Latest Cybersecurity News and Articles


77% of financial organizations detected a cyberattack in the last year

19 December 2023
According to a recent Netwrix report, 77% of financial organizations detected a cyberattack in the last year, compared to 68% in other industries.

Xfinity Discloses Massive Data Breach Affecting Over 35 Million People

19 December 2023
The breach occurred after attackers exploited a critical vulnerability, known as Citrix Bleed, that had been actively exploited as a zero-day since August 2023. The company has asked users to reset their passwords.

Novel SMTP Smuggling Technique Slips Past DMARC, Email Protections

19 December 2023
Attackers can exploit SMTP smuggling to send spoofed emails with fake sender addresses, bypassing email security checks and putting organizations and individuals at risk for targeted phishing attacks.

Hackers Abusing GitHub to Evade Detection and Control Compromised Hosts

19 December 2023
Threat actors are increasingly making use of GitHub for malicious purposes through novel methods, including abusing secret Gists and issuing malicious commands via git commit messages. "Malware authors occasionally place their samples in services like Dropbox, Google Drive, OneDrive, and Discord to host second stage malware and sidestep detection tools," ReversingLabs researcher Karlo Zanki 

US Agencies Release Security Guidance on Managing SBOMs and Open Source Software

19 December 2023
The report provides guidance on open source software adoption, including criteria for selection, risk assessment, licensing, export control, maintenance, vulnerability response, and secure software delivery.

Henry Schein reports 29K affected in September cyberattack

19 December 2023
In a filing with the Maine Attorney General, dental and medical products supplier Henry Schein announced more than 29,000 people were potentially affected from a recent data breach.

Henry Schein reports 29K affected in September cyber attack

19 December 2023
In a filing with the Maine Attorney General, dental and medical products supplier Henry Schein announced more than 29,000 people were potentially affected from a recent data breach.

CISA Urges Manufacturers to Eliminate Default Passwords to Thwart Cyber Threats

19 December 2023
Manufacturers are advised to follow Secure by Design principles, provide unique setup passwords or disable them after a preset time period, and implement phishing-resistant multi-factor authentication methods to mitigate these risks.

Are We Ready to Give Up on Security Awareness Training?

19 December 2023
Some of you have already started budgeting for 2024 and allocating funds to security areas within your organization. It is safe to say that employee security awareness training is one of the expenditure items, too. However, its effectiveness is an open question with people still engaging in insecure behaviors at the workplace. Besides, social engineering remains one of the most prevalent attacks

Iran Hit by Major Cyberattack Targeting Nation's Fuel Supply

19 December 2023
Gas stations in Iran experienced widespread disruptions due to a cyberattack claimed by the group Predatory Sparrow, which has previously targeted Iranian critical infrastructure.

Iranian Hackers Using MuddyC2Go in Telecom Espionage Attacks Across Africa

19 December 2023
The Iranian nation-state actor known as MuddyWater has leveraged a newly discovered command-and-control (C2) framework called MuddyC2Go in its attacks on the telecommunications sector in Egypt, Sudan, and Tanzania. The Symantec Threat Hunter Team, part of Broadcom, is tracking the activity under the name Seedworm, which is also tracked under the monikers Boggy Serpens, Cobalt

New Malvertising Campaign Distributing PikaBot Disguised as Popular Software

19 December 2023
The malware loader known as PikaBot is being distributed as part of a malvertising campaign targeting users searching for legitimate software like AnyDesk. "PikaBot was previously only distributed via malspam campaigns similarly to QakBot and emerged as one of the preferred payloads for a threat actor known as TA577," Malwarebytes' Jérôme Segura said. The malware family,

Apparel Giant VF Corporation Reports Cyberattack on First Day of SEC Disclosure Rule

19 December 2023
VF Corporation, one of the largest apparel companies in the world, reported a cyberattack to the U.S. Securities and Exchange Commission (SEC) on the first day of a new cyber incident reporting rule.

What the SEC Weighed in Finalizing the Cyber Disclosure Rules

19 December 2023
The SEC does not aim to manage security but wants better disclosures. The final rule requires the disclosure of material cybersecurity incidents, but does not require specific technical details to avoid providing a roadmap for future attacks.

Insights from the CISA Healthcare and Public Health Sector Risk and Vulnerability Assessment

19 December 2023
The external assessment did not identify any significant vulnerabilities that would allow easy access to the organization's network, but the internal assessment revealed multiple weaknesses that led to domain compromise.

US Regulators Warn of AI Risk to Financial Systems

19 December 2023
The Financial Stability Oversight Council has classified artificial intelligence as an "emerging vulnerability" in the financial system, acknowledging both its potential for innovation and the risks it poses.

xorbot: A Stealthy Botnet Family That Defies Detection

19 December 2023
Xorbot utilizes encryption and decryption algorithms, borrowed from the Mirai source code, to encrypt communication with its command and control server and store sensitive information.

Microsoft is Working on a More Secure Print System for Windows

19 December 2023
Microsoft has introduced Windows Protected Print Mode (WPP) to enhance security and eliminate vulnerabilities in the Windows print system. These changes aim to reduce the attack surface and enhance user safety.

Researchers Disclose Zero-Click Exploit for Microsoft Outlook

19 December 2023
The vulnerabilities, CVE-2023-35384 and CVE-2023-36710, allow an attacker to bypass security measures and execute code on a victim's machine by tricking Outlook into downloading a specially crafted sound file.

Alleged LockBit Operator to Face New Cybercrime Charges in Canada

19 December 2023
A Canadian-Russian man, Mikhail Vasiliev, who is facing extradition to the United States for his alleged involvement in the LockBit ransomware group, is now facing new cybercrime charges in Ontario.