Latest Cybersecurity News and Articles


Italy, France and Singapore Warn of a Spike in ESXI Ransomware

09 February 2023
CERT-FR was the first to notice and send an alert about the attack. Italy’s National Cybersecurity Agency (ACN) and Cyber Security Agency of Singapore have also issued warnings for organizations to take immediate action to protect their systems.

Biden Announces New Appointees for Telecommunications Advisory Committee

09 February 2023
Biden’s announcement also included new leadership for NSTAC. Scott Charney, VP for Security Policy at Microsoft, will chair the committee, while Jeffrey Storey, former President and CEO at Lumen Technologies will serve as vice-chair.

Linux Variant of Clop Ransomware Spotted, But Uses Faulty Encryption Algorithm

09 February 2023
The first-ever Linux variant of the Clop ransomware has been detected in the wild, but with a faulty encryption algorithm that has made it possible to reverse engineer the process. "The ELF executable contains a flawed encryption algorithm making it possible to decrypt locked files without paying the ransom," SentinelOne researcher Antonis Terefos said in a report shared with The Hacker News.

VMware Finds No Evidence of 0-Day in Ongoing ESXiArgs Ransomware Spree

09 February 2023
VMware on Monday said it found no evidence that threat actors are leveraging an unknown security flaw, i.e., a zero-day, in its software as part of an ongoing ransomware attack spree worldwide. "Most reports state that End of General Support (EoGS) and/or significantly out-of-date products are being targeted with known vulnerabilities which were previously addressed and disclosed in VMware

Hive takedown puts ‘small dent’ in ransomware problem

09 February 2023
The takedown did not result in criminal arrests of any individuals involved or affiliated with Hive, and the predominant assumption is that the Hive members will regroup or splinter to join other ransomware groups.

Banking Trojan TgToxic Targets Android Users in Southeast Asia

09 February 2023
Trend Micro experts took the wraps off of an ongoing campaign that has been targeting Android users in Southeast Asia since July 2022. It involves embedding a trojan they named TgToxic for harvesting user data from multiple fake finance and banking apps, including cryptocurrency wallets. The samples of the malware have been identified in Taiwan, with its phishing lures detected in Thailand and Indonesia as well.

GuLoader Malware Using Malicious NSIS Executables to Target E-Commerce Industry

09 February 2023
Over the course of 2022, the NSIS scripts used to deliver GuLoader are said to have grown in sophistication, packing in additional obfuscation and encryption layers to conceal the shellcode.

Eurocops shut down Exclu encrypted messaging app

09 February 2023
An encrypted messaging service that has been on law enforcement's radar since a 2019 raid on an old NATO bunker has been shut down after a sweeping series of raids across Europe last week.

TechScape: Why Twitter ending free access to its APIs should be a ‘wake-up call’

09 February 2023
TechScape: Why Twitter ending free access to its APIs should be a ‘wake-up call’ In this week’s newsletter: The social media network is putting its APIs – the under-praised tool that keeps the internet as we know it going – behind a paywall. And the ramifications are hugeDon’t get TechScape delivered to your inbox? Sign up hereAPIs may not seem like the sexiest thing to write about in a tech newsletter, but bear with me. Because APIs – or application programming interfaces – are important. They’re the synapses of our digital world: without them, our current ways of living wouldn’t work.For example, when you visit a website that requires you to log in, and you choose to connect with a Google or Facebook account, you’re utilising an API. That click of a button that links your existing account on one platform with a new account on another is enabled by an API. They spring into action whenever one type of work interacts with another, working to bridge that gap. APIs are the overlooked and under-praised army that keeps the internet as we know it going. Continue reading...

Linux Variant of Clop Ransomware Spotted But Uses Faulty Encryption Algorithm

09 February 2023
The first-ever Linux variant of the Clop ransomware has been detected in the wild, but with a faulty encryption algorithm that has made it possible to reverse engineer the process.

AveMaria Info-stealer Changes its Strategy to Infect More Users

09 February 2023
Zscaler’s ThreatLabz disclosed details about a new infostealer AveMaria RAT that targets sensitive data with added capabilities of remote camera control and privilege escalation. Over the past six months, the operators behind the info-stealer have been making significant additions to the execution stages to infect more users. Organizations are advised to have a better email security solution in place to thwart such threats in the initial stages.

Massachusetts-Based MKS Instruments Falls Victim to Ransomware Attack

09 February 2023
The company said it has notified law enforcement authorities while it investigates and assesses the impact of the incident by engaging “appropriate incident response professionals.”

Hackers Exploit Vulnerabilities in Sunlogin to Deploy Sliver C2 Framework

09 February 2023
Threat actors are leveraging known flaws in Sunlogin software to deploy the Sliver command-and-control (C2) framework for carrying out post-exploitation activities. The findings come from AhnLab Security Emergency response Center (ASEC), which found that security vulnerabilities in Sunlogin, a remote desktop program developed in China, are being abused to deploy a wide range of payloads. "Not

Tackling the New Cyber Insurance Requirements: Can Your Organization Comply?

09 February 2023
With cyberattacks around the world escalating rapidly, insurance companies are ramping up the requirements to qualify for a cyber insurance policy. Ransomware attacks were up 80% last year, prompting underwriters to put in place a number of new provisions designed to prevent ransomware and stem the record number of claims. Among these are a mandate to enforce multi-factor authentication (MFA)

Sharp HealthCare Notifies Nearly 63,000 Patients of Data Breach

09 February 2023
Sharp HealthCare, San Diego’s largest health provider, announced Monday that it has begun notifying 62,777 of its patients that some of their personal information was compromised during an attack on the computers that run its website, sharp.com.

Update: LockBit ransomware gang claims Royal Mail cyberattack

09 February 2023
The LockBit ransomware operation has claimed the cyberattack on UK's leading mail delivery service Royal Mail that forced the company to halt its international shipping services due to "severe service disruption."

Cyberattack Gives 19,000 Students A Day Off School at Berkeley County Schools

09 February 2023
The Berkeley County Schools suffered a network outage which affected IT operations across the school system, WV Metro News reported. Personal data on the students may have been harvested in the cyberattack.

Actively exploited GoAnywhere MFT zero-day gets emergency patch

09 February 2023
The zero-day vulnerability allows attackers to perform remote code execution attacks on vulnerable GoAnywhere MFT instances whose administrative console is exposed online.

Unauthorized network access most common cause of third-party attacks

09 February 2023
Black Kite’s annual Third-Party Breach Report was released and examines the impact of third-party cyber breaches, which doubled in 2022.

Governor Abbott announces statewide plan for banning use of TikTok

09 February 2023
Texas Governor announces plan outlining the use of TikTok on government devices. Other states have banned the app due to data privacy concerns.