Latest Cybersecurity News and Articles


Blackfly: Espionage Group Targets Materials Technology

02 March 2023
The Blackfly espionage group (aka APT41, Winnti Group, Bronze Atlas) has continued to mount attacks against targets in Asia and recently targeted two subsidiaries of an Asian conglomerate, likely attempting to steal intellectual property

Cambodia-Based "Sour Grapes" Pig Butchering Scam Targets Southeast Asia

02 March 2023
The teams running these scams include a young man or woman acting as the face of the scam, keyboarders who keep the victim engaged, and a team generating and repurposing media content with fabricated proof of their backstory.

1 year of war: From weaponizing Ukraine to Russia's outsourced cyber war

02 March 2023
In Episode 14 of the Cybersecurity & Geopolitical Podcast from Security magazine, hosts Ian Thornton-Trump and Philip Ingram assess the Russia-Ukraine conflict.

R3NIN Sniffer Malware Stealing Credit Card Data From E-Commerce Consumers

02 March 2023
In the event of a website being hacked, attackers may implant an encoded malicious script into the web server, designed to activate when a target user accesses the corrupted web page.

Hackers Exploit Containerized Environments to Steals Proprietary Data and Software

02 March 2023
A sophisticated attack campaign dubbed SCARLETEEL is targeting containerized environments to perpetrate theft of proprietary data and software. "The attacker exploited a containerized workload and then leveraged it to perform privilege escalation into an AWS account in order to steal proprietary software and credentials," Sysdig said in a new report. The advanced cloud attack also entailed the

Cisco to Acquire Valtix for Cloud Network Security Tech

02 March 2023
Cisco is dipping into the acquisition pool to beef up its cybersecurity portfolio with plans to acquire Valtix, an early-stage Silicon Valley startup in the cloud network security business.

Cybercriminals Targeting Law Firms with GootLoader and FakeUpdates Malware

02 March 2023
GootLoader, active since late 2020, is a first-stage downloader that's capable of delivering a wide range of secondary payloads such as Cobalt Strike and various ransomware.

New cyberattack tactics rise up as ransomware payouts increase

02 March 2023
While phishing, business email compromise (BEC), and ransomware still rank among the most popular cyberattack techniques, a mix of new-breed attacks is gaining steam, according to a new report from cybersecurity and compliance company Proofpoint.

New Cryptojacking Campaign Leverages Misconfigured Redis Database Servers

02 March 2023
Misconfigured Redis database servers are the target of a novel cryptojacking campaign that leverages a legitimate and open source command-line file transfer service to implement its attack. "Underpinning this campaign was the use of transfer[.]sh," Cado Security said in a report shared with The Hacker News. "It's possible that it's an attempt at evading detections based on other common code

2023 Browser Security Report Uncovers Major Browsing Risks and Blind Spots

02 March 2023
As a primary working interface, the browser plays a significant role in today's corporate environment. The browser is constantly used by employees to access websites, SaaS applications and internal applications, from both managed and unmanaged devices. A new report published by LayerX, a browser security vendor, finds that attackers are exploiting this reality and are targeting it in increasing

SCARLETEEL Hackers Use Advanced Cloud Skills to Steal Source Code, Data

02 March 2023
While the attackers deployed cryptominers in the compromised cloud environments, the hackers showed advanced expertise in AWS cloud mechanics, which they used to burrow further into the company's cloud infrastructure.

Experts Identify Fully-Featured Info Stealer and Trojan in Python Package on PyPI

02 March 2023
A malicious Python package uploaded to the Python Package Index (PyPI) has been found to contain a fully-featured information stealer and remote access trojan. The package, named colourfool, was identified by Kroll's Cyber Threat Intelligence team, with the company calling the malware Colour-Blind. "The 'Colour-Blind' malware points to the democratization of cybercrime that could lead to an

Scammers hijack business listings on search engines to lay down phishing bait

02 March 2023
Scammers manipulate search engine business listings, bid for digital ads displaying fake numbers, and place phishing links in the comment section of websites like Quora or business ratings to trap customers into calling phony customer care numbers.

Google adds client-side encryption to Gmail and Calendar. Should you care?

02 March 2023
On Tuesday, Google made client-side encryption available to a limited set of Gmail and Calendar users in a move designed to give them more control over who sees sensitive communications and schedules.

Security Defects in TPM 2.0 Spec Raise Alarm

02 March 2023
Security researchers at Quarkslab have identified a pair of serious security defects in the Trusted Platform Module (TPM) 2.0 reference library specification, prompting a massive cross-vendor effort to identify and patch vulnerable installations.

Malicious package flood on PyPI might be sign of new attacks to come

02 March 2023
Over the weekend, an attacker was found uploading thousands of malicious Python packages to the public PyPI software repository. If executed on a Windows system, these packages will download and install a Trojan program hosted on Dropbox.

Update: Dish Network confirms network outage was a cybersecurity breach

02 March 2023
“Certain data was extracted,” the company said in a statement Tuesday. The acknowledgment is an evolution from last week’s earnings call, where it was described as an “internal outage.”

Update: Gamers are fixing a video game ‘taken over’ by hackers

02 March 2023
Because of its age, patching the vulnerabilities does not appear to be a priority for the game’s publisher Activision, so two gamers-turned-hackers have taken it into their own hands to patch the game’s vulnerabilities and make it safer to play.

Dormant accounts are a low-hanging fruit for attackers

02 March 2023
Successful attacks on systems no longer require zero-day exploits, as attackers now focus on compromising identities through methods such as bypassing MFA, hijacking sessions, or brute-forcing passwords, according to Oort.

Critical Flaw in Cisco IP Phone Series Exposes Users to Command Injection Attack

02 March 2023
The vulnerability, tracked as CVE-2023-20078, is rated 9.8 out of 10 on the CVSS scoring system and is described as a command injection bug in the web-based management interface arising due to insufficient validation of user-supplied input.