Latest Cybersecurity News and Articles


New Hacker Group 'GambleForce' Tageting APAC Firms Using SQL Injection Attacks

14 December 2023
The group relies on open-source tools like dirsearch, sqlmap, tinyproxy, and redis-rogue-getshell at different stages of the attacks and a post-exploitation framework called Cobalt Strike.

Russian SVR-Linked APT29 Targets JetBrains TeamCity Servers in Ongoing Attacks

14 December 2023
Threat actors affiliated with the Russian Foreign Intelligence Service (SVR) have targeted unpatched JetBrains TeamCity servers in widespread attacks since September 2023. The activity has been tied to a nation-state group known as APT29, which is also tracked as BlueBravo, Cloaked Ursa, Cozy Bear, Midnight Blizzard (formerly Nobelium), and The Dukes. It's notable for the supply chain

EU’s Internet Reforms Will Undermine a Decade of Advances in Online Security

14 December 2023
The proposed eIDAS 2.0 bill in the European Union threatens online privacy and security by revoking web browsers' ability to independently test the authenticity and trustworthiness of certificate authorities.

Update: Hackers are Exploiting Critical Apache Struts Flaw Using Public PoC

14 December 2023
Hackers are actively exploiting a critical vulnerability in Apache Struts that allows for remote code execution, potentially leading to unauthorized access, data theft, and network disruption.

Whatsapp, Slack, Teams, and Other Messaging Platforms Face Constant Security Risks

14 December 2023
According to SafeGuard Cyber, the use of popular messaging apps like WhatsApp in business settings has led to a significant increase in security incidents, with 42% of flagged messages occurring in WhatsApp.

US Senate Confirms Harry Coker Jr. as National Cyber Director

14 December 2023
Harry Coker Jr., a Navy veteran and former executive director of the National Security Agency, will lead the Office of the National Cyber Director and be responsible for implementing the national cybersecurity strategy.

Silent, Yet Powerful Pandora hVNC, The Popular Cybercrime Tool That Flies Under the Radar

14 December 2023
Pandora hVNC is a widely used remote access trojan (RAT) that allows cybercriminals to gain covert control over victims' computers, enabling activities like data theft and unauthorized access to sensitive systems.

LockBit Ransomware Now Poaching BlackCat, NoEscape Affiliates

14 December 2023
Affiliates associated with NoEscape claimed that the ransomware operators pulled an exit scam, stealing millions of dollars in ransom payments and shutting off the operation's web panels and data leak sites.

Update: Credit Union Operations Restored After Tech Supplier Ransomware Attack

14 December 2023
The NCUA has been in contact with the affected financial institutions and helped them get their systems back online. The attack, which was caused by ransomware, affected credit unions using cloud services provided by Ongoing Operations.

New Hacker Group 'GambleForce' Tageting APAC Firms Using SQL Injection Attacks

14 December 2023
A previously unknown hacker outfit called GambleForce has been attributed to a series of SQL injection attacks against companies primarily in the Asia-Pacific (APAC) region since at least September 2023. "GambleForce uses a set of basic yet very effective techniques, including SQL injections and the exploitation of vulnerable website content management systems (CMS) to steal sensitive

Microsoft Takes Legal Action to Crack Down on Storm-1152's Cybercrime Network

14 December 2023
Microsoft on Wednesday said it obtained a court order to seize infrastructure set up by a group called Storm-1152 that peddled roughly 750 million fraudulent Microsoft accounts and tools through a network of bogus websites and social media pages to other criminal actors, netting them millions of dollars in illicit revenue. "Fraudulent online accounts act as the gateway to a host of cybercrime,

39% of security leaders cite phishing as most feared cyberattack

13 December 2023
Security leaders were surveyed about cyberattack response. According to the report, 39% indicated phishing is the most feared cyberattack.

Zero Networks Raises $20 Million Series B to Prevent Attackers From Spreading in Corporate Networks

13 December 2023
The funding round was led by U.S. Venture Partners (USVP), and included strategic investor Dmitri Alperovitch, co-founder and former CTO of CrowdStrike, as well as existing investors Venrock, CyberArk, F2 Capital, and Pico Venture Partners.

New Underground Market Comes Online Just inTime for the Holidays

13 December 2023
The OLVX marketplace operates on the clear web and has gained popularity in recent months. It offers various products and services, including phish kits, remote desktop connections, cPanel credentials, webshells, and stolen data.

BazaCall Phishing Scammers Now Leveraging Google Forms for Deception

13 December 2023
The threat actors behind the BazaCall call back phishing attacks have been observed leveraging Google Forms to lend the scheme a veneer of credibility. The method is an "attempt to elevate the perceived authenticity of the initial malicious emails," cybersecurity firm Abnormal Security said in a report published today. BazaCall (aka BazarCall), which was first

Update: Ransomware Group Publishes Stolen Medical Data

13 December 2023
The effects of a November ransomware attack against Oceanside, California’s Tri-City Medical Center were contained more than two weeks ago, but now those behind the cyber incident are publishing stolen data on the dark web.

Challenges of deep fakes in cybersecurity

13 December 2023
Brent Arnold, a partner practicing in Gowling WLG's Advocacy department, discusses the challenges the security industry faces with more and more convincing deepfakes making the rounds.

Sophos Backports Fix for CVE-2022-3236 for EOL Firewall Firmware

13 December 2023
Sophos has backported the patch for CVE-2022-3236 to end-of-life (EOL) firewall firmware versions due to ongoing attacks exploiting the vulnerability. The code injection vulnerability is being actively exploited by threat actors to target South Asia.

Report: 90% of energy companies experienced a third-party breach

13 December 2023
New research reveals that 90% of the world’s leading energy companies experienced a third-party data breach in the past 12 months.

FCC Reminds Mobile Phone Carriers They Must do More to Prevent SIM Swaps

13 December 2023
The FCC has updated its rules to require carriers to better verify customers' identities before making any changes to their accounts. The agency also emphasized the importance of quickly notifying customers of any account changes.