Breaking News

FIND INFORMATION ABOUT THE LATEST ADVANCES IN TECHNOLOGY & NEWS RELATED TO CYBERSECURITY & ARTIFICIAL INTELLIGENCE (AI)

White House Launches Initiative to Combat Cybersecurity Talent Shortage

The Biden administration launched the "Service for America" initiative, which aims to fill the cybersecurity talent shortage of about 225,000 people by removing degree requirements and encouraging work-based initiatives. One such initiative is work-based learning through apprenticeships, allowing workers to learn while on the job.

WhatsApp Will Send Messages to Other Apps Soon

Meta has finally pulled the curtain back on what its plans for third-party chats between WhatsApp and Messenger. The change, which is coming for users in the European Union, introduces new options to put Messenger and WhatsApp messages in the same inbox.

Google Issues Android Attack Warning as 0-Day Threat Strikes

The new Android security update happening in September targets common vulnerabilities. They are addressing CVE-2024-32896, which is the most severe of the vulnerabilities, since it impacts the Android framework component which are a set of various software components that all Android apps are built upon.

New Voldemort Malware Using Google Sheets To Store Stolen Data

A new malware named “Voldemort” exploits Google Sheets to steal data. Hackers use Google Sheets to covertly store and transmit stolen information, taking advantage of its trusted platform status and collaboration features, allowing them to bypass traditional security measures, making detection and prevention more challenging.

CISA Launches Cyber Incident Reporting Portal to Streamline Breach Disclosure

CISA is creating a new portal for critical infrastructure organizations to report cyber incidents, aiming to improve national cyber threat response and coordination by the end of 2024.

Chinese Hackers Attack Internet Companies

A Chinese hacker group exploited a vulnerability in software used by clients of California-based Versa Networks. The group, identified as "Volt Typhoon", is alleged to be backed by the Chinese government.

Chinese Hackers Exploit Zero-Day Vulnerability to Target US Internet Providers, Researchers Reveal

Researchers have uncovered that Chinese hackers have been exploiting a zero-day vulnerability to breach US internet providers. This sophisticated attack method allowed them to access and potentially disrupt critical infrastructure, highlighting significant cybersecurity concerns and the need for heightened vigilance.

Seattle Airport Hit with an Apparent Cyberattack and now Facing Major Power Internet Outages

The Seattle-Tacoma International Airport has been it by an apparent cyberattack, and has disrupted the phones, emails, internet, and other services. The apparent cyberattack has not affected TSA's ability to screen passengers, but there were long waits at baggage claim and checking and longer than usual security lines.

SonicWall Issues a Critical Patch for Firewall Vulnerability That is Allowing Unauthorized Access

Malicious users are able to gain unauthorized access to SonicWall devices if successfully exploited, which is why SonicWall has released a new security update to address this critical firewall issue. They have identified, in the SonicWall SonicOS management access, an improper access control vulnerability that is causing the firewall to crash. It is recommended that users install and update the latest firmware.

Stolen Credentials Within Google Chrome Browsers Create a New Twist of Ransomware Attacks

Chrome accounts for a 65% slice of the browser market and Sophos researchers suggest that an average of 87 work-related passwords and twice that for personal ones are stored per machine providing a foot in the door at a subsequent target, or troves of information about high-value targets to be exploited.

Oil Giant Halliburton Hit With a Ransomware Attack

Considered the world's second largest oil service company, Halliburton's computer systems were hit by a ransomware attack. The company immediately activated their cybersecurity response plan. The attack impacted some global connectivity networks but mainly their north Houston campus.

Microsoft Patches Critical Copilot Studio Vulnerability

Researchers discovered a critical security vulnerability in Copilot Studio which could allow hackers access to users' sensitive data. An attacker can use a Server-Side Request Forgery (SSRF) attack to gain access to sensitive data over a network.

RansomHub Group Deploys New EDR-Killing Tool in Latest Cyber Attacks

A cybercrime group linked to RansomHub ransomware has deployed EDRKillShifter, a new malware that targets endpoint detection and response (EDR) software on compromised hosts. Proper precautions, such as good Windows security practices, are recommended to mitigate its impact .

US lawmakers Urge Probe of WiFi Router Maker TP-Link Over Fears of Chinese Cyber Attacks

U.S. lawmakers are calling for an investigation into TP-Link, a Chinese WiFi router maker, due to cybersecurity concerns. They fear the products could be used for espionage or cyberattacks, posing national security risks. This highlights ongoing scrutiny of Chinese tech firms in the U.S. Photo Credit: The Hacker News

Russian Hackers are Using Fake Brand Sites to Spread Malware

Russian Hackers have led a campaign that is meant to impersonate brands in order to distribute different malware, such as StealC and DanaBot. These hackers are using the reputation of these well-known and reputable brands in order to trick victims into downloading the malware using different social media accounts and other bogus sites.

Hackers Might Have Stolen Every American’s Social Security Number

A hacking group has claimed that they were able to steal around 3 billion personal records, which includes Social Security numbers. The hacking group, known as USDoD, stole the records and data from National Public Data. Experts say the best possible solutuon would be to freeze credit card files as the best immediate safeguard.

Elon Musk Reveals Major DDoS Attack on X During Trump Interview

Elon Musk reported that X (formerly Twitter) suffered a major DDoS attack during a live interview with Donald Trump, causing significant access issues. The interview, scheduled for 8 PM ET, was delayed by 40 minutes due to the attack. Musk said the event would proceed with fewer live viewers and the full conversation would be posted afterward.

New Windows 10 And 11 Blue Screen Of Death Warning Issued

After the issue with a CrowdStrike update left Windows users in an endless blue screen of death loop, a new blue screen threat has been revealed. Even if the current security updates are installed, all versions of Windows 10 and Windows 11 are affected.

Personal Data of 3 Billion People Exposed in Hack

A Database, owned by National Public Data, was breached. It contained the data of (up to) 3 Billion People, according to a class action lawsuit. The data was initially being sold on the dark web, but recently it was made available to download for free.

Microsoft Authenticator is Overwriting MFA Accounts and Locking Users Out

When a user adds a new account via QR scan, Microsoft Authenticator often overwrites accounts with the same usernames. Even worse, it is difficult to determine the exact account that was overwritten. To avoid being locked out, users should use another authentication app or avoid the QR code scan on Microsoft Authenticator.