News
  • "Study Finds AI Assistants Help Developers Produce Code That's More Likely to Be Buggy"
    Stanford University computer scientists have discovered that programmers who accept assistance from Artificial Intelligence (AI) tools such as GitHub Copilot write less secure code than those who do not. In a paper titled, "Do Users Write More Insecure…
  • "BetMGM Confirms Breach as Hackers Offer to Sell Data of 1.5 Million Customers"
    MGM Resorts-owned online sports betting company BetMGM recently confirmed that it suffered a data breach the same day hackers offered to sell a database containing the information of 1.5 million BetMGM customers.  BetMGM said, “patron records were…
  • "Killnet Targeted US Healthcare Sector Organization"
    The US Department of Health and Human Services Cybersecurity Coordination Center (HC3) says that the pro-Russian threat actor group Killnet has tried to achieve its political goals by targeting American hospitals and healthcare groups. After Russia…
  • "Threat Predictions for 2023: From Hacktivism to Cyberwar"
    Trellix forecasts an increase in geopolitically motivated attacks across Asia and Europe in 2023, as well as hacktivism spurred by tensions between competing political parties and vulnerabilities in core software supply chains. In cybersecurity,…
  • "Google WordPress Plug-in Bug Allows AWS Metadata Theft"
    A Server-Side Request Forgery (SSRF) vulnerability in the Google Web Stories plugin for WordPress could be exploited to obtain Amazon Web Services (AWS) metadata from sites hosted on the AWS server. This metadata may contain sensitive data such as…
  • "Comcast Xfinity Accounts Hacked in Widespread 2FA Bypass Attacks"
    Customers of Comcast Xfinity have reported that their accounts have been compromised by widespread hacks that circumvent two-factor authentication (2FA). The hacked accounts are then used to reset the passwords of other services, including the Coinbase…
  • "LastPass: Customer Vault Data Was Taken"
    Password management giant LastPass has recently revealed that hackers that breached the firm in August made off with encrypted customer vault data and unencrypted account information.  The update comes after the firm initially said that the incident…
  • "New Exploit for Microsoft's ProxyNotShell Mitigation Side Steps Fix"
    CrowdStrike researchers found a new Play ransomware exploit method that can circumvent Microsoft's rewrite mitigations released in October. Microsoft's fixes were intended to protect against ProxyNotShell vulnerabilities. The researchers uncovered the…
  • "FIN7 Cybercrime Syndicate Emerges as a Major Player in Ransomware Landscape"
    A comprehensive investigation of FIN7 has uncovered the cybercrime syndicate's organizational structure, as well as its position as an affiliate in the escalating ransomware attacks. It has also revealed deeper ties between the group and the greater…
  • "Zerobot IoT Botnet Adds More Exploits, DDoS Capabilities"
    The recently detailed Internet of Things (IoT) botnet Zerobot has been updated with an expanded list of exploits and distributed denial-of-service (DDoS) capabilities.  Zerobot was initially detailed two weeks ago.  Zerobot is a self-…
  • "Some Universities Are Now Restricting TikTok Access on Campus"
    A small but growing number of universities are now blocking access to TikTok on school-owned devices or WiFi networks, in the latest sign of a widening crackdown on the popular short-form video app.  The University of Oklahoma and Auburn University…
  • "Okta Source Code Stolen by Hackers"
    Identity and access management solutions provider Okta recently informed customers that some of the company’s source code was stolen recently from its GitHub repositories.  Okta was informed about the breach in early December by GitHub.  An…