Latest Cybersecurity News and Articles
12 December 2023
A phishing campaign has been observed delivering an information stealer malware called MrAnon Stealer to unsuspecting victims via seemingly benign booking-themed PDF lures.
"This malware is a Python-based information stealer compressed with cx-Freeze to evade detection," Fortinet FortiGuard Labs researcher Cara Lin said. "MrAnon Stealer steals its victims' credentials, system
12 December 2023
The White House plans to collaborate with the Department of Health and Human Services to establish minimum cybersecurity standards to protect the healthcare sector from ransomware and other cyber threats.
12 December 2023
Henry Schein has notified Maine's attorney general that the personal information of over 29,000 people may have been accessed in a cyber incident in September. The hackers obtained names, financial account information, and security codes.
12 December 2023
Amazon has taken legal action against an underground refund scheme called REKK, involving an international fraudulent organization and former Amazon employees, resulting in the theft of millions of dollars worth of products.
12 December 2023
The National Cybersecurity Authority will coordinate and implement policies and measures to enhance Greece's cybersecurity ecosystem and effectively prevent and manage cyberattacks.
12 December 2023
Apple has released security patches for various devices and software, including iOS, iPadOS, macOS, tvOS, watchOS, and Safari. These patches address multiple security flaws, including two recently disclosed zero-day vulnerabilities.
12 December 2023
Kubescape, an open-source project, has become the first to generate Vulnerability Exploitability eXchange (VEX) documents. VEX is a standard that helps share information about vulnerabilities and their potential for exploitation.
12 December 2023
This settlement marks the first resolution by HHS involving a phishing attack that violated the Health Insurance Portability and Accountability Act (HIPAA), highlighting the need for healthcare organizations to prioritize cybersecurity measures.
12 December 2023
LivaNova has not yet issued an official statement or response regarding the breach, and cybersecurity experts are closely monitoring the situation for further developments.
12 December 2023
Apple on Monday released security patches for iOS, iPadOS, macOS, tvOS, watchOS, and Safari web browser to address multiple security flaws, in addition to backporting fixes for two recently disclosed zero-days to older devices.
This includes updates for 12 security vulnerabilities in iOS and iPadOS spanning AVEVideoEncoder, ExtensionKit, Find My, ImageIO, Kernel, Safari
12 December 2023
Apache has released a security advisory warning of a critical security flaw in the Struts 2 open-source web application framework that could result in remote code execution.
Tracked as CVE-2023-50164, the vulnerability is rooted in a flawed "file upload logic" that could enable unauthorized path traversal and could be exploited under the circumstances to upload a malicious file
11 December 2023
According to a recent report by Apple, the total number of data breaches more than tripled between 2013 and 2022, and rose further in 2023.
11 December 2023
The APT group known as Sandman and a China-based threat cluster using the backdoor KEYPLUG share infrastructure control and management practices, indicating potential overlap in their operations.
11 December 2023
Kelvin Security has been active since 2013, targeting public-facing systems to obtain user credentials and steal confidential data, which they would sell or leak on hacking forums.
11 December 2023
The University of Wollongong has experienced a data breach, with potentially both staff and students affected. The breach has been detected and contained, and investigations are underway to determine the scope of the breach.
11 December 2023
Identity management solution provider Opal Security has managed to raise $22 million in a Series B round to expand its team and develop new AI-powered tools for identity and access risk remediation.
11 December 2023
The Apache Software Foundation has released security updates to address a critical file upload vulnerability in the Struts 2 framework, which could allow for remote code execution.
11 December 2023
Red Roof confirmed that the organization experienced a data breach in late September of 2023. The breach did not involve any Red Roof guest data.
11 December 2023
Researchers have identified new techniques employed by the GuLoader malware to enhance its evasion capabilities and make analysis more challenging. The highly evasive shellcode downloader malware was found leveraging Vectored Exception Handler (VEH) capability. Organizations can leverage the latest YARA rules from Elastic Security to detect malware.
11 December 2023
Insider threats, including both malicious attacks and unintentional risks, are on the rise, with privilege escalation exploits being a significant component of unauthorized activity.