Latest Cybersecurity News and Articles


Toyota Recovering From Cyberattack on its Financial Services Division

17 November 2023
The company has taken certain systems offline to investigate the unauthorized activity and reduce risk. Toyota is working with law enforcement and gradually bringing systems back online.

Over a Dozen Exploitable Vulnerabilities Found in AI/ML Tools

17 November 2023
Bug hunters uncover over a dozen exploitable vulnerabilities in tools used to build chatbots and other types of AI/ML models. The post Over a Dozen Exploitable Vulnerabilities Found in AI/ML Tools appeared first on SecurityWeek.

40% of organizations have a clear understanding of their AI use

17 November 2023
According to a recent cybersecurity predictions report, the top 2024 risk cited by internal audit leaders is cyber and data security (80%).

Half of Ransomware Groups Operating in 2023 Are New

17 November 2023
Leaked source codes from established ransomware groups like Conti, Lockbit, and Babuk have been utilized by other cybercriminals, leading to the cross-pollination of tactics and tools.

Bots and fraud make up 73% of website and app traffic

17 November 2023
A recent cyber threat report found that bots and human fraud farms were responsible for billions of attacks in the first half of 2023 and into Q3.

FBI and CISA Warn of Social Engineering Attacks From Scattered Spider Group

17 November 2023
The Scattered Spider cybercriminal group targets commercial facilities sectors and subsectors, engaging in data theft for extortion using social engineering techniques and BlackCat/ALPHV ransomware.

Beware: Malicious Google Ads Trick WinSCP Users into Installing Malware

17 November 2023
Threat actors are leveraging manipulated search results and bogus Google ads that trick users who are looking to download legitimate software such as WinSCP into installing malware instead. Cybersecurity company Securonix is tracking the ongoing activity under the name SEO#LURKER. “The malicious advertisement directs the user to a compromised WordPress website gameeweb[.]com, which redirects the

Google to Distribute 100,000 Titan Security Keys to High-Risk Users

17 November 2023
Google is distributing 100,000 free Titan Security Keys to high-risk individuals, including those involved in elections. Google plans to distribute these keys to governments worldwide by 2024.

Researchers Dive Into Activities of Indian Hack-for-Hire Firm Appin

17 November 2023
Researchers uncover the activities of Appin, a hack-for-hire Indian firm involved in espionage, surveillance, and disruptive attacks. The post Researchers Dive Into Activities of Indian Hack-for-Hire Firm Appin appeared first on SecurityWeek.

Roshan Navagamuwa hired as EVP and Chief Information Officer at AIG

17 November 2023
Roshan Navagamuwa has been hired as Executive Vice President (EVP) and Chief Information Officer (CIO) at American International Group (AIG). 

Long Beach is Latest California City Facing Cybersecurity Incident

17 November 2023
While it is unclear if it is a ransomware attack, the city has taken its systems offline and plans to keep them offline for several days while working on identifying the source and implementing additional security measures.

Key GOP Lawmaker Calls for Renewal of Surveillance Tool as He Proposes Changes to Protect Privacy

17 November 2023
The Republican chairman of the House Intelligence Committee has called for the renewal of a key US government surveillance tool as he proposed a series of changes aimed at safeguarding privacy. The post Key GOP Lawmaker Calls for Renewal of Surveillance Tool as He Proposes Changes to Protect Privacy appeared first on SecurityWeek.

Businesses that eliminate passwords report better security outcomes

17 November 2023
New research shows organizations using passwordless technologies experience the fewest phishing attacks, are more productive and achieve greater levels of employee satisfaction.

SonicWall Buys Solutions Granted to Offer MSPs More Services

17 November 2023
Solutions Granted will continue to support products from competing endpoint security vendors while working with SonicWall, emphasizing an open and inclusive approach in the industry.

FCC Enforces Stronger Rules to Protect Customers Against SIM Swapping Attacks

17 November 2023
The U.S. Federal Communications Commission (FCC) is adopting new rules that aim to protect consumers from cell phone account scams that make it possible for malicious actors to orchestrate SIM-swapping attacks and port-out fraud. “The rules will help protect consumers from scammers who target data and personal information by covertly swapping SIM cards to a new device or porting phone numbers to

Vietnam Post Exposes 1.2 Terabytes of Data, Including Email Addresses

17 November 2023
The exposed data included device usernames with employee names or emails, allowing potential attackers to identify employees and their activities, posing a significant threat to the organization's security.

CISA Warns of Attacks Exploiting Sophos Web Appliance Vulnerability

17 November 2023
CISA adds Sophos, Oracle and Microsoft product security holes to its Known Exploited Vulnerabilities (KEV) catalog. The post CISA Warns of Attacks Exploiting Sophos Web Appliance Vulnerability appeared first on SecurityWeek.

Israeli Man Who Made $5M From Hacking Scheme Sentenced to Prison in US

17 November 2023
Aviram Azari, an Israeli man who made nearly $5 million from a hacking scheme, has been sentenced to 80 months in prison in the US. The post Israeli Man Who Made $5M From Hacking Scheme Sentenced to Prison in US appeared first on SecurityWeek.

Update: MeridianLink Confirms Cyberattack After Ransomware Gang Claims to Report Company to SEC

17 November 2023
The ransomware gang behind the attack, AlphV/Black Cat, took extraordinary measures by pressuring MeridianLink to pay a ransom and even claimed to have reported the incident to the SEC.

Discover 2023's Cloud Security Strategies in Our Upcoming Webinar - Secure Your Spot

17 November 2023
In 2023, the cloud isn't just a technology—it's a battleground. Zenbleed, Kubernetes attacks, and sophisticated APTs are just the tip of the iceberg in the cloud security warzone. In collaboration with the esteemed experts from Lacework Labs, The Hacker News proudly presents an exclusive webinar: 'Navigating the Cloud Attack Landscape: 2023 Trends, Techniques, and Tactics.' Join us for an