Latest Cybersecurity News and Articles


Hackers Can Exploit 'Forced Authentication' to Steal Windows NTLM Tokens

28 November 2023
Cybersecurity researchers have discovered a case of "forced authentication" that could be exploited to leak a Windows user's NT LAN Manager (NTLM) tokens by tricking a victim into opening a specially crafted Microsoft Access file. The attack takes advantage of a legitimate feature in the database management system solution that allows users to link to external data sources, such as a remote SQL

What a Failed Attack Against ColdFusion Revealed About Ransomware Tools and Tactics

28 November 2023
Following the trail of telemetry left behind, the Sophos researchers found the attackers had left directory listings enabled on the web server hosting their repository of tools. This enabled the researchers to explore the materials.

Ardent Hospitals Diverting Patients Following Ransomware Attack

28 November 2023
Ransomware attack forces Ardent hospitals to shut down systems, impacting clinical and financial operations. The post Ardent Hospitals Diverting Patients Following Ransomware Attack appeared first on SecurityWeek.

'Serial Cybercriminal and Scammer' Jailed for 8 Years

28 November 2023
Between April 2019 and February 2023, Golshan defrauded "hundreds" of people via various online scams and digital account thefts, according to prosecutors. Over the nearly four-year period, he stole about $740,000 from more than 500 people.

Scott Metro joins Hazeltree as Chief Information Security Officer

28 November 2023
Scott Metro has been appointed as Chief Information Security Officer (CISO) at Hazeltree. Scott brings more than 25 years of compliance experience.

N. Korean Hackers 'Mixing' macOS Malware Tactics to Evade Detection

27 November 2023
The North Korean threat actors behind macOS malware strains such as RustBucket and KANDYKORN have been observed "mixing and matching" different elements of the two disparate attack chains, leveraging RustBucket droppers to deliver KANDYKORN. The findings come from cybersecurity firm SentinelOne, which also tied a third macOS-specific malware called ObjCShellz to the RustBucket campaign.

How to Handle Retail SaaS Security on Cyber Monday

27 November 2023
If forecasters are right, over the course of today, consumers will spend $13.7 billion. Just about every click, sale, and engagement will be captured by a CRM platform. Inventory applications will trigger automated re-orders; communication tools will send automated email and text messages confirming sales and sharing shipping information.  SaaS applications supporting retail efforts will host

Rivers Casino Joins the Club of Hacked Casinos

27 November 2023
Rivers Casino Des Plaines is the most profitable casino in the state of Illinois. Currently, there is no information on who is behind the attack. The number of people potentially affected by the breach is also unknown.

Rhysida Ransomware Group Claimed China Energy Hack

27 November 2023
The ransomware group claims to have stolen a substantial trove of ‘impressive data’ and is auctioning it for 50 BTC. The gang announced to publicly release the data over the seven days following the announcement.

Portneuf Medical Center Latest In a String of Cyberattacks

27 November 2023
The hospital’s IT team is working to determine the impact of the outage and restore access to the network. Meanwhile, the healthcare provider is following established downtime protocols, revealed a spokesperson for Portneuf Medical Center.

Critical ownCloud Flaws Lead to Sensitive Information Disclosure, Authentication Bypass

27 November 2023
Three critical vulnerabilities in ownCloud could lead to sensitive information disclosure and authentication and validation bypass. The post Critical ownCloud Flaws Lead to Sensitive Information Disclosure, Authentication Bypass appeared first on SecurityWeek.

Henry Schein Again Restoring Systems After Ransomware Group Causes More Disruption

27 November 2023
Healthcare solutions giant Henry Schein is once again restoring systems after ransomware group claims it re-encrypted files. The post Henry Schein Again Restoring Systems After Ransomware Group Causes More Disruption appeared first on SecurityWeek.

Municipal Water Authority of Aliquippa Hacked by Iranian-backed Cyber Group

27 November 2023
The machine that was hacked uses a system called Unitronics, which contains software or has components that are Israeli-owned. The system has since been disabled. Authorities stressed that there is no known risk to the drinking water or water supply.

Lazarus Group Exploit MagicLine4NX Flaw to Launch Supply Chain Attacks

27 November 2023
The NCSC and South Korea’s NIS issued a joint warning against the Lazarus hacking group leveraging a zero-day flaw in the MagicLine4NX software. The zero-day exploit allowed Lazarus to conduct a series of supply-chain attacks, starting with a watering hole attack on a media outlet's website. Organizations using a vulnerable version of MagicLine4NX must update the software to the latest version to stay safe.

DHS CISA release joint guidelines for secure AI system development

27 November 2023
 CISA and the NCSC jointly released Guidelines for Secure AI System Development to help developers of any systems that use AI make informed cybersecurity decisions at every stage of the development process. 

E-commerce is used a lure for 43% of phishing attacks

27 November 2023
According to a Kapersky report, there were over 30 million phishing attacks in 2023, increasing during holiday online shopping periods.

New 'HrServ.dll' Web Shell Detected in APT Attack Targeting Afghan Government

27 November 2023
The attack chain involves the PAExec remote administration tool, an alternative to PsExec that's used as a launchpad to create a scheduled task that masquerades as 'MicrosoftsUpdate' which subsequently is configured to execute a Windows batch script.

Experts Uncover Passive Method to Extract Private RSA Keys from SSH Connections

27 November 2023
A new study has demonstrated that it's possible for passive network attackers to obtain private RSA host keys from a vulnerable SSH server by observing when naturally occurring computational faults that occur while the connection is being established. The Secure Shell (SSH) protocol is a method for securely transmitting commands and logging in to a computer over an unsecured network. Based on a

US, UK Cybersecurity Agencies Publish AI Development Guidance

27 November 2023
New guidance from US and UK cybersecurity agencies provides recommendations for secure AI system development. The post US, UK Cybersecurity Agencies Publish AI Development Guidance appeared first on SecurityWeek.

KyberSwap Says $54.7 Million in Cryptocurrency Stolen During Attack

27 November 2023
The company is now trying to recover the funds but argued that the incident “stands out as one of the most sophisticated in the history of DeFi.” The company advised users to “promptly withdraw their funds.”