Latest Cybersecurity News and Articles


Sublime nabs $9.8M for an anti-phishing email security platform built on collective, crowdsourced rules

23 February 2023
Decibel is leading the round, with Slow Ventures and a number of cybersecurity veterans participating, including Sounil Yu, Martin Roesch, Jerry Perullo, Michael Sutton, Rishi Bhargava, Slavik Markovich, Kevin Patrick Mahaffey, and Oliver Friedrichs.

Attackers Flood NPM Repository with Over 15,000 Spam Packages Containing Phishing Links

23 February 2023
"The packages were created using automated processes, with project descriptions and auto-generated names that closely resembled one another," Checkmarx researcher Yehuda Gelb said in a Tuesday report.

More vulnerabilities in industrial systems raise fresh concerns about critical infrastructure hacks

23 February 2023
Aslew of new reports about vulnerabilities in operational technology systems are raising fresh concerns about potential weaknesses inside U.S. critical infrastructure organizations.

New S1deload Stealer Malware Hijacks Youtube, Facebook Accounts

23 February 2023
Security researchers with Bitdefender's Advanced Threat Control (ATC) team discovered the new malware and dubbed it S1deload Stealer due to its extensive use of DLL sideloading for evading detection.

Cyberattack on Dole Temporarily Shuts Down Production in North America

23 February 2023
The previously unreported hack — which a source familiar with the incident said was ransomware — led some grocery shoppers to complain on Facebook in recent days that store shelves were missing Dole-made salad kits.

Open source software supply chain has security risks

23 February 2023
The increasing use of open-source packages in application development also creates a path for threat groups that want to use the software supply chain as a backdoor to myriad targets that depend on it.

The Secret Vulnerability Finance Execs are Missing

23 February 2023
The (Other) Risk in Finance A few years ago, a Washington-based real estate developer received a document link from First American – a financial services company in the real estate industry – relating to a deal he was working on. Everything about the document was perfectly fine and normal. The odd part, he told a reporter, was that if he changed a single digit in the URL, suddenly, he could see

Previously Unknown Group 'Hydrochasma' Targets Medical and Shipping Organizations in Asia

23 February 2023
Hydrochasma, the threat actor behind this campaign, has not been linked to any previously identified group, but appears to have a possible interest in industries that may be involved in COVID-19-related treatments or vaccines.

Meta successfully resists certification in data privacy collective action

23 February 2023
In an early victory for Meta, the Competition Appeal Tribunal has refused to certify a collective claim brought on behalf of some 45 million consumers by proposed class representative Dr. Liza Lovdahl Gormsen (the “PCR”).

New Hacking Cluster 'Clasiopa' Targeting Materials Research Organizations in Asia

23 February 2023
Materials research organizations in Asia have been targeted by a previously unknown threat actor using a distinct set of tools. Symantec, by Broadcom Software, is tracking the cluster under the moniker Clasiopa. The origins of the hacking group and its affiliations are currently unknown, but there are hints that suggest the adversary could have ties to India. This includes references to "

Lazarus Group Using New WinorDLL64 Backdoor to Exfiltrate Sensitive Data

23 February 2023
A new backdoor associated with a malware downloader named Wslink has been discovered, with the tool likely used by the notorious North Korea-aligned Lazarus Group, new findings reveal. The payload, dubbed WinorDLL64 by ESET, is a fully-featured implant that can exfiltrate, overwrite, and delete files; execute PowerShell commands; and obtain comprehensive information about the underlying machine.

European Commission bans staff from using TikTok on work devices

23 February 2023
European Commission bans staff from using TikTok on work devices Employees given until 15 March to comply amid concerns over app’s Chinese ownershipThe EU’s executive body has banned its thousands of staff from using TikTok, as governments and officials become increasingly concerned over the company’s data practices and Chinese ownership.The European Commission sent an email to employees ordering them to delete the app from all work phones and devices, and any personally owned ones that use the commission’s apps and email. Employees have until 15 March to comply. Continue reading...

Two Health Data Hacks Affect More Than One Million Individuals

23 February 2023
Two recent separate hacking incidents involving attackers stealing copies of protected health information have affected more than one million patients of a New Jersey healthcare system and an Alabama cardiovascular clinic.

Android Voice Chat App With 5 Million Installs Leaked User Chats

23 February 2023
Researchers warned that malicious actors could have deleted the dataset, resulting in a permanent loss of users’ private messages, if the leaked data had not been backed up.

DDoS Attacks Becoming More Potent, Shorter in Duration

23 February 2023
Tech giant Microsoft says it observed distributed denial-of-services attacks become shorter in duration in 2022 while also becoming more potent and capable of larger impact.

New S1deload Malware Hijacking Users' Social Media Accounts and Mining Cryptocurrency

23 February 2023
An active malware campaign has set its sights on Facebook and YouTube users by leveraging a new information stealer to hijack the accounts and abuse the systems' resources to mine cryptocurrency. Bitdefender is calling the malware S1deload Stealer for its use of DLL side-loading techniques to get past security defenses and execute its malicious components. "Once infected, S1deload Stealer steals

Russia blames 'hackers' for fake missile strike alerts

23 February 2023
Millions of Russians in almost a dozen cities throughout the country were greeted Wednesday morning by radio alerts, text messages, and sirens warning of an air raid or missile strikes that never occurred. The warnings were later blamed on hackers.

Dutch intelligence say many cyberattacks by Russia are not yet public knowledge

23 February 2023
Many of Russia’s cyber operations against Ukraine and NATO members during the past year have not yet become public knowledge, according to a joint report published this week by two Dutch intelligence services.

Civil liberties groups call for EU-wide ban on spyware

23 February 2023
The European Digital Rights (EDRi) association on Tuesday called for the European Parliament committee investigating spyware to amend its recommendations around the technology.

NCUA Issues Final Rule on Cyber Incident Notification

23 February 2023
On February 16, 2023, the National Credit Union Administration (NCUA) issued its final rule on cyber incident notification requirements for federally insured credit unions.