Latest Cybersecurity News and Articles


An MP who gives out colleagues’ numbers to blackmailers. Isn’t William Wragg just right for this Tory party? | Marina Hyde

05 April 2024
An MP who gives out colleagues’ numbers to blackmailers. Isn’t William Wragg just right for this Tory party? | Marina Hyde The ‘senior Tory’ has issued a self-flagellating apology, but he still has the whip – and Sunak’s low bar sinks lowerWhere to start with Westminster’s latest scandal, which – without wishing to speculate on spoilers – I suggest you formally label as “developing”? Blowing his own cover in it is William Wragg, MP for Hazel Grove in Greater Manchester, and chair of the public administration and constitutional affairs committee. Aged 36, William is described as a “senior Tory” on the basis of something or other – possibly his predilection for calling for other politicians to resign on moral grounds. Mind you, these days being an MP since 2015 means you’ve seen five prime ministers. If anything, you’re a Tory grandee.Anyway, here follow the bare bones of what Wragg seems to have got himself mixed up in. Having connected with someone on Grindr, he began an exchange that led, in his own words, to his correspondent getting “compromising things on me”. Instead of going immediately to the police, as far as we know Wragg instead opted to start obliging his tormentor with the numbers of other MPs, Westminster staff and political journalists. These new targets were duly sent photos fairly early on in their own exchanges with their mystery correspondent, and – incredibly and yet entirely credibly – at least two MPs then responded by sending explicit pictures themselves.Marina Hyde is a Guardian columnistDo you have an opinion on the issues raised in this article? If you would like to submit a response of up to 300 words by email to be considered for publication in our letters section, please click here. Continue reading...

Talent shortage is leading to automation and outsourcing

05 April 2024
A new report discusses trends in automation and outsourcing within IT teams. 

Senior Tory MP to keep whip during sexting scandal investigation

05 April 2024
Senior Tory MP to keep whip during sexting scandal investigation Party source says William Wragg will not face suspension for now after giving phone numbers of colleagues to Grindr app contactUK politics – latest updatesA senior Conservative MP will keep the whip while the party investigates his role in a sexting scandal.A Conservative source said William Wragg, the Tory MP for Hazel Grove, would not be suspended from the party whip for now amid concerns that he is also a victim. Continue reading...

CISO Perspectives on Complying with Cybersecurity Regulations

05 April 2024
Compliance requirements are meant to increase cybersecurity transparency and accountability. As cyber threats increase, so do the number of compliance frameworks and the specificity of the security controls, policies, and activities they include. For CISOs and their teams, that means compliance is a time-consuming, high-stakes process that demands strong organizational and

From PDFs to Payload: Bogus Adobe Acrobat Reader Installers Distribute Byakugan Malware

05 April 2024
Bogus installers for Adobe Acrobat Reader are being used to distribute a new multi-functional malware dubbed Byakugan. The starting point of the attack is a PDF file written in Portuguese that, when opened, shows a blurred image and asks the victim to click on a link to download the Reader application to view the content. According to Fortinet FortiGuard Labs, clicking the URL

Bing Ad for NordVPN Leads to SecTopRAT

05 April 2024
A very recent malvertising campaign was found impersonating the popular VPN software NordVPN. A malicious advertiser is capturing traffic from Bing searches and redirecting users to a decoy site that looks almost identical to the real one.

Fake Lawsuit Threat Exposes Privnote Phishing Sites

05 April 2024
A cybercrook who has been setting up websites that mimic the self-destructing message service privnote.com accidentally exposed the breadth of their operations recently when they threatened to sue a software company.

Byakugan – The Malware Behind a Phishing Attack

05 April 2024
In January 2024, FortiGuard Labs collected a PDF file written in Portuguese that distributes a multi-functional malware known as Byakugan. While investigating this campaign, a report about it was published.

New Wave of JSOutProx Malware Targeting Financial Firms in APAC and MENA

05 April 2024
Financial organizations in the Asia-Pacific (APAC) and Middle East and North Africa (MENA) are being targeted by a new version of an "evolving threat" called JSOutProx. "JSOutProx is a sophisticated attack framework utilizing both JavaScript and .NET," Resecurity said in a technical report published this week. "It employs the .NET (de)serialization feature to interact with a core

Critical Flaw in LayerSlider WordPress Plugin Impacts One Million Sites

05 April 2024
A premium WordPress plugin named LayerSlider, used in over one million sites, is vulnerable to unauthenticated SQL injection, requiring admins to prioritize applying security updates for the plugin.

Researchers Identify Multiple China Hacker Groups Exploiting Ivanti Security Flaws

05 April 2024
Multiple China-nexus threat actors have been linked to the zero-day exploitation of three security flaws impacting Ivanti appliances (CVE-2023-46805, CVE-2024-21887, and CVE-2024-21893). The clusters are being tracked by Mandiant under the monikers UNC5221, UNC5266, UNC5291, UNC5325, UNC5330, and UNC5337. Another group linked to the exploitation spree is UNC3886. The Google Cloud

Senior Tory ‘mortified’ after reportedly passing MPs’ data to dating app contact

04 April 2024
Senior Tory ‘mortified’ after reportedly passing MPs’ data to dating app contact William Wragg says he was pressed for colleagues’ details after sharing compromising photos of himselfA senior Conservative MP has reportedly admitted to giving out the personal phone numbers of colleagues to a person he met on a dating app.William Wragg told the Times that he gave the information after he had sent intimate pictures of himself, saying he was “scared” and “mortified”. Continue reading...

Police launch inquiry after MPs targeted in apparent ‘spear-phishing’ attack

04 April 2024
Police launch inquiry after MPs targeted in apparent ‘spear-phishing’ attack At least a dozen people sent suspicious messages, with senior figures suggesting foreign state could be culpritA police investigation has been launched after MPs were apparently targeted in a “spear-phishing” attack, in what security experts believe could be an attempt to compromise parliament.A police force said it had started an inquiry after receiving a complaint from an MP who was sent a number of unsolicited messages last month. Continue reading...

DHS proposes reporting rules for critical infrastructure

04 April 2024
Security leaders respond to the proposed critical infrastructure rules set forth by the DHS. 

Vietnam-Based Hackers Steal Financial Data Across Asia with Malware

04 April 2024
A suspected Vietnamese-origin threat actor has been observed targeting victims in several Asian and Southeast Asian countries with malware designed to harvest valuable data since at least May 2023. Cisco Talos is tracking the cluster under the name CoralRaider, describing it as financially motivated. Targets of the campaign include India, China, South Korea, Bangladesh, Pakistan, Indonesia,

New Phishing Campaign Targets Oil & Gas with Evolved Data-Stealing Malware

04 April 2024
An updated version of an information-stealing malware called Rhadamanthys is being used in phishing campaigns targeting the oil and gas sector. "The phishing emails use a unique vehicle incident lure and, in later stages of the infection chain, spoof the Federal Bureau of Transportation in a PDF that mentions a significant fine for the incident," Cofense researcher Dylan Duncan said. The

Scrut Automation Secures $10 Million in Growth Capital

04 April 2024
Scrut Automation, a GRC platform provider, has announced today that it secured $10 million in growth capital from its existing investors, including Lightspeed, MassMutual Ventures, and Endiya Partners.

Fake Lawsuit Threat Exposes Privnote Phishing Sites

04 April 2024
A cybercrook who has been setting up websites that mimic the self-destructing message service Privnote.com accidentally exposed the breadth of their operations recently when they threatened to sue a software company. The disclosure revealed a profitable network of phishing sites that behave and look like the real Privnote, except that any messages containing cryptocurrency addresses will be automatically altered to include a different payment address controlled by the scammers.

New SEXi Ransomware Gang Targets VMware ESXi Servers

04 April 2024
Chilean data center and hosting provider IxMetro Powerhost has suffered a cyberattack at the hands of a new ransomware gang known as SEXi, which encrypted the company's VMware ESXi servers and backups.

Targeted Phishing Linked to 'The Com' Surges in the US, the UK, and Canada

04 April 2024
A persistent social engineering threat faced by enterprises involves attackers trying to obtain login credentials for identity and access management (IAM), cloud resources, or single sign-on (SSO)-enabled systems.