Latest Cybersecurity News and Articles


How to Automate the Hardest Parts of Employee Offboarding

16 November 2023
According to recent research on employee offboarding, 70% of IT professionals say they’ve experienced the negative effects of incomplete IT offboarding, whether in the form of a security incident tied to an account that wasn't deprovisioned, a surprise bill for resources that aren’t in use anymore, or a missed handoff of a critical resource or account. This is despite an average of five hours

Gamblers’ Data Compromised After Casino Giant Strendus Fails to Set Password

16 November 2023
The Mexican online casino Strendus exposed sensitive user data, including home addresses and gambling amounts, due to poor cybersecurity practices and unauthorized access.

Critical Systems Restored at English Council Following Ransomware Attack

16 November 2023
The St Helens Borough Council in northwest England has managed to restore most of its services after a ransomware attack, highlighting the increasing threat faced by local government authorities.

New PoC Exploit for Apache ActiveMQ Flaw Could Let Attackers Fly Under the Radar

16 November 2023
The researchers have engineered a better exploit that allows the threat actors to remain memory resident and avoid dropping their tools to disk, highlighting the urgency of patching and removing ActiveMQ servers from the internet.

Update: Toronto Public Library Confirms Data Stolen in Ransomware Attack

16 November 2023
The ransomware attack targeted a file server and resulted in the theft of personal information belonging to employees, customers, volunteers, and donors, dating back to 1998.

ALTR Closes $25M Series C Financing

16 November 2023
The funding will be used to strengthen ALTR's market position in the cloud data access governance and security space, expand its reach across various data sources, and develop partner integrations and channel relations.

Critical Flaw Fixed in SAP Business One Product

16 November 2023
SAP Business One installation version 10.0 has an improper access control vulnerability that allows malicious users to read, write, and execute files in the SMB shared folder, posing a significant risk to confidentiality, integrity, and availability.

Vulcan Cyber Raises $34M to Safeguard Attack Path Management

16 November 2023
The funding round was led by Maor Investments and Ten Eleven Ventures. Vulcan Cyber aims to integrate third-party sensor data and build partnerships with technology vendors.

Google Workspace Weaknesses Allow Plaintext Password Theft

16 November 2023
Researchers discovered vulnerabilities in Google Workspace that could lead to ransomware attacks, data theft, and password decryption. They exploit Google Credential Provider for Windows, allowing attackers to steal refresh tokens and bypass MFA.

Russian Hackers Launch 'Largest Ever Cyber Attack' on Danish Critical Infrastructure

16 November 2023
Russian threat actors have been possibly linked to what's been described as the "largest cyber attack against Danish critical infrastructure," in which 22 companies associated with the operation of the country's energy sector were targeted in May 2023.  "22 simultaneous, successful cyberattacks against Danish critical infrastructure are not commonplace," Denmark's SektorCERT said [PDF]. "The

Google Suing Cybercriminals Who Delivered Malware via Fake Bard Downloads

15 November 2023
Google is taking legal action against cybercriminals who used fake websites to deliver malware and gain control of social media accounts through a scam involving its chat-based AI tool, Bard.

NY Governor Wants New Cybersecurity Rules for Hospitals After Multiple Attacks

15 November 2023
New York Governor Kathy Hochul has proposed new cybersecurity rules for hospitals in the state to establish robust cybersecurity programs, assess risks, and implement protective measures to combat the rising threat of cyberattacks.

Python Package Index Faces Security Crisis With Validated Leaks

15 November 2023
Security researchers have discovered a total of 3938 unique secrets on PyPI, the official third-party package management system for the Python community, across all projects, with 768 of them validated as authentic.

One in four Gen Z and Millennial consumers buy with bots

15 November 2023
New research reveals around half of buyers suspected bots snap up in-demand goods before they can get them, forcing many to either pay inflated prices or use bots themselves.

Credit Card Skimming on the Rise for the Holiday Shopping Season

15 November 2023
A credit card skimming campaign called Kritec has recently picked up in activity, compromising numerous online stores and stealing credit card information from unsuspecting shoppers.

Cyberattack on North Carolina County Allowed Hackers to Access Data

15 November 2023
Although the nature of the attack was not specified, the county's IT staff discovered irregularities in their system and called in external cybersecurity experts to investigate and secure their servers.

File-Transfer Services, Rich With Sensitive Data, are Under Attack

15 November 2023
Compliance requirements drive the use of these services, making them attractive targets for ransomware groups looking to exploit the systems used for sending sensitive data.

Aligning cybersecurity & business objectives leads to security success

15 November 2023
A new benchmark study reveals that aligning cybersecurity organization models with business objectives enables talent retention and security program success.

The holiday season sees a rise in credit card skimming

15 November 2023
Holiday shopping often brings increased risk, and organizations aren’t exempt. According to a recent report, credit card skimming is on the rise.

U.S. Takes Down IPStorm Botnet, Russian-Moldovan Mastermind Pleads Guilty

15 November 2023
The U.S. government on Tuesday announced the takedown of the IPStorm botnet proxy network and its infrastructure, as the Russian and Moldovan national behind the operation pleaded guilty. "The botnet infrastructure had infected Windows systems then further expanded to infect Linux, Mac, and Android devices, victimizing computers and other electronic devices around the world, including in Asia,