Latest Cybersecurity News and Articles


Tonga is the latest Pacific Island nation hit with ransomware

15 February 2023
Tonga Communications Corporation (TCC) — one of two telecoms companies in the country — published a notice on Facebook saying the attack may slow down administrative operations.

Vladislav “Vlad” Rudnitsky hired as CISO for Kaufman Rossin

15 February 2023
Vladislav Rudnitsky has been hired as Kaufman Rossin's CISO and will be responsible for safeguarding the firm’s systems, data and applications.

SAP’s February 2023 Security Updates Patch High-Severity Vulnerabilities

15 February 2023
The most severe of the new security notes delivers updates to the Chromium browser in the SAP Business Client, to resolve a total of 54 vulnerabilities, including 22 high-severity issues.

Binance, Huobi freeze some cryptocurrency stolen in $100 million Harmony hack

15 February 2023
The two crypto platforms were notified about the funds by blockchain research company Elliptic, which managed to trace it through sanctioned cryptocurrency mixer Tornado Cash.

Citrix Patches High-Severity Vulnerabilities in Windows, Linux Apps

15 February 2023
Tracked as CVE-2023-24483, the Virtual Apps and Desktops vulnerability is described as a privilege escalation issue that allows an attacker with access to a Windows VDA as a standard Windows user to elevate privileges to System.

North Korea's APT37 Targeting Southern Counterpart with New M2RAT Malware

15 February 2023
The North Korea-linked threat actor tracked as APT37 has been linked to a piece of new malware dubbed M2RAT in attacks targeting its southern counterpart, suggesting continued evolution of the group's features and tactics. APT37, also tracked under the monikers Reaper, RedEyes, Ricochet Chollima, and ScarCruft, is linked to North Korea's Ministry of State Security (MSS) unlike the Lazarus and

One in nine online stores are leaking your data: study

15 February 2023
Sansec has revealed it's found a number of online stores accidentally leaking highly sensitive data. After studying 2,037 online stores, the company found that 12.3 percent exposed compressed files (in ZIP, SQL, and TAR archive formats).

Oligo raises $28M to secure open-source libraries at runtime

15 February 2023
The investors include Lightspeed Venture Partners, Ballistic Ventures, and TLV Partners, as well as angel investors like Eyal Waldman, Adi Sharabani, and Eyal Manor. Cyber Club London (CCL), Kmehin Ventures, and OperAngels also participated.

Webinar — A MythBusting Special: 9 Myths about File-based Threats

15 February 2023
Bad actors love to deliver threats in files. Persistent and persuasive messages convince unsuspecting victims to accept and open files from unknown sources, executing the first step in a cyber attack.  This continues to happen whether the file is an EXE or a Microsoft Excel document. Far too often, end users have an illusion of security, masked by good faith efforts of other users and (

Financially Motivated Threat Actor Strikes with New Ransomware and Clipper Malware

15 February 2023
A new financially motivated campaign that commenced in December 2022 has seen the unidentified threat actor behind it deploying a novel ransomware strain dubbed MortalKombat and a clipper malware known as Laplas. Cisco Talos said it "observed the actor scanning the internet for victim machines with an exposed remote desktop protocol (RDP) port 3389." The attacks, per the cybersecurity company,

Malware that can do anything and everything is on the rise

15 February 2023
“Swiss Army knife” malware – multi-purpose malware that can perform malicious actions across the cyber-kill chain and evade detection by security controls – is on the rise, according to Picus Security’s analysis of 550,000 real-world malware samples.

16 NPM Packages Posing as Speed Testers Install Crypto Miners Instead

15 February 2023
CheckPoint discovered these packages on January 17, 2023, all uploaded to NPM by a user named "trendava." Following the company's report, NPM removed them the following day.

Namecheap's Services Abused to Obtain Recovery Phrase

15 February 2023
Email inboxes of Namecheap subscribers started to receive phishing messages last week in an attempt to dupe them into disclosing personal data or their crypto wallets' recovery phrases. Scammers impersonated DHL and MetaMask in their campaigns. Namecheap said that their own systems had not been compromised and that the upstream third-party system they employ to send emails was responsible for the campaign.

Royal Mail hackers demanded $79.4 million ransom

15 February 2023
The LockBit hacking group that encrypted Royal Mail data sought a $79.4 million ransom from the company, a demand that the postal group’s board appears to have rebuffed, setting the stage for a potential large-scale leak of company information.

Chinese Hackers Infiltrate South American Diplomatic Networks

15 February 2023
The Chinese state-sponsored threat actor DEV-0147 has been spotted targeting diplomatic entities in South America with the ShadowPad remote access Trojan (RAT), also known as PoisonPlug.

RedEyes Hackers Use New Malware to Steal Data From Windows, Phones

15 February 2023
The APT37 threat group uses a new evasive 'M2RAT' malware and steganography to target individuals for intelligence collection. APT37, aka 'RedEyes' or 'ScarCruft,' is a North Korean cyber espionage hacking group believed to be state-supported.

Lazarus Group Conceals Blockchain Trails with New Custodial-based Mixer

15 February 2023
The North Korean Lazarus APT group has laundered over $100 million in cryptocurrency since October 2022, through a new single crypto mixer, named Sinbad - found blockchain analysts. Last year, the U.S. Treasury's Office of Foreign Assets Control (OFAC) imposed sanctions against these mixing services. Since then, it is suspected that Lazarus has shifted to the new mixer service to launder its funds.

How a man-on-the-side attack works

15 February 2023
Basically, a client sends a request to a server via a compromised data-transfer channel. This channel isn’t controlled by the cybercriminals, but it is “listened to” by them.

Experts Warn of New Evasive 'Beep' Malware That Can Fly Under the Radar

15 February 2023
Cybersecurity researchers have unearthed a new piece of evasive malware dubbed Beep that's designed to fly under the radar and drop additional payloads onto a compromised host.

Breaking Down the Seven Steps of an SQL Injection Kill Chain

15 February 2023
Much like other cyberattacks, malicious actors carry out SQL injection attacks in various stages across the attack life cycle. During an SQL injection attack specifically, attackers use a wide variety of techniques to gain access to their targets.