Latest Cybersecurity News and Articles


37% of organizations will increase cybersecurity spending

09 November 2023
Cloud adoption and cybersecurity spending for small and medium businesses (SMBs) was analyzed in a recent report by DigitalOcean Holdings.

Zero-Day Alert: Lace Tempest Exploits SysAid IT Support Software Vulnerability

09 November 2023
The threat actor known as Lace Tempest has been linked to the exploitation of a zero-day flaw in SysAid IT support software in limited attacks, according to new findings from Microsoft. Lace Tempest, which is known for distributing the Cl0p ransomware, has in the past leveraged zero-day flaws in MOVEit Transfer and PaperCut servers. The issue, tracked as CVE-2023-47246, concerns a path traversal

Medical Company Fined $450,000 by New York AG Over Data Breach

09 November 2023
A medical company has been fined $450,000 by the New York AG over a data breach that may have involved exploitation of a SonicWall vulnerability. The post Medical Company Fined $450,000 by New York AG Over Data Breach appeared first on SecurityWeek.

OpenAI Reveals ChatGPT is Being Targeted with DDoS Attacks

09 November 2023
The Russia-linked hacker group Anonymous Sudan claimed responsibility for the DDoS attacks, targeting OpenAI due to its support for Israel and alleged bias in ChatGPT against Palestine.

Tidal Cyber Raises $5 Million for Threat-Informed Defense Platform

09 November 2023
The Washington, DC startup is building a threat-informed defense platform that helps organizations automate detection and response work. The post Tidal Cyber Raises $5 Million for Threat-Informed Defense Platform appeared first on SecurityWeek.

New report shows 51% rise in QR code phishing for September

09 November 2023
As organizations increasingly use QR codes, it seems QR code phishing AKA "quishing" is also on the rise with a 51% increase in September.

Medical Transcription Hack Affects 1.2 Million Chicagoans

09 November 2023
The breach exposed sensitive patient data, including names, birthdates, addresses, medical information, and potentially Social Security numbers, emphasizing the risk of identity theft and healthcare fraud.

39% of software developers say supply chain security is essential

09 November 2023
A report found that 70% of developers and 52% of chief information security officers view software supply chain security as a top priority.

Threat Actors Impersonate Windows News Portal to Distribute RedLine Stealer

09 November 2023
A new malvertising campaign has been observed wherein threat actors are copying a legitimate Windows news portal to promote a malicious installer for the popular processor tool CPU-Z. Based on the infrastructure, domain names, and cloaking templates used, researchers believe the incident is part of a larger malvertising campaign targeting other utilities such as Notepad++, Citrix, and VNC Viewer.

New BlazeStealer Malware in PyPI Targets Developers

09 November 2023
A new set of malicious Python packages has been discovered on the Python Package Index (PyPI) repository. These packages masquerade as harmless obfuscation tools but contain a malware called BlazeStealer. The campaign started in January 2023 and includes eight packages. Developers must stay alert and thoroughly assess the reliability and safety of packages before incorporating them into their work.

‘BlazeStealer’ Malware Delivered to Python Developers Looking for Obfuscation Tools

09 November 2023
Checkmarx uncovers a malicious campaign targeting Python developers with malware that takes over their systems. The post ‘BlazeStealer’ Malware Delivered to Python Developers Looking for Obfuscation Tools appeared first on SecurityWeek.

Russian Sandworm APT Group Caused Power Outage in October 2022

09 November 2023
The attack was not driven by military necessity but rather aimed to increase the psychological toll of the war, showcasing Russia's focus on disrupting and degrading military readiness through cyber means.

Major ChatGPT Outage Caused by DDoS Attack

09 November 2023
ChatGPT and its API have experienced a major outage due to a DDoS attack apparently launched by Anonymous Sudan. The post Major ChatGPT Outage Caused by DDoS Attack appeared first on SecurityWeek.

New Malvertising Campaign Uses Fake Windows News Portal to Distribute Malicious Installers

09 November 2023
A new malvertising campaign has been found to employ fake sites that masquerade as legitimate Windows news portal to propagate a malicious installer for a popular system profiling tool called CPU-Z. "This incident is a part of a larger malvertising campaign that targets other utilities like Notepad++, Citrix, and VNC Viewer as seen in its infrastructure (domain names) and cloaking templates used

SysAid Zero-Day Vulnerability Exploited by Ransomware Group

09 November 2023
The vulnerability, tracked as CVE-2023-47246, allows for arbitrary code execution and has been exploited by a threat actor known as Lace Tempest, who is associated with the deployment of Cl0p ransomware.

Study shows data breaches decreased 84% in US during Q3

09 November 2023
The U.S. is still the first most breached country in Q3 2023 despite a decrease in breach count, according to a recent report.

CISA Alerts of High-Severity SLP Vulnerability Now Under Active Exploitation

09 November 2023
The vulnerability allows an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a DoS attack with a significant amplification factor, making it a serious threat to network and server security.

Iranian Hackers are Using New MuddyC2Go C2 Framework Against Israel

09 November 2023
MuddyC2Go allows the threat actors to automate the connection to their command-and-control server using an embedded PowerShell script, eliminating the need for manual execution.

Risk Ledger Raises £6.25 Million for Supply Chain Security Solution

09 November 2023
UK-based Risk Ledger has raised £6.25 million (~$7.65 million) in Series A funding to prevent supply chain attacks. The post Risk Ledger Raises £6.25 Million for Supply Chain Security Solution appeared first on SecurityWeek.

Japan Aviation Electronics Targeted in Ransomware Attack

09 November 2023
Japan Aviation Electronics confirms cyberattack as Alphv/BlackCat ransomware group publishes allegedly stolen data. The post Japan Aviation Electronics Targeted in Ransomware Attack appeared first on SecurityWeek.