Latest Cybersecurity News and Articles


US Teen Pleads Guilty to Credential Stuffing Attack on Fantasy Sports Website

20 November 2023
Along with others, Joseph Garrison stole approximately $600,000 from 1,600 victim accounts by adding a new payment method, depositing $5 into each account, and then withdrawing the funds.

Are DarkGate and PikaBot the New QakBot?

20 November 2023
Phishing campaigns are using tactics previously seen in attacks involving the QakBot trojan to deliver malware families such as DarkGate and PikaBot. These campaigns utilize hijacked email threads, unique URL patterns, and a similar infection chain.

AT&T Forms Joint Venture for Managed Cybersecurity Business

20 November 2023
AT&T is forming a joint venture with investor WillJam Ventures to separate its managed cybersecurity services from its core connectivity business. WillJam Ventures will make a capital investment into the stand-alone cybersecurity services unit.

Public Service, RCMP, CAF Members Affected in Canadian Federal Government Data Breach

20 November 2023
The personal and financial information of current and former public service employees and members of the RCMP and Canadian Armed Forces may have been accessed in a data breach.

Report: Bad Bots Account for 73% of Internet Traffic

20 November 2023
The prevalence of bad bots is increasing due to the availability of artificial intelligence and the professionalization of the criminal underworld through crime-as-a-service offerings.

Drone Systems Maker Autonomous Flight Technologies Targeted by BlackCat Ransomware

20 November 2023
The attackers claim to have stolen data from Autonomous Flight Technologies (AFT) and sold it to a foreign entity. AFT, known for its partnerships with industry giants like Airbus and NASA, has not yet confirmed or responded to the breach.

NetSupport RAT Infections on the Rise - Targeting Government and Business Sectors

20 November 2023
Threat actors are targeting the education, government and business services sectors with a remote access trojan called NetSupport RAT. "The delivery mechanisms for the NetSupport RAT encompass fraudulent updates, drive-by downloads, utilization of malware loaders (such as GHOSTPULSE), and various forms of phishing campaigns," VMware Carbon Black researchers said in a report shared with The

Administrator of Darkode Hacking Forum Sentenced to Prison

20 November 2023
Thomas Kennedy McCormick, also known as 'Fubar', has been sentenced to 18 years in prison for his involvement in running the cybercrime forum Darkode. He was one of the last administrators of Darkode before it was shut down by authorities in 2015.

CISA Releases Cybersecurity Guidance for Healthcare, Public Health Organizations

20 November 2023
New CISA guidance details cyber threats and risks to healthcare and public health organizations and recommends mitigations. The post CISA Releases Cybersecurity Guidance for Healthcare, Public Health Organizations appeared first on SecurityWeek.

Product Walkthrough: Silverfort's Unified Identity Protection Platform

20 November 2023
In this article, we will provide a brief overview of Silverfort's platform, the first (and currently only) unified identity protection platform on the market. Silverfort’s patented technology aims to protect organizations from identity-based attacks by integrating with existing identity and access management solutions, such as AD (Active Directory) and cloud-based services, and extending secure

DarkGate and PikaBot Malware Resurrect QakBot's Tactics in New Phishing Attacks

20 November 2023
Phishing campaigns delivering malware families such as DarkGate and PikaBot are following the same tactics previously used in attacks leveraging the now-defunct QakBot trojan. “These include hijacked email threads as the initial infection, URLs with unique patterns that limit user access, and an infection chain nearly identical to what we have seen with QakBot delivery,” Cofense said in a report

Stately Taurus Targets the Philippines as Tensions Flare in the South Pacific

20 November 2023
The campaigns involved sideloading malicious files through renamed legitimate software like Solid PDF Creator and SmadavProtect, indicating a sophisticated approach to infiltrate and compromise government entities.

CISA Launches Pilot Program Offering ‘Cutting-Edge’ Services to Critical Infrastructure Orgs

20 November 2023
This program aims to reduce cyber risks, increase cost savings, and establish a common baseline of cyber protection for entities that face frequent cyberattacks and ransomware incidents.

Morgan Stanley Fined $6.5 Million for Exposing Customer Information

20 November 2023
Morgan Stanley agrees to pay $6.5 million for exposing personal information through negligent data-security practices. The post Morgan Stanley Fined $6.5 Million for Exposing Customer Information appeared first on SecurityWeek.

Microsoft Hires Sam Altman and OpenAI’s New CEO Vows to Investigate His Firing

20 November 2023
Microsoft hired Sam Altman and another architect of OpenAI for a new venture after their sudden departures shocked the artificial intelligence world. The post Microsoft Hires Sam Altman and OpenAI’s New CEO Vows to Investigate His Firing appeared first on SecurityWeek.

FTC orders communication company to disclose data breaches

20 November 2023
The FTC announced that prison communications provider Global Tel*Link Corp will now be required to disclose any future data breaches within 30 days.

Johnson Controls Patches Critical Vulnerability in Industrial Refrigeration Products

20 November 2023
Johnson Controls has patched a critical vulnerability that can be exploited to take complete control of Frick industrial refrigeration products.  The post Johnson Controls Patches Critical Vulnerability in Industrial Refrigeration Products appeared first on SecurityWeek.

Scattered Spider Joins Hands with BlackCat Ransomware for Extortion: Warns FBI

20 November 2023
The CISA and FBI have issued a joint advisory warning about the evolving tactics of the cybercriminal group Scattered Spider, which recently incorporated BlackCat ransomware into its extortion strategy. After encrypting the servers, attackers would communicate with victims via TOR, Tox, email, or encrypted applications. To reduce the likelihood and impact of cyberattacks by Scattered Spider, federal agencies have advised organizations to follow the best cybersecurity practices. 

LummaC2 Malware Deploys New Trigonometry-Based Anti-Sandbox Technique

20 November 2023
The malware delays its activation until it detects human mouse activity, making it difficult for analysis systems to detect. It utilizes cursor positions to calculate angles and determine if human behavior is present.

5 Steps to Assessing Risk Profiles of Third-Party SSE Platforms

20 November 2023
It's crucial to thoroughly assess the risk profiles of various SSE platforms and weigh their suitability against their organization's risk tolerance before adopting SSE. The post 5 Steps to Assessing Risk Profiles of Third-Party SSE Platforms appeared first on SecurityWeek.