North Korea’s Lazarus Group Rakes in $3 Billion from Cryptocurrency Hacks

Threat actors from the Democratic People’s Republic of Korea (DPRK) are increasingly targeting the cryptocurrency sector as a major revenue generation mechanism since at least 2017 to get around sanctions imposed against the country. “Even though movement in and out of and within the country is heavily restricted, and its general population is isolated from […]

Continue reading


Design Flaw in Google Workspace Could Let Attackers Gain Unauthorized Access

Cybersecurity researchers have detailed a “severe design flaw” in Google Workspace’s domain-wide delegation (DWD) feature that could be exploited by threat actors to facilitate privilege escalation and obtain unauthorized access to Workspace APIs without super admin privileges. “Such exploitation could result in theft of emails from Gmail, data exfiltration from Google Drive, or other unauthorized […]

Continue reading


NCSC warns of enduring and significant threat to UK’s critical infrastructure

The UK’s cyber chief has today signalled that the threat to the nation’s most critical infrastructure is ‘enduring and significant’, amid a rise of state-aligned groups, an increase in aggressive cyber activity, and ongoing geopolitical challenges. In its latest Annual Review, published today, the National Cyber Security Centre (NCSC) – which is a part of GCHQ […]

Continue reading


FBI struggled to disrupt dangerous casino hacking gang, cyber responders say

SAN FRANCISCO/WASHINGTON, Nov 14 (Reuters) – The U.S. Federal Bureau of Investigation (FBI) has struggled to stop a hyper-aggressive cybercrime gang that’s been tormenting corporate America over the last two years, according to nine cybersecurity responders, digital crime experts and victims. For more than six months, the FBI has known the identities of at least […]

Continue reading


When Email Security Meets SaaS Security: Uncovering Risky Auto-Forwarding Rules

While intended for convenience and efficient communication, email auto-forwarding rules can inadvertently lead to the unauthorized dissemination of sensitive information to external entities, putting confidential data at risk of exposure to unauthorized parties. Wing Security (Wing), a SaaS security company, announced yesterday that their SaaS shadow IT discovery methods now include a solution that solves […]

Continue reading


Biggest-ever DDoS attack threatens companies worldwide, and other cybersecurity news to know this month

1. Biggest-ever DDoS attack threatens companies worldwide Companies including Google and Amazon say they have fought off the world’s biggest distributed denial of service (DDoS) attack, but are warning internet users that these types of attacks could cause widespread disruption unless cybersecurity measures are stepped up. A DDoS attack aims to make a website unreachable […]

Continue reading