Latest Cybersecurity News and Articles


New Russian Hacking Group Pretends to be a Pentesting Training Organization

15 November 2023
AlphaLock's business model represents a new and sophisticated approach to cybercrime, creating a pipeline of trained hackers and monetizing their services through an affiliate program.

Q3 2023 sees a rise in botnet activity

15 November 2023
According to a Nuspire threat report, there was a surge in botnet activity in Q3 2023, including an increase in activity of nearly 93% over Q2.

Cyble Raises $6.2M; Expands Series B to $30.2M

15 November 2023
The round, which brought the total amount to $30.2M, was led by Summit Peak Ventures (US) and King River Capital (US), with participation from Care Super (Australia) and BlackBird Ventures (Australasia), along with other investors.

Data Security Firm ALTR Banks $25M Series C 

15 November 2023
Florida late-state startup ALTR gets another cash infusion to expand markets for data security technologies. The post Data Security Firm ALTR Banks $25M Series C  appeared first on SecurityWeek.

Application Security Startup Aikido Security Raises €5 Million

15 November 2023
Aikido Security has raised €5 million (~$5.4 million) in seed funding for an all-in-one application security platform. The post Application Security Startup Aikido Security Raises €5 Million appeared first on SecurityWeek.

Cyber Espionage Operation on Embassies Linked to Russia’s Cozy Bear Hackers

15 November 2023
The Cozy Bear APT utilized a legitimate tool called Ngrok to obfuscate their activities and communicate with compromised systems, making detection and attribution more challenging.

Microsoft Patches Sensitive Information Disclosure Vulnerability in Azure CLI

15 November 2023
Microsoft provided guidance on an Azure CLI bug leading to the exposure of sensitive information through GitHub Actions logs. The post Microsoft Patches Sensitive Information Disclosure Vulnerability in Azure CLI appeared first on SecurityWeek.

Rackspace Records $5M in Expenses Related to 2022 Ransomware Attack

15 November 2023
The attack disrupted email access for customers, leading to the discontinuation of the Hosted Exchange product. Rackspace expects to receive $5.4 million in insurance reimbursement, but the timing may differ from expense recognition.

Security of AMD's Trusted Execution Environment Undone by Cache Meddling

15 November 2023
Researchers have discovered a vulnerability named CacheWarp in AMD's SEV trusted execution environment, which can lead to arbitrary code execution, exposure of sensitive data, or privilege escalation within a guest VM.

6 steps for protecting small businesses from cyberattacks

15 November 2023
The increased shopping during the holiday season often leads to increased cyberattacks affecting both the organization and their consumers. 

New PoC Exploit for Apache ActiveMQ Flaw Could Let Attackers Fly Under the Radar

15 November 2023
Cybersecurity researchers have demonstrated a new technique that exploits a critical security flaw in Apache ActiveMQ to achieve arbitrary code execution in memory. Tracked as CVE-2023-46604 (CVSS score: 10.0), the vulnerability is a remote code execution bug that could permit a threat actor to run arbitrary shell commands. It was patched by Apache in ActiveMQ versions 5.15.16, 5.16.7, 5.17.6,

CISA Outlines AI-Related Cybersecurity Efforts

15 November 2023
CISA details its efforts to promote the use of AI in cybersecurity and guide critical infrastructure in adopting AI. The post CISA Outlines AI-Related Cybersecurity Efforts appeared first on SecurityWeek.

Info Stealers Thrive in Hot Market for Stolen Data

15 November 2023
Browser data, especially website credentials, remains the most frequently stolen information by info stealers, followed by cryptocurrency wallet credentials and chat app credentials.

Millions of Cryptocurrency Wallets Found Affected by Randstorm Flaw

15 November 2023
Millions of browser-based cryptocurrency wallets face a potential $1 billion theft risk due to the Randstorm vulnerability in Bitcoin JS 0.13, affecting wallets created between 2011 and 2015. Notable affected vendors include Blockchain.com, Bitgo, and BitPay, prompting recommendations for users to transition to new wallets and vendors to conduct audits for enhanced security.

Cryptocurrency Wallets Might be Vulnerable to ‘Randstorm’ Flaw in Bitcoin JavaScript Library

15 November 2023
The vulnerability, known as "Randstorm," is a result of programming mistakes and weaknesses in random number generation in the BitcoinJS library, making Bitcoin private keys more vulnerable to attacks.

US Announces IPStorm Botnet Takedown and Its Creator’s Guilty Plea

15 November 2023
US government announces the takedown of the IPStorm proxy service botnet and the guilty plea of its creator, a Russian/Moldovan national. The post US Announces IPStorm Botnet Takedown and Its Creator’s Guilty Plea appeared first on SecurityWeek.

NCSC: UK Facing “Enduring and Significant” Cyber Threat

15 November 2023
The UK’s critical infrastructure (CNI) providers face a persistent and critical threat from emboldened state-backed and aligned actors, a leading UK cybersecurity agency has warned. The NCSC issued the warning in its Annual Review 2023.

Azerbaijan Agencies Sign Cyber-Partner Deals

15 November 2023
The agreement, which focuses on information security, was made between the State Service for Special Communication and Information Security of Azerbaijan and the Turkmenistan agency of Transport and Communications.

New Reptar CPU Flaw Impacts Intel Desktop and Server Systems

15 November 2023
Google researchers independently discovered the vulnerability and identified "very strange behavior" related to how redundant prefixes are interpreted by the CPU, leading to potential security bypasses.

SAP Patches Critical Vulnerability in Business One Product

15 November 2023
SAP released a hotfix for a critical-severity improper access control vulnerability in Business One product installation. The post SAP Patches Critical Vulnerability in Business One Product appeared first on SecurityWeek.