Latest Cybersecurity News and Articles


Ransomware reported as a top concern for 64% of consumers

14 November 2023
According to a recent ThreatX report, 97% of consumers are concerned that cyberattacks will continue to grow in volume over the next year.

Researchers Uncover Info-Stealing Campaign Targeting Gaming Community

14 November 2023
A targeted campaign against the gaming community exploits Discord channels and fake download sites to distribute types of information-stealing malware. Multiple information stealer families, including BBy Stealer, Nova Sentinel, Doenerium, and Epsilon Stealer, were identified. To counter similar threats, online gamers are urged to download software exclusively from official and trustworthy websites.

Microsoft Warns of Critical Bugs Being Exploited in the Wild

14 November 2023
Patch Tuesday: Redmond’s security response team flags two vulnerabilities -- CVE-2023-36033 and CVE-2023-36036 -- already being exploited in the wild. The post Microsoft Warns of Critical Bugs Being Exploited in the Wild appeared first on SecurityWeek.

CacheWarp Attack: New Vulnerability in AMD SEV Exposes Encrypted VMs

14 November 2023
A group of academics has disclosed a new "software fault attack" on AMD's Secure Encrypted Virtualization (SEV) technology that could be potentially exploited by threat actors to infiltrate encrypted virtual machines (VMs) and even perform privilege escalation. The attack has been codenamed CacheWarp (CVE-2023-20592) by researchers from the CISPA Helmholtz Center for Information Security. It

Royal Ransomware Rebrands as BlackSuit - Warn FBI and CISA

14 November 2023
The Royal ransomware gang, now known as BlackSuit, has undergone a strategic rebranding, unveiled in a joint advisory by CISA and the FBI. This shift, observed since November 2022, involves advanced encryption methods and sophisticated attack vectors, emphasizing the exploitation of vulnerabilities in public-facing applications and remote desktop protocols.

61% of organizations store sensitive data in multiple locations

14 November 2023
According to a recent zero trust and data protection report, one of six organizations experienced multiple losses of data in the past 12 months.

Adobe Patch Tuesday: Critical Bugs in Acrobat, Reader, ColdFusion

14 November 2023
Adobe patches 72 security bugs and calls special attention to code-execution defects in the widely deployed Acrobat and Reader software. The post Adobe Patch Tuesday: Critical Bugs in Acrobat, Reader, ColdFusion appeared first on SecurityWeek.

Protected Virtual Machines Exposed to New ‘CacheWarp’ AMD CPU Attack

14 November 2023
CacheWarp is a new attack method affecting a security feature present in AMD processors that can pose a risk to virtual machines. The post Protected Virtual Machines Exposed to New ‘CacheWarp’ AMD CPU Attack appeared first on SecurityWeek.

Zip Raises $7.7 Million to Expand SMB Cybersecurity Business

14 November 2023
New York City and Washington DC-based startup Zip Security raised $7.7 million seed financing led by General Catalyst, co-led by Human Capital, and with participation from Box Group. The post Zip Raises $7.7 Million to Expand SMB Cybersecurity Business appeared first on SecurityWeek.

UK Cybersecurity Center Says ‘Deepfakes’ and Other AI Tools Pose a Threat to the Next Election

14 November 2023
Britain’s cybersecurity agency said that artificial intelligence poses a threat to the country’s next election, and cyberattacks by hostile countries and their proxies are getting harder to track. The post UK Cybersecurity Center Says ‘Deepfakes’ and Other AI Tools Pose a Threat to the Next Election appeared first on SecurityWeek.

75% of security leaders say security automation is important

14 November 2023
According to a recent ThreatQuotient survey, 75% of security professionals say cybersecurity automation is important, up from 68% last year.

TA402 Uses Complex IronWind Infection Chains to Target Middle East-Based Government Entities

14 November 2023
TA402 has recently employed a new initial access downloader called IronWind, using various infection chains and delivery methods such as Dropbox links, XLL and RAR file attachments, in order to evade detection.

Vietnamese Hackers Using New Delphi-Powered Malware to Target Indian Marketers

14 November 2023
The attackers utilize deceptive tactics, such as sending archive files disguised as PDFs, to trick victims into launching malicious executables and gain unauthorized access to their accounts.

Canadian Banking Tech Giant Moneris Says It Prevented Ransomware Attack

14 November 2023
The Medusa ransomware gang demanded a $6 million ransom, but Moneris stated that its security team stopped access to critical data and no ransom request was made. The company didn't disclose when the breach was attempted or whether it paid a ransom.

MySQL Servers, Docker Hosts Infected With DDoS Malware

14 November 2023
Researchers warn attackers are targeting MySQL servers and Docker hosts to plant malware capable of launching distributed DDoS attacks. The post MySQL Servers, Docker Hosts Infected With DDoS Malware appeared first on SecurityWeek.

Royal Ransomware Possibly Rebranding After Targeting 350 Organizations Worldwide

14 November 2023
CISA says Royal ransomware has targeted 350 organizations to date, demanding over $275 million in ransoms. The post Royal Ransomware Possibly Rebranding After Targeting 350 Organizations Worldwide appeared first on SecurityWeek.

Denmark Hit With Largest Cyberattack on Record by Exploiting Firewall Vulnerabilities

14 November 2023
Hackers linked to the Russian GRU targeted Danish critical infrastructure, exploiting vulnerabilities in Zyxel firewalls and demonstrating meticulous planning and coordination.

Radiant Snags $15 Million for AI-Powered SOC Technology

14 November 2023
Radiant Security gets $15 million in new financing as investors double down on early stage companies experimenting with AI technology. The post Radiant Snags $15 Million for AI-Powered SOC Technology appeared first on SecurityWeek.

ICS Patch Tuesday: 90 Vulnerabilities Addressed by Siemens and Schneider Electric

14 November 2023
Siemens and Schneider Electric’s Patch Tuesday advisories for November 2023 address 90 vulnerabilities affecting their products.  The post ICS Patch Tuesday: 90 Vulnerabilities Addressed by Siemens and Schneider Electric appeared first on SecurityWeek.

DP World Cyberattack Blocks Thousands of Containers in Australian Ports

14 November 2023
DP World is working to restore normal operations and investigate the possibility of data access and theft, engaging with cybersecurity experts and the Office of the Australian Information Commissioner.