Latest Cybersecurity News and Articles


PixPirate: New Android Banking Trojan Targeting Brazilian Financial Institutions

09 February 2023
A new Android banking trojan has set its eyes on Brazilian financial institutions to commit fraud by leveraging the PIX payments platform. Italian cybersecurity company Cleafy, which discovered the malware between the end of 2022 and the beginning of 2023, is tracking it under the name PixPirate. "PixPirate belongs to the newest generation of Android banking trojan, as it can perform ATS (

Finland’s Most-Wanted Hacker Nabbed in France

09 February 2023
Julius "Zeekill" Kivimäki, a 25-year-old Finnish man charged with extorting a local online psychotherapy practice and leaking therapy notes for more than 22,000 patients online, was arrested this week in France. A notorious hacker convicted of perpetrating tens of thousands of cybercrimes, Kivimäki had been in hiding since October 2022, when he failed to show up in court and Finland issued an international warrant for his arrest.

What SOCs Need to Know About Water Dybbuk

09 February 2023
Once the email attachment is opened, the target’s computer will reach out to the command-and-control (C&C) server hosting a BadaxxBot toolkit that acts as a redirector to the final phishing page.

FormBook Malware Spreads via Malvertising Using MalVirt Loader to Evade Detection

09 February 2023
An ongoing malvertising campaign is being used to distribute virtualized .NET loaders that are designed to deploy the FormBook information-stealing malware. "The loaders, dubbed MalVirt, use obfuscated virtualization for anti-analysis and evasion along with the Windows Process Explorer driver for terminating processes," SentinelOne researchers Aleksandar Milenkoski and Tom Hegel said in a

‘0ktapus’ hackers are back and targeting tech and gaming companies, says leaked report

09 February 2023
The hackers who reportedly hit more than 130 organizations last year and stole the credentials of almost 10,000 employees are still targeting several tech and video game companies, according to a report obtained by TechCrunch.

Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware

09 February 2023
The Mustang Panda APT group loads the PlugX malware in the memory of legitimate software by employing a four-stage infection chain that leverages malicious shortcut (LNK) files, triggering execution via DLL search-order-hijacking.

SaaS in the Real World: Who's Responsible to Secure this Data?

09 February 2023
When SaaS applications started growing in popularity, it was unclear who was responsible for securing the data. Today, most security and IT teams understand the shared responsibility model, in which the SaaS vendor is responsible for securing the application, while the organization is responsible for securing their data.  What’s far murkier, however, is where the data responsibility lies on the

OpenSSH Releases Patch for New Pre-Auth Double Free Vulnerability

09 February 2023
The maintainers of OpenSSH have released OpenSSH 9.2 to address a number of security bugs, including a memory safety vulnerability in the OpenSSH server (sshd). Tracked as CVE-2023-25136, the shortcoming has been classified as a pre-authentication double free vulnerability that was introduced in version 9.1. "This is not believed to be exploitable, and it occurs in the unprivileged pre-auth

Short-staffed SOCs struggle to gain visibility into cloud activities

09 February 2023
Enterprises have a limited number of analysts running their security operations centers (SOCs) and are deploying multiple tools in an attempt to address their cloud security challenges, according to ManageEngine.

InTheBox Sells Over 1,800 Android Phishing Forms

09 February 2023
Cyble observed the InTheBox threat actor selling over 1,800 web injects in its dark web shop, which can target users from Australia, Japan, Indonesia, the U.S., India, and other countries. The overlays support several Android banking trojans and impersonate apps operated by organizations across the globe. Due to the mass availability and low-cost web injects, threat actors are able to focus on other parts of their operations, including malware development and expansion of their attack surface. 

Pupils across the UK crowned champions of the NCSC cyber contest for girls

09 February 2023
Thirteen teams around the country claimed victory at the finals of the 2023 CyberFirst Girls Competition

Russian Cybercriminals Launch New 'Passion' Attack Platform

09 February 2023
Medical institutions in the U.S. and Europe are under attack from a new botnet network called Passion launching DDoS attacks. It operates as a DDoS-as-a-Service (DDoSaaS) platform and has distinctive ties with Russian hacking groups, such as Anonymous Russia, Killnet, MIRAI, and Venom. It ran several defacement campaigns on Japanese and South African organizations in early January.

High-Severity Privilege Escalation Vulnerability Patched in VMware Workstation

09 February 2023
The flaw, tracked as CVE-2023-20854 and rated ‘high severity’, has been described by VMware as an arbitrary file deletion vulnerability affecting version 17.x on Windows.

Serious security hole plugged in infosec tool binwalk

09 February 2023
Security analysis tool Binwalk itself poses a security risk to users running out-of-date versions due to a path traversal vulnerability that could lead to remote code execution (RCE).

QUAD agrees to leverage machine learning, related advanced technologies to enhance cybersecurity

09 February 2023
The White House said progress on these objectives will enhance Quad members' national cyber capabilities, lowering the number of serious cyber incidents and improving their response capabilities.

New 'PixPirate' Android Banking Trojan Targets Brazilian Financial Institutions

09 February 2023
Besides stealing passwords entered by users on banking apps, the threat actors behind the operation have leveraged code obfuscation and encryption using a framework known as Auto.js to resist reverse engineering efforts.

Update: Microsoft attributes Charlie Hebdo data leak to Iran-linked NEPTUNIUM APT

09 February 2023
Microsoft’s Digital Threat Analysis Center (DTAC) attributes a recent cyberattack against the satirical French magazine Charlie Hebdo to an Iran-linked threat actor tracked as NEPTUNIUM (aka Emennet Pasargad, Holy Souls).

GuLoader Malware Using Malicious NSIS Executable to Target E-Commerce Industry

09 February 2023
E-commerce industries in South Korea and the U.S. are at the receiving end of an ongoing GuLoader malware campaign, cybersecurity firm Trellix disclosed late last month. The malspam activity is notable for transitioning away from malware-laced Microsoft Word documents to NSIS executable files for loading the malware. Other countries targeted as part of the campaign include Germany, Saudi Arabia,

Microsoft: Iranian Nation-State Group Sanctioned by U.S. Behind Charlie Hebdo Hack

09 February 2023
An Iranian nation-state group sanctioned by the U.S. government has been attributed to the hack of the French satirical magazine Charlie Hebdo in early January 2023. Microsoft, which disclosed details of the incident, is tracking the activity cluster under its chemical element-themed moniker NEPTUNIUM, which is an Iran-based company known as Emennet Pasargad. In January 2022, the U.S. Federal

Truck Brokerage Company FR8 Exposed 140GB of Data Due to Misconfigured Server

09 February 2023
According to the IT security researcher Anurag Sen working with Italian cyber security firm FlashStart, the organization has exposed more than 140 gigabytes of data, which is available to the public without any password or security authentication.