Latest Cybersecurity News and Articles


Armenian Entities Hit by New Version of OxtaRAT Spying Tool

20 February 2023
The latest campaign is said to have commenced in November 2022 and marks the first time the threat actors behind the activity have expanded their focus beyond Azerbaijan.

Samsung Introduces New Feature to Protect Users from Zero-Click Malware Attacks

20 February 2023
Samsung has announced a new feature called Message Guard that comes with safeguards to protect users from malware and spyware via what's referred to as zero-click attacks. The South Korean chaebol said the solution "preemptively" secures users' devices by "limiting exposure to invisible threats disguised as image attachments." The security feature, available on Samsung Messages and Google

Havoc Replaces Cobalt Strike and Brute Ratel

19 February 2023
Threat actors have been switching to a new open-source C2 framework, dubbed Havoc, as an alternative to Brute Ratel and Cobalt Strike - stated researchers. The advanced post-exploitation C2 framework can bypass even the most updated version of Windows 11 Defender. An unknown threat group dropped Havoc on an undisclosed government organization in January.

Scammers Found Exploiting YouTube to Launch Crypto Scams

19 February 2023
Researchers discovered a massive network of fake YouTube videos that cybercriminals are using to launch crypto scams. These fake videos advertise fraudulent web-based apps for USDT. To make the channels look legitimate, threat actors automated copy-pasting comments to videos. Many of these videos also encouraged victims to invite friends and family to participate, asking for a small amount from each person.

Fortinet Issues Patches for 40 Flaws Affecting FortiWeb, FortiOS, FortiOS, and FortiProxy

19 February 2023
Fortinet has released security updates to address 40 vulnerabilities in its software lineup, including FortiWeb, FortiOS, FortiNAS, and FortiProxy, among others. Two of the 40 flaws are rated Critical, 15 are rated High, 22 are rated Medium, and one is rated Low in severity. Top of the list is a severe bug residing in the FortiNAC network access control solution (CVE-2022-39952, CVSS score: 9.8)

New Frebniis Malware Abuses IIS Features for Secret Communications

18 February 2023
There’s a new malware threat to Microsoft Internet Information Services (IIS) servers dubbed Frebniss. Discovered by Symantec's Threat Hunter Team, the malware abuse 'Failed Request Event Buffering' (FREB) feature of IIS that is responsible for collecting request metadata such as IP addresses, HTTP headers, and cookies. By abusing the FREB component, it becomes relatively easier for hackers to evade detection.

Twitter Limits SMS-Based 2-Factor Authentication to Blue Subscribers Only

18 February 2023
Twitter has announced that it's limiting the use of SMS-based two-factor authentication (2FA) to its Blue subscribers. "While historically a popular form of 2FA, unfortunately we have seen phone-number based 2FA be used – and abused – by bad actors," the company said. "We will no longer allow accounts to enroll in the text message/SMS method of 2FA unless they are Twitter Blue subscribers."

New Variant of Mirai Targets 13 Known IoT Device Vulnerabilities

18 February 2023
Researchers at Unit42 laid bare a Mirai botnet variant dubbed V3G4 that compromised hosts by abusing several vulnerabilities in products from DrayTek, Geutebruck, FreePBX, Atlassian, and others. The botnet infected exposed servers and networking devices running on Linux OS. Successful exploitation of the bugs could let hackers take full control of the hosts and make them a part of the botnet.

SolarWinds Announces Upcoming Patches for High-Severity Vulnerabilities

18 February 2023
Out of a total of seven security defects, five are described as deserialization of untrusted data issues that could be exploited to achieve command execution. Four of them have a CVSS score of 8.8.

GoDaddy Discloses Multi-Year Security Breach Causing Malware Installations and Source Code Theft

18 February 2023
Web hosting services provider GoDaddy on Friday disclosed a multi-year security breach that enabled unknown threat actors to install malware and siphon source code related to some of its services. The company attributed the campaign to a "sophisticated and organized group targeting hosting services." GoDaddy said in December 2022, it received an unspecified number of customer complaints about

WordPress sites backdoored with ad fraud plugin

18 February 2023
About 50 WordPress blogs have been backdoored with a plugin called fuser-master. This plugin is being triggered via popunder traffic from a large ad network. The WordPress sites are loaded on a separate page underneath and display a number of ads.

Analysis of New CatB Ransomware Variant

18 February 2023
CatB is a reasonably new entrant to the ransomware field, with samples only dating back to December 2022. The CatB threat actor does not offer a web portal (on TOR or otherwise) to name and shame victims.

Fortinet fixes critical RCE flaws in FortiNAC and FortiWeb

18 February 2023
Fortinet has released security updates for its FortiNAC and FortiWeb products, addressing two critical-severity vulnerabilities that may allow unauthenticated attackers to perform arbitrary code or command execution.

New Protections for Food Benefits Stolen by Skimmers

17 February 2023
Millions of Americans receiving food assistance benefits just earned a new right that they can't yet enforce: The right to be reimbursed if funds on their Electronic Benefit Transfer (EBT) cards are stolen by card skimming devices secretly installed at cash machines and grocery store checkout lanes.

Federal government announces new disruptive technology strike force

17 February 2023
Federal disruptive technology strike force aims to defend against illicit actors, strengthen supply chains and protect critical technological assets.

Hackers Using Google Ads to Spread FatalRAT Malware Disguised as Popular Apps

17 February 2023
A majority of the victims are located in Taiwan, China, and Hong Kong, followed by Malaysia, Japan, the Philippines, Thailand, Singapore, Indonesia, and Myanmar. The attackers' end goals are unclear as yet.

ChatGPT Subs In as Security Analyst, Hallucinates Only Occasionally

17 February 2023
A number of experiments suggest ChatGPT could be useful to help defenders triage potential security incidents and find security vulnerabilities in code, even though it was not specifically trained for such activities, according to recent studies.

Atlassian Says Leaked Data Stolen via Third-Party App

17 February 2023
A threat group called SiegedSec recently posted a cache of employee and operations information allegedly stolen from software workforce collaboration tool provider Atlassian.

The US Government’s Open Source Security Policy Discussed

17 February 2023
With a reliance on volunteers and committed contributors to manage vulnerabilities in the open-source ecosystem, there are often disparities in the extent to which codes are maintained, if at all.

Experts Warn of RambleOn Android Malware Targeting South Korean Journalists

17 February 2023
Suspected North Korean nation-state actors targeted a journalist in South Korea with a malware-laced Android app as part of a social engineering campaign. The findings come from South Korea-based non-profit Interlab, which coined the new malware RambleOn. The malicious functionalities include the "ability to read and leak target's contact list, SMS, voice call content, location and others from