Latest Cybersecurity News and Articles


Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication

16 October 2023
NTLM, which has been used as a fallback mechanism, relies on a three-way handshake and password hashing, while Kerberos uses a two-part process and encryption. NTLM has security weaknesses and is vulnerable to relay attacks.

Colonial Pipeline Attributes Ransomware Claims to ‘Unrelated’ Third-Party Data Breach

16 October 2023
The Ransomed.vc gang attempted to extort Colonial Pipeline last week but was unsuccessful. As per researchers, the stolen documents shared by the gang appear to be unrelated to Colonial Pipeline.

UK Fines Equifax $13.6 Million for 2017 Data Breach

16 October 2023
Equifax Ltd's outsourcing of data processing to its US parent company led to delays in addressing the breach, as the UK arm was only informed minutes before the incident was publicly announced, hindering its ability to respond effectively.

AI Algorithm Detects MitM Attacks on Unmanned Military Vehicles

16 October 2023
Researchers have developed an algorithm using machine learning techniques to detect and prevent man-in-the-middle attacks on unmanned military robots, which are highly susceptible to cyberattacks.

Singapore and US pledge to combat online scams in cross-border cooperation

16 October 2023
The collaboration aims to enhance regulatory enforcement activities, exchange information, and implement anti-scam measures in both countries to mitigate the risks faced by citizens and businesses.

Cybersecurity Should be a Business Priority for CEOs

16 October 2023
A recent report by Accenture reveals that although 96% of CEOs consider cybersecurity to be critical for organizational growth and stability, 74% are concerned about their ability to minimize damage from cyberattacks.

As Biohacking Evolves, How Vulnerable are we to Cyber Threats?

16 October 2023
The security of implantable technologies lies in the devices themselves, not the human body, and it is crucial to prioritize the security of these technologies before implanting them.

Binance's Smart Chain Exploited in New 'EtherHiding' Malware Campaign

16 October 2023
Threat actors have been observed serving malicious code by utilizing Binance's Smart Chain (BSC) contracts in what has been described as the "next level of bulletproof hosting." The campaign, detected two months ago, has been codenamed EtherHiding by Guardio Labs. The novel twist marks the latest iteration in an ongoing campaign that leverages compromised WordPress sites to serve unsuspecting

‘Our health data is about to flow more freely, like it or not’: big tech’s plans for the NHS – podcast

16 October 2023
‘Our health data is about to flow more freely, like it or not’: big tech’s plans for the NHS – podcast The government is about to award a £480m contract to build a vast new database of patient data. But if people don’t trust it, they’ll opt out – I know, because I felt I had to Continue reading...

Voice Phishing Campaigns Using Access Keys

14 October 2023
The phishing attack starts with an HTML file disguised as a voice message, which leads to the download of a file hosted on a disguised AWS URL. The attackers initially impersonate Zoom but later switch to spoofing Outlook and Teams login pages.

Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication

14 October 2023
Microsoft has announced that it plans to eliminate NT LAN Manager (NTLM) in Windows 11 in the future, as it pivots to alternative methods for authentication and bolster security. "The focus is on strengthening the Kerberos authentication protocol, which has been the default since 2000, and reducing reliance on NT LAN Manager (NTLM)," the tech giant said. "New features for Windows 11 include

Kwik Trip IT Systems Outage Caused by Mysterious ‘Network Incident’

14 October 2023
The outages have affected various operations, such as new orders, payments, and access to support systems, leading to customer frustration and the posting of signs by employees.

“EtherHiding” — Hiding Web2 Malicious Code in Web3 Smart Contracts

14 October 2023
A new malware campaign called "EtherHiding" has emerged, using BSC contracts to host parts of a malicious code chain. The campaign starts by hijacking WordPress sites and tricking users into downloading fake browser updates that are actually malware.

Juniper Networks Patches Over 30 Vulnerabilities in Junos OS

13 October 2023
Six high-severity vulnerabilities, including five that can be exploited remotely, have been addressed by the patches, which could potentially lead to denial of service (DoS) attacks.

18% of African banking apps have vulnerable high severity secrets

13 October 2023
The security of African financial service applications were analyzed in a recent report by Approov, finding sensitive data was left vulnerable.

CISA Now Flagging Vulnerabilities, Misconfigurations Exploited by Ransomware

13 October 2023
Through its Ransomware Vulnerability Warning Pilot (RVWP) program, the CISA has released two new resources to help identify and fix vulnerabilities exploited by ransomware groups.

Conveyor Raises $12.5m to Automate Security Reviews Using LLMs

13 October 2023
Conveyor, a startup using large language models (LLMs) like OpenAI's ChatGPT, has raised $12.5 million in funding led by Cervin Ventures to automate the security review response process for companies.

Indian State Government Fixes Website Bug That Revealed Aadhaar Numbers and Fingerprints

13 October 2023
The website bug allowed unauthorized access to land deed records by guessing sequential application numbers, highlighting the lack of robust security measures on the website.

New PEAPOD Cyberattack Campaign Targeting Women Political Leaders

13 October 2023
European Union military personnel and political leaders working on gender equality initiatives have emerged as the target of a new campaign that delivers an updated version of RomCom RAT called PEAPOD. Cybersecurity firm Trend Micro attributed the attacks to a threat actor it tracks under the name Void Rabisu, which is also known as Storm-0978, Tropical Scorpius, and UNC2596, and is also

Void Rabisu Targets Female Political Leaders with New Slimmed-Down ROMCOM Variant

13 October 2023
Void Rabisu employs various tactics, such as signing malware with bought certificates, using malicious advertisements, and exploiting vulnerabilities, including zero-day vulnerabilities.