Latest Cybersecurity News and Articles


CitrixBleed Vulnerability Exploitation Suspected in Toyota Ransomware Attack

17 November 2023
Toyota Financial Services has been hit by a ransomware attack that may have involved exploitation of the CitrixBleed vulnerability.  The post CitrixBleed Vulnerability Exploitation Suspected in Toyota Ransomware Attack appeared first on SecurityWeek.

CISA Adds Three Security Flaws with Active Exploitation to KEV Catalog

17 November 2023
These vulnerabilities include a Microsoft Windows security feature bypass, a command injection vulnerability in Sophos Web Appliance, and an unspecified vulnerability in Oracle Fusion Middleware.

New SpyAgent Campaign Infects Smartphone Users in South Korea

17 November 2023
A new SpyAgent campaign targeting smartphone users in South Korea has infected over 200 devices since early October. The malware is distributed through phishing sites, utilizing malicious Android and iOS apps, with attackers initiating contact via SMS, persuading victims to switch to LINE messenger for further communication.

27 Malicious PyPI Packages with Thousands of Downloads Found Targeting IT Experts

17 November 2023
An unknown threat actor has been observed publishing typosquat packages to the Python Package Index (PyPI) repository for nearly six months with an aim to deliver malware capable of gaining persistence, stealing sensitive data, and accessing cryptocurrency wallets for financial gain. The 27 packages, which masqueraded as popular legitimate Python libraries, attracted thousands of downloads,

Ukrainian and Czech Police Bust $9 Million Bank Fraud Gang

17 November 2023
The gang operated from call centers in Ukraine and targeted victims primarily in the Czech Republic. They employed a technique called "vishing" to deceive victims into revealing sensitive information.

Zero-Day Flaw in Zimbra Email Software Exploited by Four Hacker Groups

17 November 2023
The vulnerability (CVE-2023-37580) allowed for the execution of malicious scripts by tricking users into clicking on specially crafted URLs, reflecting the attack back to the user.

Fortinet Warns of Critical Command Injection Bug in FortiSIEM

17 November 2023
The command injection vulnerability, identified as CVE-2023-36553, is a variant of a previously fixed security issue and can lead to unauthorized data access, modification, or deletion.

U.S. Cybersecurity Agencies Warn of Scattered Spider's Gen Z Cybercrime Ecosystem

17 November 2023
U.S. cybersecurity and intelligence agencies have released a joint advisory about a cybercriminal group known as Scattered Spider that's known to employ sophisticated phishing tactics to infiltrate targets. "Scattered Spider threat actors typically engage in data theft for extortion using multiple social engineering techniques and have recently leveraged BlackCat/ALPHV ransomware alongside their

CISA Adds Three Security Flaws with Active Exploitation to KEV Catalog

17 November 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation in the wild. The vulnerabilities are as follows - CVE-2023-36584 (CVSS score: 5.4) - Microsoft Windows Mark-of-the-Web (MotW) Security Feature Bypass Vulnerability CVE-2023-1671 (CVSS score: 9.8) -

Alleged Extortioner of Psychotherapy Patients Faces Trial

16 November 2023
Prosecutors in Finland this week commenced their criminal trial against Julius Kivimäki, a 26-year-old Finnish man charged with extorting a once popular and now-bankrupt online psychotherapy practice and thousands of its patients. In a 2,200-page report, Finnish authorities laid out how they connected the extortion spree to Kivimäki, a notorious hacker who was convicted in 2015 of perpetrating tens of thousands of cybercrimes, including data breaches, payment fraud, operating a botnet and calling in bomb threats.

Hundreds of Websites Cloned to Run Ads for Chinese Gambling

16 November 2023
The motive behind these cloned sites is likely to generate traffic for gambling operators, as they can serve third-party ads that publishers may be reluctant to carry on their own sites.

Citrix Hypervisor Gets Hotfix for New Reptar Intel CPU Flaw

16 November 2023
One of the vulnerabilities, known as "Reptar," affects Intel CPUs and could lead to system instability or privilege escalation. The other vulnerability, CVE-2023-46835, could allow malicious code in a guest VM to compromise an AMD-based host.

Google Adds Passkey Support to New Titan Security Key 

16 November 2023
Google launches new Titan security key with passkey support, allowing users to store up to 250 unique passkeys. The post Google Adds Passkey Support to New Titan Security Key  appeared first on SecurityWeek.

21 Vulnerabilities Discovered in Crucial IT-OT Connective Routers

16 November 2023
These vulnerabilities, including critical and high-severity bugs, can enable attackers to compromise networks, deploy malware, and disrupt services, highlighting the need for improved security measures in OT and IoT devices.

Report: 46% of SMBs have experienced a ransomware attack

16 November 2023
According to a new report, 46% of small-to-medium sized businesses have experienced a ransomware attack.

Biden Campaign Looking for CISO

16 November 2023
The Biden for President campaign is looking for a cybersecurity chief to “define the organization's risk appetite” and manage its cybersecurity and IT initiatives. The post Biden Campaign Looking for CISO appeared first on SecurityWeek.

Fraudsters Make $50,000 a Day by Spoofing Crypto Researchers

16 November 2023
Scammers are exploiting the trust placed in reputable accounts by creating fake accounts with similar names and spreading fabricated security breach claims to deceive users into clicking on malicious links and revealing their wallet information.

Zero-Day Flaw in Zimbra Email Software Exploited by Four Hacker Groups

16 November 2023
A zero-day flaw in the Zimbra Collaboration email software was exploited by four different groups in real-world attacks to pilfer email data, user credentials, and authentication tokens. "Most of this activity occurred after the initial fix became public on GitHub," Google Threat Analysis Group (TAG) said in a report shared with The Hacker News. The flaw, tracked as CVE-2023-37580 (CVSS score:

Zimbra Zero-Day Exploited to Hack Government Emails

16 November 2023
Google says a Zimbra zero-day from earlier this year, CVE-2023-37580, was exploited in several campaigns to hack government emails. The post Zimbra Zero-Day Exploited to Hack Government Emails appeared first on SecurityWeek.

State-Sponsored Online Spies Likely to Target Australian Submarine Program, Spy Agency Says

16 November 2023
Australia’s cooperation with the U.S. and Britain to develop an Australian fleet of submarines powered by U.S. nuclear technology is a likely target of state-sponsored cyberespionage, the nation’s digital spy agency said. The post State-Sponsored Online Spies Likely to Target Australian Submarine Program, Spy Agency Says appeared first on SecurityWeek.