Latest Cybersecurity News and Articles
08 August 2023
The Cybersecurity Strategic Plan for fiscal years 2024-2026 outlines the agency’s plans for achieving a future where damaging cyberattacks are rare, organizations are resilient, and technology is secure by design.
08 August 2023
New research has revealed that threat actors are abusing Cloudflare Tunnels to establish covert communication channels from compromised hosts and retain persistent access.
"Cloudflared is functionally very similar to ngrok," Nic Finn, a senior threat intelligence analyst at GuidePoint Security, said. "However, Cloudflared differs from ngrok in that it provides a lot more usability for free,
08 August 2023
The phishing operation, originating from Russia but pretending to be Ukrainian, utilized a high-quality single-page application to create convincing websites and steal credit card and bank details.
08 August 2023

Elections watchdog says it is unable to say conclusively what information was accessed in cyber-attackThe UK’s elections watchdog has been targeted by a cyber-attack that enabled “hostile actors” to access electoral registers.The Electoral Commission revealed it had been hacked but was “not able to know conclusively” what information had been accessed and said it apologised to people whose information was accessible to the hackers. Continue reading...
08 August 2023
A new study found that top institutional leaders are increasingly focused on improving both physical and network security.
08 August 2023
Interestingly, the analysis also revealed that malicious attacks such as malware, phishing, and ransomware accounted for just a third (33%) of breaches reported to the ICO, versus 40% of incidents caused by insider threats.
08 August 2023
A joint advisory urges organizations to implement secure by design practices and prioritize patching known exploited vulnerabilities to reduce risk of compromise.
08 August 2023
A recent investigation by cybersecurity firm SentinelLabs has revealed that North Korean hackers have targeted a Russian missile engineering organization called NPO Mashinostroyeniya.
08 August 2023
The State and Local Cybersecurity Grant Program (SLCGP), now in its second year, is a $1 billion fund with allocations spanning four years and specifically targeting state, local, and territorial government cyber resilience efforts.
08 August 2023
Multiple vulnerabilities in the popular airline and hotel rewards platform points.com could have allowed attackers to access users’ personal information, security researchers warn.
08 August 2023
Upon analyzing the attack code, Phylum uncovered that it utilized a combination of post-install hooks and pre-install scripts to trigger the execution of malicious code once the packages were installed.
08 August 2023
Government organizations and public services are increasingly targeted by cyberattacks from both nation-states and cybercriminals, necessitating the need for stronger cybersecurity measures.
08 August 2023
Introduced in 1999, Microsoft Active Directory is the default identity and access management service in Windows networks, responsible for assigning and enforcing security policies for all network endpoints. With it, users can access various resources across networks. As things tend to do, times, they are a'changin' – and a few years back, Microsoft introduced Azure Active Directory, the
08 August 2023
“Since originally reporting CVE-2023-35082… Ivanti has continued its investigation and has found that this vulnerability impacts all versions of Ivanti Endpoint Manager Mobile 11.10, 11.9, and 11.8 and MobileIron Core 11.7 and below,” Ivanti said.
08 August 2023
The group mainly targeted ATMs of Spanish national banks using cloned payment cards. Spanish police estimated the group had fraudulently pocketed nearly 196,000 euros (~$215,000).
08 August 2023
Ransomware attacks on manufacturing organizations have surged annually, resulting in substantial financial losses, with a recent report by Comparitech revealing that the sector suffered $46 billion in downtime since 2018. So far 56 manufacturing organizations have been targeted in ransomware attacks, this year.
08 August 2023
The TargetCompany ransomware is using fully undetectable (FUD) packers and Metasploit to infect vulnerable systems, making it difficult for current security solutions to detect and prevent.
08 August 2023
An unknown threat actor is using a variant of the Yashma ransomware to target various entities in English-speaking countries, Bulgaria, China, and Vietnam at least since June 4, 2023.
Cisco Talos, in a new write-up, attributed the operation with moderate confidence to an adversary of likely Vietnamese origin.
"The threat actor uses an uncommon technique to deliver the ransom note," security
08 August 2023
A Nigerian national pleaded guilty to participating in a BEC scheme to steal $1.25m from a Boston investment firm. The scam involved using malware and a spoofed domain name to trick the firm into transferring money to attacker-controlled accounts.
08 August 2023
A recent phishing scam has been using an old trick to fool Microsoft Windows users. The scam involves sending an email with an attachment that appears to be a PDF file, but is actually an .eml file disguised as a .pdf.