Latest Cybersecurity News and Articles


Russian hacker convicted of $90 million hack-to-trade charges

16 February 2023
Russian national Vladislav Klyushin was found guilty of participating in a global scheme that involved hacking into U.S. computer networks to steal confidential earnings reports, which helped the criminals net $90,000,000 in illegal profits.

ESXiArgs Ransomware Infects Over 500 New Targets in European Countries

16 February 2023
More than 500 hosts have been newly compromised en masse by the ESXiArgs ransomware strain, most of which are located in France, Germany, the Netherlands, the U.K., and Ukraine.

High-risk users may be few, but the threat they pose is huge

16 February 2023
High-risk users represent approximately 10% of the worker population and are found in every department and function of the organization, according to Elevate Security research.

Controller-level flaws can let hackers physically damage moving bridges

16 February 2023
By exploiting these flaws, hackers can access anything from sensors responsible for gauging temperature, pressure, liquid, air, and gas levels, as well as analyzers used to determine chemical compositions.

PE Firm Francisco Partners to Take Sumo Logic Private in $1.7B Deal

16 February 2023
Cloud monitoring, log management, and SIEM solutions provider Sumo Logic is set to become a private company after it has entered into a definitive agreement to be acquired by affiliates of private equity firm Francisco Partners for $1.7 billion.

Xavier University Says Personal Data From 44,000 Students Accessed in November Cyberattack

16 February 2023
The only Catholic historically Black college or university (HBCU) reported a data breach this week involving Social Security numbers and other personal information from more than 44,000 students and vendors.

Hackers Using Google Ads to Spread FatalRAT Malware Disguised as Popular Apps

16 February 2023
Chinese-speaking individuals in Southeast and East Asia are the targets of a new rogue Google Ads campaign that delivers remote access trojans such as FatalRAT to compromised machines. The attacks involve purchasing ad slots to appear in Google search results that direct users searching for popular applications to rogue websites hosting trojanized installers, ESET said in a report published

Researchers Warn of Critical Security Bugs in Schneider Electric Modicon PLCs

16 February 2023
Security researchers have disclosed two new vulnerabilities affecting Schneider Electric Modicon programmable logic controllers (PLCs) that could allow for authentication bypass and remote code execution. The flaws, tracked as CVE-2022-45788 (CVSS score: 7.5) and CVE-2022-45789 (CVSS score: 8.1), are part of a broader collection of security defects tracked by Forescout as OT:ICEFALL. Successful

Deepwatch raises $180 million to accelerate platform innovation

16 February 2023
Deepwatch has unveiled a total of $180 million in equity investments and strategic financing from Springcoast Capital Partners, Splunk Ventures, and Vista Credit Partners, a subsidiary of Vista Equity Partners.

SAS Airline Network Hit by Hackers, Says Mobile App was Compromised

16 February 2023
SAS said it was hit by a cyberattack Tuesday evening and urged customers to refrain from using its app but later said it had fixed the problem. News reports said the hack paralyzed the carrier's website and leaked customer information from its app.

Why Keeping Your Gaming Console Secure Should be a Priority in 2023

16 February 2023
There are an estimated 3.09 billion active video gamers worldwide. Unsurprisingly, the rising popularity of video gaming has proved an irresistible draw for cyber-criminals looking to target players’ login credentials and personal information.

China-base 8220 Gang Evolves its Tactics to Target Cloud Environments

16 February 2023
Chinese 8220 Gang has been found enhancing its attack techniques, such as involving using malicious Docker images and exploiting Struts2, Redis, and Weblogic servers, to launch cryptomining attacks. Some of these attacks leveraged vulnerable Oracle Weblogic servers, and the other campaign attacked a vulnerable Apache web server. Companies can leverage threat intelligence platforms to track IOCs and understand the attack patterns of such attacks.

Emsisoft Says Hackers are Spoofing its Code Signing Certificates to Breach Networks

16 February 2023
?A hacker is using fake code-signing certificates impersonating cybersecurity firm Emsisoft to target customers using its security products, hoping to bypass their defenses.

Dark Web Revenue Down Dramatically After Hydra's Demise

16 February 2023
Until its takedown in April 2022, Hydra owned 93% of all illicit underground economic activities. Year-over-year, dark web marketplace revenues at the end of 2021 were about $3.1 billion, but by the end of 2022, they totaled only about $1.5 billion.

Mirai Botnet Variant V3G4 Exploiting IoT Devices for DDoS Attacks

16 February 2023
Dubbed V3G4 by researchers, it is a type of malware that specifically targets Internet of Things (IoT) devices. Like the original Mirai botnet, V3G4 infects IoT devices by exploiting default data login credentials such as usernames and passwords.

APT37 Exploits Hangul Vulnerability with Highly-Evasive M2RAT Malware

16 February 2023
North Korean APT37 was spotted using a highly evasive M2RAT malware and steganography to target individuals for intelligence collection. It exploits an old EPS bug, tracked as CVE-2017-8291, in the Hangul word processor (commonly used in South Korea). The malware uses a shared memory region for executing commands and exfiltrating data from infected machines.

GAO Calls for Improved Data Privacy Protections

16 February 2023
The most recent in a series of US Government Accountability Office (GAO) reports on the state of cybersecurity across the federal government makes specific recommendations about the collection, use, and sharing of PII.

Breaking the Security "Black Box" in DBs, Data Warehouses and Data Lakes

16 February 2023
Security teams typically have great visibility over most areas, for example, the corporate network, endpoints, servers, and cloud infrastructure. They use this visibility to enforce the necessary security and compliance requirements. However, this is not the case when it comes to sensitive data sitting in production or analytic databases, data warehouses or data lakes. Security teams have to

ProxyShellMiner Campaign Creating Dangerous Backdoors

16 February 2023
As the name suggests, ProxyShellMiner exploits the ProxyShell vulnerabilities CVE-2021-34473 and CVE-2021-34523 in Windows Exchange servers for initial access and compromise of an organization to deliver crypto miners.

New Threat Actor WIP26 Targeting Telecom Service Providers in the Middle East

16 February 2023
Telecommunication service providers in the Middle East are being targeted by a previously undocumented threat actor as part of a suspected espionage-related campaign. Cybersecurity firms SentinelOne and QGroup are tracking the activity cluster under the former's work-in-progress moniker WIP26. "WIP26 relies heavily on public cloud infrastructure in an attempt to evade detection by making