence for Running Marketplace for Americans’ Data

01 December 2023
Vitalii Chychasov, a Ukrainian citizen, has been sentenced to eight years in prison for running a marketplace that sold personal information of millions of Americans, impacting about 24 million people in total.

New FjordPhantom Android Malware Targets Banking Apps in Southeast Asia

01 December 2023
Cybersecurity researchers have disclosed a new sophisticated Android malware called FjordPhantom that has been observed targeting users in Southeast Asian countries like Indonesia, Thailand, and Vietnam since early September 2023. "Spreading primarily through messaging services, it combines app-based malware with social engineering to defraud banking customers," Oslo-based mobile app

Google Unveils RETVec - Gmail's New Defense Against Spam and Malicious Emails

01 December 2023
Integration of RETVec in Gmail has significantly improved spam detection rates, reduced false positives, and decreased computational costs, making it ideal for large-scale applications and on-device models.

Five Resolutions to Prepare for SEC’s New Cyber Disclosure Rules

01 December 2023
The new SEC rules on cybersecurity risk management and incident disclosure will require publicly traded companies to reevaluate their security strategies and provide investors with a greater understanding of the cyber threats they face.

LogoFAIL Bugs in UEFI Code Allow Planting Bootkits via Images

01 December 2023
LogoFAIL is a set of security vulnerabilities that affect the image-parsing components in the UEFI code used by various vendors. These vulnerabilities can be exploited to hijack the booting process and deliver bootkits.

Qakbot Takedown Aftermath: Mitigations and Protecting Against Future Threats

01 December 2023
The U.S. Department of Justice (DOJ) and the FBI recently collaborated in a multinational operation to dismantle the notorious Qakbot malware and botnet. While the operation was successful in disrupting this long-running threat, concerns have arisen as it appears that Qakbot may still pose a danger in a reduced form. This article discusses the aftermath of the takedown, provides mitigation

Chinese Hackers Using SugarGh0st RAT to Target South Korea and Uzbekistan

01 December 2023
A suspected Chinese-speaking threat actor has been attributed to a malicious campaign that targets the Uzbekistan Ministry of Foreign Affairs and South Korean users with a remote access trojan called SugarGh0st RAT. The activity, which commenced no later than August 2023, leverages two different infection sequences to deliver the malware, which is a customized variant of Gh0st RAT 

WhatsApp’s New Secret Code Feature Hides Your Locked Chats

01 December 2023
WhatsApp has introduced a new Secret Code feature that allows users to set a custom password to hide and protect their locked chats. The Chat Lock feature automatically conceals locked chat details from notifications.

Discover How Gcore Thwarted Powerful 1.1Tbps and 1.6Tbps DDoS Attacks

01 December 2023
The most recent Gcore Radar report and its aftermath have highlighted a dramatic increase in DDoS attacks across multiple industries. At the beginning of 2023, the average strength of attacks reached 800 Gbps, but now, even a peak as high as 1.5+ Tbps is unsurprising. To try and break through Gcore’s defenses, perpetrators made two attempts with two different strategies.

English Council Spent $1.4 Million Recovering From Ransomware Attack

01 December 2023
The attack, initiated through a spearphishing email, exposed failures in the council's cybersecurity measures, including the lack of a security information and event management system, hindering the investigation and remediation process.

WhatsApp's New Secret Code Feature Lets Users Protect Private Chats with Password

01 December 2023
Meta-owned WhatsApp has launched a new Secret Code feature to help users protect sensitive conversations with a custom password on the messaging platform. The feature has been described as an "additional way to protect those chats and make them harder to find if someone has access to your phone or you share a phone with someone else." Secret Code builds on another feature

Black Basta Ransomware Made Over $100 Million From Extortion

01 December 2023
Black Basta has collected over $100 million in ransom payments from over 90 victims since April 2022. High-profile victims targeted by Black Basta include the American Dental Association, Sobeys, Knauf, Yellow Pages Canada, and Rheinmetall.

Open-Source LLM Security Scanner Vigil Helps Prevent Prompt Injection

01 December 2023
Vigil focuses on identifying prompt injections, jailbreaks, and other potential vulnerabilities. Its creator, Adam M. Swanda, developed the tool to improve security practices around LLM applications.

New SugarGh0st RAT Targets Uzbekistan Government and South Korea

01 December 2023
The campaign involves the use of Windows Shortcut files embedded with malicious JavaScript to deliver the components of the trojan, and there are indications that a Chinese-speaking threat actor is behind the attacks based on the samples.

PoC for Splunk Enterprise RCE flaw released (CVE-2023-46214)

01 December 2023
The vulnerability arises from the failure to safely sanitize user-supplied extensible stylesheet language transformations (XSLT), enabling attackers to upload malicious XSLT and gain remote access to Splunk Enterprise instances.

Apple Rolls Out iOS, macOS, and Safari Patches for Two Actively Exploited Flaws

01 December 2023
The two actively exploited security flaws, CVE-2023-42916 and CVE-2023-42917, were found in the WebKit web browser engine and could leak sensitive information or allow arbitrary code execution.

North Texas Water Utility Serving Two Million Hit With Cyberattack

01 December 2023
North Texas Municipal Water District (NTMWD) has experienced a cyberattack on its business computer network, but its core water, wastewater, and solid waste services remain unaffected.