Latest Cybersecurity News and Articles


Taj Hotel Data Breach Potentially Impacts 1.5 Million Customers

24 November 2023
The breach occurred in November and a threat actor named "Dnacookies" is demanding $5,000 for the full dataset, which includes customers' addresses, mobile numbers, and membership IDs.

Rhysida, the new ransomware gang behind British Library cyber-attack

24 November 2023
Rhysida, the new ransomware gang behind British Library cyber-attack Gang thought to be from Russia or CIS has attacked companies and institutions in several countriesA new name was added to the cyber-rogues’ gallery of ransomware gangs this week after a criminal group called Rhysida claimed responsibility for an attack on the British Library.The library confirmed that personal data stolen in a cyber-attack last month has appeared for sale online. Continue reading...

Cyberattack at Legal Sector Service Provider CTS Disrupts UK Property Deals

24 November 2023
CTS, a legal sector specialist infrastructure service provider, confirmed in a statement that it has experienced a service outage caused by a cyber-incident. The outage is believed to have affected up to 200 law firms that use CTS’ services.

Australia’s Cybersecurity Strategy Focuses on Protecting Small Businesses and Critical Infrastructure

24 November 2023
The strategy includes financial investments to support small and medium businesses, strengthen critical infrastructure, and enhance cyber capabilities, but critics argue that the allocated funds are insufficient.

Cybercriminals Using Telekopye Telegram Bot to Craft Phishing Scams on a Grand Scale

24 November 2023
More details have emerged about a malicious Telegram bot called Telekopye that's used by threat actors to pull off large-scale phishing scams. "Telekopye can craft phishing websites, emails, SMS messages, and more," ESET security researcher Radek Jizba said in a new analysis. The threat actors behind the operation – codenamed Neanderthals – are known to run the criminal enterprise as a

BlackCat Ransomware Claims Attack on Fidelity National Financial

24 November 2023
The incident involved an intruder accessing Fidelity National Financial's systems and acquiring certain credentials, leading to the shutdown of various systems and impacting the company's operations.

Telekopye Toolkit Used as Telegram Bot to Scam Online Marketplace Users

24 November 2023
The Telekopye Toolkit, implemented as a Telegram bot, is a tool used by scammers to deceive users in online marketplaces by creating phishing websites and fabricating fake screenshots, emails, and SMS messages.

FTC announces plans to mitigate AI voice fraud

24 November 2023
The Federal Trade Commission (FTC) has announced plans to better protect consumers from artificial intelligence (AI) voice cloning and fraud.

Rust-Powered SysJoker Backdoor Used in Hamas-Linked Cyberattacks Against Israel

24 November 2023
The use of OneDrive instead of Google Drive for storing command-and-control server URLs allows attackers to easily change the C2 address and stay ahead of reputation-based services.

Phishing Emails Soar 237% Ahead of Black Friday

24 November 2023
Between November 1 and November 14 this year, security vendor Egress detected a 237% increase in phishing emails relating specifically to Black Friday and Cyber Monday, versus the period September 1-October 31.

William Wetherill named new DefenseStorm CISO

24 November 2023
 After nine years, Robert Thibodeaux, DefenseStorm's Chief Information Security Officer (CISO), will retire and William Wetherill will step in as the new CISO.

Kubernetes Secrets of Fortune 500 Companies Exposed in Public Repositories

24 November 2023
Publicly exposed Kubernetes configuration secrets pose a significant risk of supply chain attacks, with credentials for accessing container image registries being stored in public repositories.

North Korean Software Supply Chain Attack Hits North America, Asia 

24 November 2023
North Korean hackers breached a Taiwanese company and used its systems to deliver malware to the US, Canada, Japan and Taiwan in a supply chain attack. The post North Korean Software Supply Chain Attack Hits North America, Asia  appeared first on SecurityWeek.

In Other News: National Laboratory Breach, Airplane GPS Attacks, Russia Accuses Allies of Hacking

24 November 2023
Noteworthy stories that might have slipped under the radar: Idaho National Laboratory breach, GPS attacks target airplanes, Russian accuses China and North Korea of hacking. The post In Other News: National Laboratory Breach, Airplane GPS Attacks, Russia Accuses Allies of Hacking appeared first on SecurityWeek.

New WailingCrab Malware Loader Spreading via Shipping-Themed Emails

24 November 2023
WailingCrab incorporates stealth features and utilizes MQTT, a rare messaging protocol, to evade detection and download payloads directly from the C2 server, bypassing Discord.

Tell Me Your Secrets Without Telling Me Your Secrets

24 November 2023
The title of this article probably sounds like the caption to a meme. Instead, this is an actual problem GitGuardian's engineers had to solve in implementing the mechanisms for their new HasMySecretLeaked service. They wanted to help developers find out if their secrets (passwords, API keys, private keys, cryptographic certificates, etc.) had found their way into public GitHub repositories. How

Hamas-Linked Cyberattacks Using Rust-Powered SysJoker Backdoor Against Israel

24 November 2023
Cybersecurity researchers have shed light on a Rust version of a cross-platform backdoor called SysJoker, which is assessed to have been used by a Hamas-affiliated threat actor to target Israel amid the ongoing war in the region. “Among the most prominent changes is the shift to Rust language, which indicates the malware code was entirely rewritten, while still maintaining similar

London & Zurich Ransomware Attack Causes Customer Chaos

24 November 2023
The company has not provided information on whether any data was compromised or how the attackers breached its systems. London & Zurich has stated that it is working to restore its services by the end of the week.

Malicious Chrome Extension Called ParaSiteSnatcher Targets Users in Brazil

24 November 2023
The malware utilizes a VBScript downloader to install itself on infected systems and employs obfuscation techniques to conceal its activities and make analysis more challenging.

Kubernetes Secrets of Fortune 500 Companies Exposed in Public Repositories

24 November 2023
Cybersecurity researchers are warning of publicly exposed Kubernetes configuration secrets that could put organizations at risk of supply chain attacks. “These encoded Kubernetes configuration secrets were uploaded to public repositories,” Aqua security researchers Yakir Kadkoda and Assaf Morag said in a new research published earlier this week. Some of those impacted include two top blockchain