Latest Cybersecurity News and Articles


1.3 Million Maine Residents Impacted by MOVEit Hack

10 November 2023
The State of Maine says the personal information of 1.3 million individuals was compromised in the MOVEit attack. The post 1.3 Million Maine Residents Impacted by MOVEit Hack appeared first on SecurityWeek.

Kyocera AVX Says Ransomware Attack Impacted 39,000 Individuals

10 November 2023
The LockBit ransomware gang claimed responsibility for the breach and leaked stolen data, including passport scans and financial documents, potentially exposing proprietary designs and patented information.

Ransomware Attack on China’s Biggest Bank Disrupts Treasury Market Trades, Reports Say

10 November 2023
A ransomware attack on China’s biggest bank, the Industrial and Commercial Bank of China Financial Services, disrupts Treasury market trades. The post Ransomware Attack on China’s Biggest Bank Disrupts Treasury Market Trades, Reports Say appeared first on SecurityWeek.

SentinelOne to Acquire Cybersecurity Consulting Firm Krebs Stamos Group

10 November 2023
Cybersecurity company SentinelOne is acquiring advisory firm Krebs Stamos Group to create a new entity called PinnacleOne Strategic Advisory Group, with Christopher Krebs and Alex Stamos taking on key positions.

NATO Allies Express Support for Collective Response to Cyberattacks

10 November 2023
Germany's National Security Strategy envisions the establishment of a dedicated entity for offensive cyber operations, although it rejects the use of hack-backs as a means of cyber defense.

Threat Actors Leverage File-Sharing Service and Reverse Proxies for Credential Harvesting

10 November 2023
The use of a reverse proxy in this phishing campaign allows the attackers to bypass multi-factor authentication (MFA) and gain access to victims' Microsoft 365 accounts, leading to further distribution of phishing emails.

MGM Resorts Anticipates No Further Disruptions From September Cyberattack

10 November 2023
MGM Resorts is investing $40 million in IT upgrades next year and is facing multiple class-action lawsuits and potential financial losses from legal proceedings related to the attack.

Predator AI ChatGPT Integration Poses Risk to Cloud Services

10 November 2023
The hacking tool is distributed through Telegram channels linked to hacking communities and focuses on facilitating web application attacks on commonly used technologies.

WhatsApp Introduces New Privacy Feature to Protect IP Address in Calls

10 November 2023
The privacy feature builds upon previous measures such as "Silence Unknown Callers" to protect users from unwanted contact and minimize the risk of zero-click attacks and spyware.

Ransomed.vc Gang Claims to Shut Down After Six Affiliates Allegedly Arrested

10 November 2023
The group initially threatened victims with European data breach fines but later offered to sell the entire operation, including domain names, breached company access, and databases.

GitHub Enhances Security Capabilities With AI

10 November 2023
GitHub is leveraging AI to enhance its secret scanning program, allowing code maintainers to create custom patterns for detecting organization-specific secrets and improving scanning accuracy.

The New 80/20 Rule for SecOps: Customize Where it Matters, Automate the Rest

10 November 2023
There is a seemingly never-ending quest to find the right security tools that offer the right capabilities for your organization. SOC teams tend to spend about a third of their day on events that don’t pose any threat to their organization, and this has accelerated the adoption of automated solutions to take the place of (or augment) inefficient and cumbersome SIEMs. With an estimated 80% of

Alert: 'Effluence' Backdoor Persists Despite Patching Atlassian Confluence Servers

10 November 2023
Cybersecurity researchers have discovered a stealthy backdoor named Effluence that's deployed following the successful exploitation of a recently disclosed security flaw in Atlassian Confluence Data Center and Server. "The malware acts as a persistent backdoor and is not remediated by applying patches to Confluence," Aon's Stroz Friedberg Incident Response Services said in an analysis published

UK Shoppers Lost Over $13 Million to Fraud Last Festive Season

10 November 2023
While AI tools make fraud campaigns more convincing, users can still protect themselves by being cautious of phishing emails, recognizing warning signs, and following online shopping guidance provided by the NCSC.

Risk Ledger Raises $7.65 Million for Supply Chain Security Solution

10 November 2023
The London-based company offers a collaborative platform that helps organizations identify and mitigate supply chain security risks in real time. The funding will be used to advance product development and deepen partnerships in key industries.

NY AG Hits Radiology Group With $450K Fine in SonicWall Hack

10 November 2023
The breach was a result of the group failing to apply a firmware patch to fix a zero-day vulnerability in their SonicWall firewall, highlighting the importance of promptly updating and securing computer hardware and systems.

FBI Highlights Emerging Initial Access Methods Used by Ransomware Groups

10 November 2023
Organizations should implement security measures such as regular backups, vendor security reviews, strong user account security, and network monitoring to mitigate the risk of ransomware attacks.

Iran-Linked Imperial Kitten Cyber Group Targeting Middle East's Tech Sectors

10 November 2023
A group with links to Iran targeted transportation, logistics, and technology sectors in the Middle East, including Israel, in October 2023 amid a surge in Iranian cyber activity since the onset of the Israel-Hamas war. The attacks have been attributed by CrowdStrike to a threat actor it tracks under the name Imperial Kitten, and which is also known as Crimson Sandstorm (previously Curium),

Russian State-Owned Sberbank Hit by 1 Million RPS DDoS Attack

10 November 2023
The attack generated one million requests per second (RPS), four times larger than any previous attack on the bank. Sberbank believes that new, highly skilled hackers are targeting major Russian resources.

Stealthy Kamran Spyware Targeting Urdu-speaking Users in Gilgit-Baltistan

10 November 2023
Urdu-speaking readers of a regional news website that caters to the Gilgit-Baltistan region have likely emerged as a target of a watering hole attack designed to deliver a previously undocumented Android spyware dubbed Kamran. The campaign, ESET has discovered, leverages Hunza News (urdu.hunzanews[.]net), which, when opened on a mobile device, prompts visitors of the Urdu version to install its