Latest Cybersecurity News and Articles
22 February 2023
The high-severity vulnerability has a CVSS base score of 7.1 and affects Windows 7, 10, and 11 OS versions. It was patched by Microsoft in its first Patch Tuesday of 2023.
22 February 2023
The latest annual IBM X-Force Threat Intelligence Index released today reported that deployment of backdoor malware, which allows remote access to systems, emerged as the top action by cyberattackers last year.
22 February 2023
The exposed server was part of an internal mailbox system storing about three terabytes of internal military emails, many pertaining to U.S. Special Operations Command (USSOCOM), the military unit tasked with conducting special military operations.
22 February 2023
Apple has revised the security advisories it released last month to include three new vulnerabilities impacting iOS, iPadOS, and macOS.
The first flaw is a race condition in the Crash Reporter component (CVE-2023-23520) that could enable a malicious actor to read arbitrary files as root. The iPhone maker said it addressed the issue with additional validation.
The two other vulnerabilities,
22 February 2023
In a new report from Cyber Security Works (CSW), Ivanti, Cyware, and Securin, researchers identified 56 new vulnerabilities associated with ransomware threats among a total of 344 threats identified in 2022 – marking a 19% increase year-over-year.
22 February 2023
The FortiGuard Labs team discovered another 0-day attack in the PyPI packages (Python Package Index) by the malware authors ‘Portugal’ and ‘Brazil’ who published the packages ‘xhttpsp’ and ‘httpssp’.
22 February 2023
By providing insiders with solutions that make security and privacy easier for them, organizations reduce the likelihood that people will find workarounds that undermine data protection objectives.
22 February 2023
On Sunday, the cybersecurity and malware research group vx-underground published screenshots of data purportedly stolen from Activision, including the schedule of planned content to be released for the popular first-person shooter Call of Duty.
22 February 2023
In what's a continuing assault on the open source ecosystem, over 15,000 spam packages have flooded the npm repository in an attempt to distribute phishing links.
"The packages were created using automated processes, with project descriptions and auto-generated names that closely resembled one another," Checkmarx researcher Yehuda Gelb said in a Tuesday report.
"The attackers referred to retail
22 February 2023
If you Google "third-party data breaches" you will find many recent reports of data breaches that were either caused by an attack at a third party or sensitive information stored at a third-party location was exposed. Third-party data breaches don't discriminate by industry because almost every company is operating with some sort of vendor relationship – whether it be a business partner,
22 February 2023
The released PoC involves writing a cron job to/etc/cron.d/ that triggers every minute to initiate a root reverse shell to the attacker, giving them remote code execution capabilities.
22 February 2023
Shipping companies and medical laboratories in Asia have been the subject of a suspected espionage campaign carried out by a never-before-seen threat actor dubbed Hydrochasma.
The activity, which has been ongoing since October 2022, "relies exclusively on publicly available and living-off-the-land tools," Symantec, by Broadcom Software, said in a report shared with The Hacker News.
There is no
22 February 2023
Speaking at the 17th India Digital Summit, organized by the IAMAI in partnership with Google and MessageBird, Dr. Pant emphasized that cybersecurity must never be compromised and that companies must invest in it to meet the challenges of the future.
22 February 2023
Crypto exchange Coinbase has confirmed that it was briefly compromised by the same attackers that targeted Twilio, Cloudflare, DoorDash, and more than a hundred other organizations last year.
22 February 2023
Millions of UK adults have been victimized by digital scammers in the past, yet a quarter have no security controls to protect their online activity, according to F-Secure.
22 February 2023
The core-stab backdoor is closely linked with a malicious webshell titled task-controller, and both of them are both closely linked to the widespread and ongoing NDSW/NDSX malware infection.
22 February 2023
The newly added vulnerabilities in the KEV Catalog affect a code execution vulnerability in IBM Aspera Faspex, and a code execution and command injection vulnerability in Mitel MiVoice Connect.
22 February 2023
The state-run RIA Novosti news agency said the outage was the result of a distributed denial of service (DDoS) attack. Reuters was unable to independently verify the reason for the outages.
22 February 2023
A critical-severity advisory from VMware tracks the vulnerability as CVE-2023-20858 and warns that hackers can launch injection exploits to gain full access to the underlying server operating system.
22 February 2023
An open source command-and-control (C2) framework known as Havoc is being adopted by threat actors as an alternative to other well-known legitimate toolkits like Cobalt Strike, Sliver, and Brute Ratel.
Cybersecurity firm Zscaler said it observed a new campaign in the beginning of January 2023 targeting an unnamed government organization that utilized Havoc.
"While C2 frameworks are prolific, the