Latest Cybersecurity News and Articles


Perception gap exists in what causes cyber incidents & data breaches

08 December 2023
A recent study reveals that the media, academia and the general public overestimate the prevalence of system intrusions while underestimating more common causes of cybersecurity incidents and data breaches.

N. Korean Kimsuky Targeting South Korean Research Institutes with Backdoor Attacks

08 December 2023
The North Korean threat actor known as Kimsuky has been observed targeting research institutes in South Korea as part of a spear-phishing campaign with the ultimate goal of distributing backdoors on compromised systems. "The threat actor ultimately uses a backdoor to steal information and execute commands," the AhnLab Security Emergency Response Center (ASEC) said in an

Russian Military Hackers Target NATO Fast Reaction Corps

08 December 2023
Russian APT28 hackers, also known as Fancy Bear, exploited a Microsoft Outlook zero-day vulnerability to target European NATO member countries, including a NATO Rapid Deployable Corps.

Hacking the Human Mind: Exploiting Vulnerabilities in the 'First Line of Cyber Defense'

08 December 2023
Understanding human vulnerabilities and the ways in which attackers manipulate emotions and fundamental traits is crucial for identifying and responding to cybersecurity threats.

Novel 'DDSpoof' Attacks Abuse Microsoft DHCP Servers to Spoof DNS Records

08 December 2023
The default configuration of Microsoft Dynamic Host Configuration Protocol (DHCP) servers leaves a significant number of organizations vulnerable to these attacks, making them accessible to a wide range of attackers.

ProvenRun Raises $16.2M in Series A Funding

08 December 2023
The round was led by Tikehau Capital, through its new vintage of Brienne, its flagship private equity cybersecurity strategy with the French Ministry of Defence’s Definvest fund, managed by Bpifrance.

New Variants of HeadCrab Malware Commandeer Thousands of Servers

08 December 2023
The HeadCrab malware has resurfaced with a new variant that allows root access to Redis servers, infecting over 1,100 servers and enabling the attacker to control and modify responses.

Founder of Bitzlato Cryptocurrency Exchange Pleads Guilty in Money-Laundering Scheme

08 December 2023
The cryptocurrency exchange operated with lax know-your-customer (KYC) procedures and had a significant partnership with the Hydra darknet marketplace for cryptocurrency transactions.

Microsoft Is Getting a New 'Outsider' CISO

08 December 2023
Microsoft is making changes to its cybersecurity leadership, with Bret Arsenault being moved from his role as CISO to a chief security adviser position. Igor Tsyganskiy will take over as the new CISO.

Ransomware-as-a-Service: The Growing Threat You Can't Ignore

08 December 2023
Ransomware attacks have become a significant and pervasive threat in the ever-evolving realm of cybersecurity. Among the various iterations of ransomware, one trend that has gained prominence is Ransomware-as-a-Service (RaaS). This alarming development has transformed the cybercrime landscape, enabling individuals with limited technical expertise to carry out devastating attacks.

Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns

08 December 2023
Star Blizzard uses extensive research and preparation, including creating fake email accounts and social media profiles, to build trust with their targets before delivering malicious links.

Progress Software Discloses Two New CVEs in MOVEit

08 December 2023
Progress Software has disclosed two new high-severity vulnerabilities in its MOVEit file-transfer service, bringing the total number of vulnerabilities to eight since a zero-day exploit in May.

Mac Users Beware: New Trojan-Proxy Malware Spreading via Pirated Software

08 December 2023
Unauthorized websites distributing trojanized versions of cracked software have been found to infect Apple macOS users with a new Trojan-Proxy malware. "Attackers can use this type of malware to gain money by building a proxy server network or to perform criminal acts on behalf of the victim: to launch attacks on websites, companies and individuals, buy guns, drugs, and other illicit

BEC 3.0 Phishing Attack via Genial.ly

08 December 2023
Hackers are using the free website Genial.ly to send phishing links as part of a Business Compromise 3.0 attack. Users receive legitimate-looking emails inviting them to click on a link to view content created in Genial.ly.

MrAnon Stealer Spreads via Email with Fake Hotel Booking PDF

08 December 2023
This malware is a Python-based information stealer compressed with cx-Freeze to evade detection. MrAnon Stealer steals its victims' credentials, system information, browser sessions, and cryptocurrency extensions.

WordPress Releases Update 6.4.2 to Address Critical Remote Attack Vulnerability

08 December 2023
WordPress has released version 6.4.2 with a patch for a critical security flaw that could be exploited by threat actors by combining it with another bug to execute arbitrary PHP code on vulnerable sites. "A remote code execution vulnerability that is not directly exploitable in core; however, the security team feels that there is a potential for high severity when combined with some plugins,

WordPress Fixes POP Chain Exposing Websites to RCE Attacks

08 December 2023
This vulnerability could allow attackers to run arbitrary PHP code on a target website. The vulnerability is a Property Oriented Programming (POP) chain that requires an attacker to control all the properties of a deserialized object.

Founder of Bitzlato Cryptocurrency Exchange Pleads Guilty in Money-Laundering Scheme

08 December 2023
The Russian founder of the now-defunct Bitzlato cryptocurrency exchange has pleaded guilty, nearly 11 months after he was arrested in Miami earlier this year. Anatoly Legkodymov (aka Anatolii Legkodymov, Gandalf, and Tolik), according to the U.S. Justice Department, admitted to operating an unlicensed money-transmitting business that enabled other criminal actors to launder their

John Denning joins FS-ISAC as Chief Information Security Officer

07 December 2023
FS-ISAC has announced the appointment of John Denning as Chief Information Security Officer (CISO) effective as of January 1, 2024.

Google Pushes Yet Another Security Update to Its Chrome Browser

07 December 2023
Chrome version 120 includes 10 bug fixes, with two of them being highly critical security patches. The high-ranked security vulnerabilities include "Use after free" exploits in Media Stream and Side Panel Search.