Latest Cybersecurity News and Articles


Russian APT28 Hackers Exploiting Outlook Bug to Hijack Exchange Accounts

05 December 2023
Microsoft warned that the Russian state-sponsored hacker group APT28 is actively exploiting vulnerabilities in Outlook, WinRAR, and Windows MSHTML to hijack Microsoft Exchange accounts and steal sensitive information.

Generative AI Security: Preventing Microsoft Copilot Data Exposure

05 December 2023
Microsoft Copilot has been called one of the most powerful productivity tools on the planet. Copilot is an AI assistant that lives inside each of your Microsoft 365 apps — Word, Excel, PowerPoint, Teams, Outlook, and so on. Microsoft's dream is to take the drudgery out of daily work and let humans focus on being creative problem-solvers. What makes Copilot a different beast than ChatGPT and

NCSC launches Cyber Incident Exercising scheme

05 December 2023
New CIE assured providers give organisations support to create structured table-top or live-play cyber incident exercises.

Accounting Software Giant Tipalti Investigating Ransomware Attack

05 December 2023
ALHV, a prolific ransomware group, allegedly gained persistent access to multiple Tipalti systems and stole over 265GB of data, with claims of insider involvement in the attacks.

Hershey phishes! Crooks snarf chocolate lovers' creds

05 December 2023
The phishing emails were sent to employees in early September and allowed the criminals to steal a range of personal data, including names, health and medical information, credit card numbers, and online account credentials.

15,000 Go Module Repositories on GitHub Vulnerable to Repojacking Attack

05 December 2023
New research has found that over 15,000 Go module repositories on GitHub are vulnerable to an attack called repojacking. "More than 9,000 repositories are vulnerable to repojacking due to GitHub username changes," Jacob Baines, chief technology officer at VulnCheck, said in a report shared with The Hacker News. "More than 6,000 repositories were vulnerable to repojacking due to account

Fake WordPress Security Advisory Pushes Backdoor Plugin

05 December 2023
The fake plugin, once installed, creates a hidden admin user and sends victim information to the attackers, while also downloading a backdoor payload that allows for file management, SQL client, and server environment information access.

December Android Updates Fix Critical Zero-Click RCE Flaw

05 December 2023
The zero-click RCE bug found in Android's System component allows attackers to gain arbitrary code execution without user interaction. The bug (CVE-2023-40088) is found in Android's System component and can be exploited without additional privileges.

PDF Phishing: Beyond the Bait

05 December 2023
Phishing attackers are increasingly using PDF documents to conduct successful campaigns by exploiting the trustworthiness of the file format and leveraging social engineering tactics.

TrickMo Banking Trojan Resurfaces with New Features, Targeting Android Devices this Time Around

05 December 2023
TrickMo replaces screen recording with collecting Accessibility event logs to gather data from running applications, requiring victims to grant Accessibility Service access.

ArmorCode Raises $40M To Consolidate Security Data in One Place

05 December 2023
ArmorCode aims to surface vulnerabilities in enterprise software and infrastructure through role-specific dashboards, providing threat intelligence tools and training for security teams.

Two New Versions of OpenZFS Fix Long-Hidden Corruption Bug

05 December 2023
The OpenZFS development team has released two new versions of the open-source cross-platform filesystem. Version 2.2.2 fixes a bug that caused data corruption in file copies and affected FreeBSD 14 and various Linux distros.

New Threat Actor 'AeroBlade' Emerges in Espionage Attack on U.S. Aerospace

05 December 2023
A previously undocumented threat actor has been linked to a cyber attack targeting an aerospace organization in the U.S. as part of what's suspected to be a cyber espionage mission. The BlackBerry Threat Research and Intelligence team is tracking the activity cluster as AeroBlade. Its origin is currently unknown and it's not clear if the attack was successful. "The actor used spear-phishing

Microsoft Warns of Kremlin-Backed APT28 Exploiting Critical Outlook Vulnerability

05 December 2023
Microsoft on Monday said it detected Kremlin-backed nation-state activity exploiting a critical security flaw in its Outlook email service to gain unauthorized access to victims' accounts within Exchange servers. The tech giant attributed the intrusions to a threat actor it called Forest Blizzard (formerly Strontium), which is also widely tracked under the monikers APT28,

Suspected digital shopping fraud up 12% during Cyber Five holiday

04 December 2023
A new report highlights global e-commerce fraud that occurred during the start of the 2023 holiday shopping season.

Mobile payment fraud increased in 2023

04 December 2023
According to a recent report from BioCatch, mobile banking rates increased to 73% in 2023. This rise has also led to a surge in mobile fraud.

Australia news live: Reserve Bank to deliver year’s last interest rates decision as economists tip no change

04 December 2023
Australia news live: Reserve Bank to deliver year’s last interest rates decision as economists tip no change Poll finds 28 of 30 economists expect central bank to keep cash rate steady at 4.35%. Follow the day’s news liveGet our morning and afternoon news emails, free app or daily news podcastIn case you missed it: early this morning, Westpac services came back online following an outage overnight where customers were unable to access their online accounts or use their cards.You can read all the details on this below:Our mobile and online banking services are now restored and running as usual.We want to apologise to all our customers who were impacted by the issue overnight. We recognise this took too long to resolve and we thank customers for their patience. Continue reading...

Establishing New Rules for Cyber Warfare

04 December 2023
The International Committee of the Red Cross (ICRC) has released a set of rules for civilian hackers involved in cyber conflicts. The rules aim to clarify the line between civilians and combatants in cyberspace during times of war.

New AeroBlade Hackers Target Aerospace Sector in the U.S.

04 December 2023
The attacks involve the use of weaponized documents with malicious macros that create a reverse shell, allowing the attackers to gain control over the compromised systems.

BlackCat Ransomware Strikes Ho Chi Minh City Power Corporation

04 December 2023
The ongoing attack spree by the BlackCat ransomware group extends beyond Vietnam Electricity, with social media platforms like Roblox and Twitch potentially being targeted next.