Latest Cybersecurity News and Articles


Dollar Tree Hit by Third-Party Data Breach Impacting Two Million People

30 November 2023
Dollar Tree's service provider, Zeroed-In, suffered a security incident between August 7 and 8, 2023. As part of this cyberattack, the threat actors managed to steal data containing the personal information of Dollar Tree and Family Dollar employees.

Black Basta Ransomware Group Received Over $100 Million From 90 Victims

30 November 2023
The Black Basta ransomware group has infected over 300 victims and received more than $100 million in ransom payments. The post Black Basta Ransomware Group Received Over $100 Million From 90 Victims appeared first on SecurityWeek.

US Sanctions Cryptocurrency Mixer Sinbad for Aiding North Korean Hackers

30 November 2023
US Treasury sanctions Sinbad, saying the cryptocurrency mixer is laundering funds for North Korean hacking group Lazarus. The post US Sanctions Cryptocurrency Mixer Sinbad for Aiding North Korean Hackers appeared first on SecurityWeek.

Black Basta Ransomware Group Makes $100m Since 2022

30 November 2023
It’s long been suspected that Black Basta is an offshoot of Conti, a prolific ransomware group that ceased operations at the time Black Basta began. The new analysis from Corvus highlighted a significant crossover in targeted sectors.

Rhysida Ransomware Group Hacked King Edward VII’s Hospital

30 November 2023
The ransomware group claims to have stolen a substantial trove of ‘sensitive data’ and is auctioning it for 10 BTC. As usual, the Rhysida ransomware operators plan to sell the stolen data to a single buyer.

Palo Alto Networks Unveils New Rugged Firewall for Industrial Environments 

30 November 2023
Palo Alto Networks has launched a new rugged firewall for industrial environments and announced several OT security improvements. The post Palo Alto Networks Unveils New Rugged Firewall for Industrial Environments  appeared first on SecurityWeek.

North Korea's Lazarus Group Rakes in $3 Billion from Cryptocurrency Hacks

30 November 2023
Threat actors from the Democratic People's Republic of Korea (DPRK) are increasingly targeting the cryptocurrency sector as a major revenue generation mechanism since at least 2017 to get around sanctions imposed against the country. "Even though movement in and out of and within the country is heavily restricted, and its general population is isolated from the rest of the world, the regime's

This Free Solution Provides Essential Third-Party Risk Management for SaaS

30 November 2023
Wing Security recently announced that basic third-party risk assessment is now available as a free product. But it raises the questions of how SaaS is connected to third-party risk management (TPRM) and what companies should do to ensure a proper SaaS-TPRM process is in place. In this article we will share 5 tips to manage the third-party risks associated with SaaS, but first...  What exactly is

Dollar Tree Impacted by ZeroedIn Data Breach Affecting 2 Million Individuals

30 November 2023
ZeroedIn says personal information of 2 million individuals was compromised in an August 2023 data breach that impacts customers such as Dollar Tree. The post Dollar Tree Impacted by ZeroedIn Data Breach Affecting 2 Million Individuals appeared first on SecurityWeek.

7 Uses for Generative AI to Enhance Security Operations

30 November 2023
Welcome to a world where Generative AI revolutionizes the field of cybersecurity. Generative AI refers to the use of artificial intelligence (AI) techniques to generate or create new data, such as images, text, or sounds. It has gained significant attention in recent years due to its ability to generate realistic and diverse outputs. When it comes to security operations, Generative AI can play

CACTUS Ransomware Exploits Qlik Sense Vulnerabilities in Targeted Attacks

30 November 2023
A CACTUS ransomware campaign has been observed exploiting recently disclosed security flaws in a cloud analytics and business intelligence platform called Qlik Sense to obtain a foothold into targeted environments. "This campaign marks the first documented instance [...] where threat actors deploying CACTUS ransomware have exploited vulnerabilities in Qlik Sense for initial access," Arctic Wolf

Google’s RETVec Open Source Text Vectorizer Bolsters Malicious Email Detection

30 November 2023
Google shows how RETVec, a new and open source text vectorizer, can improve the detection of phishing attacks, spam and other harmful content. The post Google’s RETVec Open Source Text Vectorizer Bolsters Malicious Email Detection appeared first on SecurityWeek.

Ex-Motorola Tech Pleads Guilty to Cybercrime, Passport Fraud

30 November 2023
While he mostly tried to cover his tracks by using what prosecutors described as "anonymized" Amazon Web Services IP addresses for the scam, law enforcement were able to trace his actions to a Comcast IP address and his Massport email address.

CISA Debuts ‘Secure by Design’ Alert Series

30 November 2023
New CISA alerts shed light on the harm occurring when software vendors fail to implement secure by design principles. The post CISA Debuts ‘Secure by Design’ Alert Series appeared first on SecurityWeek.

Queensland Passes Mandatory Data Breach Notice Laws

30 November 2023
The bill also aligns state privacy law more closely with national privacy principles and reforms the Right to Information framework to reduce barriers to citizens accessing government-held information.

Hundreds of Malicious Android Apps Target Iranian Mobile Banking Users

30 November 2023
Zimperium has identified over 200 information-stealing Android applications targeting mobile banking users in Iran. The post Hundreds of Malicious Android Apps Target Iranian Mobile Banking Users appeared first on SecurityWeek.

U.S. Treasury Sanctions Sinbad Cryptocurrency Mixer Used by North Korean Hackers

30 November 2023
The U.S. Treasury Department on Wednesday imposed sanctions against Sinbad, a virtual currency mixer that has been put to use by the North Korea-linked Lazarus Group to launder ill-gotten proceeds. "Sinbad has processed millions of dollars' worth of virtual currency from Lazarus Group heists, including the Horizon Bridge and Axie Infinity heists," the department said. "Sinbad is also used by

56% of companies educate workers on AI risks

29 November 2023
According to a Kolide report on AI, there is a significant gap between the percentage of employees allowed to use AI and those who actually use it.

British Afrobeat singer pleads guilty to stealing $6 million in hacks on financial accounts

29 November 2023
According to the Department of Justice, from 2011 until 2018 Mustapha and his unnamed co-conspirators siphoned funds from financial accounts whose login information they illegally accessed through phishing attacks.

BlueVoyant Acquires Conquest Cyber to Help Clients Mitigate Risks

29 November 2023
BlueVoyant will integrate Conquest Cyber’s technology into its existing products and services to create the first solution to deliver comprehensive internal and external cyber defense mapped to risk maturity.