Latest Cybersecurity News and Articles


CISA Director says tech makers must take more responsibility for safety, design choices

28 February 2023
The head of the CISA called the status quo in cybersecurity today “unsustainable,” saying companies, consumers, and government must collectively shift their expectations to make software and hardware manufacturers responsible for insecure products.

Bitdefender Releases Free Decryptor for MortalKombat Ransomware Strain

28 February 2023
Romanian cybersecurity company Bitdefender has released a free decryptor for a new ransomware strain known as MortalKombat. MortalKombat is a new ransomware strain that emerged in January 2023. It's based on commodity ransomware dubbed Xorist and has been observed in attacks targeting entities in the U.S., the Philippines, the U.K., and Turkey. Xorist, detected since 2010, is distributed as a

New EX-22 Tool Empowers Hackers with Stealthy Ransomware Attacks on Enterprises

28 February 2023
A new post-exploitation framework called EXFILTRATOR-22 (aka EX-22) has emerged in the wild with the goal of deploying ransomware within enterprise networks while flying under the radar. "It comes with a wide range of capabilities, making post-exploitation a cakewalk for anyone purchasing the tool," CYFIRMA said in a new report. Some of the notable features include establishing a reverse shell

Investment Scam Network ‘Digital Smoke’ Impersonates Fortune 100 Corporations

28 February 2023
Resecurity identified one of the largest investment fraud networks by size and volume of operations defrauding users from Australia, Canada, China, Colombia, the EU, India, Singapore, Malaysia, UAE, Saudi Arabia, Mexico, the US, and other regions.

Cloud security startup Wiz, now valued at $10B, raises $300M

28 February 2023
The Series D round was co-led by Lightspeed Venture Partners and Greenoaks Capital Partners, with participation from angel investors including Starbucks owner Howard Schultz and French business magnate Bernard Arnault.

New Exfiltrator-22 Post-Exploitation Kit Linked to LockBit Ransomware

28 February 2023
Threat analysts at CYFIRMA claim that this new framework was created by former Lockbit 3.0 affiliates who are experts in anti-analysis and defense evasion, offering a robust solution in exchange for a subscription fee.

US Sanctions Several Entities Aiding Russia’s Cyber Operations

28 February 2023
On the one-year anniversary of Russia’s war against Ukraine, the US Department of the Treasury announced a new set of sanctions against tens of entities that are allegedly helping the Kremlin, including its cyber operations.

Blind Eagle Hacker Group Targets Key Industries in Colombia

28 February 2023
The activity, which was detected by the BlackBerry Research and Intelligence Team on February 20, 2023, is also said to encompass Ecuador, Chile, and Spain, suggesting a slow expansion of the hacking group's victimology footprint.

Mobile Banking Trojans Surge, Doubling in Volume

28 February 2023
Nearly 200,000 new mobile banking Trojans emerged in 2022 — a 100% increase from the year before and the biggest acceleration of mobile malware development seen in the last six years.

Social Engineering Cyberattack on Boston Union Results in $6.4M Loss

28 February 2023
A cyberattack on Pipefitters Local 537, a Boston-based labor union’s health fund, resulted in the loss of $6.4 million, but it does not appear that the personal information of members was stolen or compromised, union officials said.

Application Security vs. API Security: What is the difference?

28 February 2023
As digital transformation takes hold and businesses become increasingly reliant on digital services, it has become more important than ever to secure applications and APIs (Application Programming Interfaces). With that said, application security and API security are two critical components of a comprehensive security strategy. By utilizing these practices, organizations can protect themselves

India records over 300 mn cases of malware attack daily: Report

28 February 2023
India recorded a total virus count of 37,697,022, which was over 4,18,000 viruses per day in Q4 of 2022, a new report showed on Monday. According to Fortinet, India alone accounted for 5.81% of the global virus count deducted in the previous quarter.

Chinese Hackers Lived Inside News Corp's Network for Two Years

28 February 2023
News Corp, the mass media and publishing giant, revealed a data breach that affected the personal data and PHI of several employees. The compromised data include names, SSNs, driver's license numbers, passport and financial data, and medical and health insurance information. The breach has affected multiple news arms of the publishing conglomerate, including the New York Post, The Wall Street Journal, and other U.K. news operations.

APT-C-36 Strikes Again: Blind Eagle Hackers Target Key Industries in Colombia

28 February 2023
The threat actor known as Blind Eagle has been linked to a new campaign targeting various key industries in Colombia. The activity, which was detected by the BlackBerry Research and Intelligence Team on February 20, 2023, is also said to encompass Ecuador, Chile, and Spain, suggesting a slow expansion of the hacking group's victimology footprint. Targeted entities include health, financial, law

Vouched raises $6.3 million to enhance its platform

28 February 2023
Vouched announced $6.3 million financing led by BHG VC and SpringRock Ventures, as well as prior investors Darrell Cavens and Mark Vadon. Vouched’s expansion plans build upon the company’s rapid growth over the past year.

"Major" cyberattack compromised sensitive U.S. Marshals Service data

28 February 2023
The service is investigating a major ransomware attack that has compromised some of its most sensitive information, including law enforcement materials, and the personal information of employees, and potential targets of federal investigations.

Lazarus's New Additions: Wslink Loader and WinorDLL64 Backdoor

28 February 2023
ESET researchers uncovered a connection between the North Korean Lazarus APT group and WinorDLL64 - a new backdoor associated with the Wslink malware downloader. Wslink, primarily a malicious loader, can be leveraged by the attacker for lateral movement as well. WinorDLL64 is a fully-featured backdoor implant that can exfiltrate, overwrite, and delete files for file manipulation.

10 US states that suffered the most devastating data breaches in 2022

28 February 2023
Cyber attack risks faced by businesses across states and reported data breaches are relative to the respective state governments’ cybersecurity investment, according to Network Assured.

LastPass Says DevOps Engineer Home Computer Hacked

28 February 2023
Password management software firm LastPass says one of its DevOps engineers had a personal home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud storage resources.

Australia plans to reform cyber security rules, set up agency

28 February 2023
The Australian government on Monday said it planned to overhaul its cybersecurity rules and set up an agency to oversee government investment in the field and help coordinate responses to hacker attacks.