Latest Cybersecurity News and Articles


CISA Releases Cybersecurity Guidance for Healthcare, Public Health Organizations

21 November 2023
The guide incorporates vulnerability data, known exploited vulnerabilities, and the MITRE ATT&CK framework. It covers topics such as asset management, identity management, device security, vulnerabilities, patching, and secure design principles.

VX-Underground Malware Sharing Collective Framed by Phobos Ransomware

21 November 2023
A new variant of the Phobos ransomware has been discovered, which attempts to frame VX-Underground. Phobos ransomware, which emerged in 2018, operates as a ransomware-as-a-service and has seen wide distribution through affiliated threat actors.

8Base Group Found Deploying a New Phobos Ransomware Variant

21 November 2023
The 8Base ransomware attackers have incorporated a new variant of the Phobos ransomware and publicly available tools for financially motivated attacks. The variant used by the 8Base group includes features that can enable attackers to establish persistence on victims’ systems, perform speedy encryption, and remove backup and shadow copies. Organizations are recommended to keep track of the threats by following the latest IOCs associated with the ransomware.

Greater Paris Wastewater Agency Dealing with Cyberattack

21 November 2023
The attack prompted SIAAP to file a complaint with authorities and take immediate measures to secure their systems to prevent further spread. It has prioritized maintaining the public sanitation service and is working to ensure a return to normalcy.

Cybersecurity Firm Executive Pleads Guilty to Hacking Hospitals

21 November 2023
Vikas Singla, the former COO of a cybersecurity company, pleaded guilty to hacking two hospitals in an attempt to boost his company's business. Singla disrupted phone and printer services at the hospitals and stole personal information from patients.

MOVEit Mass-Hack Victim Count Grows to Over 2,600 Firms, 77 Million People

21 November 2023
Welltok, a patient communication services provider, has notified over 1.6 million patients that their private healthcare data may have been stolen in the MOVEit breach, affecting healthcare providers such as Stanford Health Care and Sutter Health.

LLM Security Startup Lasso Emerges From Stealth Mode

21 November 2023
Lasso Security raises $6 million in seed funding to tackle cyber threats to secure generative AI and large language model algorithms. The post LLM Security Startup Lasso Emerges From Stealth Mode appeared first on SecurityWeek.

Kinsing Hackers Exploit Apache ActiveMQ Vulnerability to Deploy Linux Rootkits

21 November 2023
Organizations running affected versions of Apache ActiveMQ should update to a patched version as soon as possible to mitigate potential threats and protect their systems from the Kinsing malware.

Play Ransomware Goes Commercial - Now Offered as a Service to Cybercriminals

21 November 2023
The ransomware strain known as Play is now being offered to other threat actors "as a service," new evidence unearthed by Adlumin has revealed. "The unusual lack of even small variations between attacks suggests that they are being carried out by affiliates who have purchased the ransomware-as-a-service (RaaS) and are following step-by-step instructions from playbooks delivered with it," the

CISA Offering Free Cybersecurity Services to Non-Federal Critical Infrastructure Entities

21 November 2023
New CISA pilot program brings cutting-edge cybersecurity services to critical infrastructure entities that need support. The post CISA Offering Free Cybersecurity Services to Non-Federal Critical Infrastructure Entities appeared first on SecurityWeek.

Hacker Leaks Vaccination Records of Over Two Million Turkish Citizens

21 November 2023
The leaked data, which includes birth dates, vaccination dates and types, hospitals, and partial Turkish Identification Numbers, was likely obtained through an information disclosure vulnerability.

Top cybersecurity trends of 2023

21 November 2023
As another year comes to a close, cybersecurity leaders are looking back and reviewing the top trends of 2023.

Top 2023 cybersecurity trends of 2023

21 November 2023
As another year comes to a close, cybersecurity leaders are looking back and reviewing the top trends of 2023.

66% of employees will shop on mobile phones this holiday season

21 November 2023
According to a recent Lookout report, phishing attacks are expected to more than double the week of Thanksgiving as employees spend more time online.

Detailed Data on Employees of US National Security Lab Leaked Online

21 November 2023
The hacking group SiegedSec claimed responsibility for the breach and stated that they obtained a significant amount of personal information, including social security numbers and banking details.

Canadian Military, Police Impacted by Data Breach at Moving Companies

21 November 2023
Data breach at moving companies impacts Canadian government employees, and military and police personnel. The post Canadian Military, Police Impacted by Data Breach at Moving Companies appeared first on SecurityWeek.

Tor Network Removes Risky Relays Associated With Cryptocurrency Scheme

21 November 2023
The Tor network has removed many relays associated with a cryptocurrency scheme, citing risk to integrity and users.  The post Tor Network Removes Risky Relays Associated With Cryptocurrency Scheme appeared first on SecurityWeek.

Morgan Stanley Fined $6.5 Million for Exposing Customer Information

21 November 2023
The company failed to properly erase personal data stored on decommissioned devices and did not monitor the actions of a third-party moving company, leading to the unauthorized sale of computer equipment containing sensitive information.

Malicious Apps Disguised as Banks and Government Agencies Targeting Indian Android Users

21 November 2023
The malware poses as legitimate organizations like banks and government services, urging users to install the malicious app to update their PAN card details, ultimately stealing banking information and personal data.

New Agent Tesla Malware Variant Using ZPAQ Compression in Email Attacks

21 November 2023
A new variant of the Agent Tesla malware has been observed delivered via a lure file with the ZPAQ compression format to harvest data from several email clients and nearly 40 web browsers. "ZPAQ is a file compression format that offers a better compression ratio and journaling function compared to widely used formats like ZIP and RAR," G Data malware analyst Anna Lvova said in a Monday analysis.