Latest Cybersecurity News and Articles


When Email Security Meets SaaS Security: Uncovering Risky Auto-Forwarding Rules

09 November 2023
While intended for convenience and efficient communication, email auto-forwarding rules can inadvertently lead to the unauthorized dissemination of sensitive information to external entities, putting confidential data at risk of exposure to unauthorized parties. Wing Security (Wing), a SaaS security company, announced yesterday that their SaaS shadow IT discovery methods now include a solution

MuddyC2Go: New C2 Framework Iranian Hackers Using Against Israel

09 November 2023
Iranian nation-state actors have been observed using a previously undocumented command-and-control (C2) framework called MuddyC2Go as part of attacks targeting Israel. "The framework's web component is written in the Go programming language," Deep Instinct security researcher Simon Kenin said in a technical report published Wednesday. The tool has been attributed to MuddyWater, an Iranian 

Council for Scottish Islands Faces IT Outage After ‘Incident’

09 November 2023
Organizations must urgently apply the patch for the Citrix vulnerability, CitrixBleed, and actively hunt for any malicious activity to prevent session hijacking and data breaches.

CISA Says SLP Vulnerability Allowing Amplified DoS Attacks Exploited in the Wild

09 November 2023
CISA says an SLP vulnerability allowing for a DoS amplification factor of 2,000 is being exploited in attacks. The post CISA Says SLP Vulnerability Allowing Amplified DoS Attacks Exploited in the Wild appeared first on SecurityWeek.

SysAid Zero-Day Vulnerability Exploited by Ransomware Group

09 November 2023
CVE-2023-47246 zero-day vulnerability in SysAid IT service management software has been exploited by Cl0p ransomware affiliates. The post SysAid Zero-Day Vulnerability Exploited by Ransomware Group appeared first on SecurityWeek.

US Urges Critical Infrastructure Firms to Get “Shields Ready”

09 November 2023
The US government has launched a new campaign designed to encourage CNI stakeholders to enhance cyber-resilience in their organizations. The “Shields Ready” initiative is intended to complement the successful “Shields Up” campaign.

Researchers Uncover Undetectable Crypto Mining Technique on Azure Automation

09 November 2023
SafeBreach discovered three methods to run the miner, including exploiting a bug in the Azure pricing calculator, creating a dummy test-job, and leveraging Azure Automation's custom Python package upload feature.

Russian Hackers Used OT Attack to Disrupt Power in Ukraine Amid Mass Missile Strikes

09 November 2023
Mandiant says Russia's Sandworm hackers used a novel OT attack to cause power outages that coincided with mass missile strikes on critical infrastructure across Ukraine. The post Russian Hackers Used OT Attack to Disrupt Power in Ukraine Amid Mass Missile Strikes appeared first on SecurityWeek.

Russian Hackers Used Novel OT Attack to Disrupt Ukrainian Power Amid Mass Missile Strikes

09 November 2023
Mandiant says Russia's Sandworm hackers used a novel OT attack to cause power outages that coincided with mass missile strikes on critical infrastructure across Ukraine. The post Russian Hackers Used Novel OT Attack to Disrupt Ukrainian Power Amid Mass Missile Strikes appeared first on SecurityWeek.

CISA Alerts: High-Severity SLP Vulnerability Now Under Active Exploitation

09 November 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw in the Service Location Protocol (SLP) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Tracked as CVE-2023-29552 (CVSS score: 7.5), the issue relates to a denial-of-service (DoS) vulnerability that could be weaponized to launch massive DoS

New ObjCShellz Malware Spotted Targeting macOS Systems

09 November 2023
The North Korea-based BlueNoroff APT group has been linked with a new malware strain that is being used to target macOS systems. Dubbed ObjCShellz, the malware shares similarities with the RustBucket malware campaign, which came to light earlier this year.

Black Friday bargain hunters warned of enhanced online scams after millions lost last year

08 November 2023
Latest Cyber Aware campaign aims to help shoppers protect themselves online in the run up to the festive period.

Protecto Joins Cadre of Startups in AI Data Protection Space

08 November 2023
Silicon Valley startup is pitching APIs to help organizations protect data and ensure compliance throughout the AI deployment lifecycle. The post Protecto Joins Cadre of Startups in AI Data Protection Space appeared first on SecurityWeek.

Organizations spend almost 8 hours a week on security compliance

08 November 2023
Security compliance was analyzed in a recent report by Vanta. According to the report, 67% say they need to improve security and compliance measures.

Sumo Logic Urges Users to Change Credentials Due to Security Breach

08 November 2023
The company revealed on Tuesday that a “potential security incident” discovered on November 3 involved unauthorized access to a Sumo Logic AWS account through the use of compromised credentials.

Royal Mail Jeopardizes Users With Open Redirect Flaw

08 November 2023
“The vulnerability can be exploited by attackers to trick users into visiting malicious websites or phishing pages by disguising the malicious URL as a legitimate one,” Cybernews researchers explained.

GitHub Enhances Security Capabilities With AI

08 November 2023
GitHub adds AI-powered security features to help developers identify and address code vulnerabilities faster. The post GitHub Enhances Security Capabilities With AI appeared first on SecurityWeek.

BlazeStealer Malware Discovered in Python Packages on PyPI Targets Developers

08 November 2023
The malware runs a Discord bot and enables the threat actor to harvest a wide range of information, including passwords from web browsers and screenshots, execute arbitrary commands, encrypt files, and deactivate Microsoft Defender on the host.

DHS Launches New Critical Infrastructure Security and Resilience Campaign

08 November 2023
DHS launches Shields Ready, a new campaign promoting security and resilience for critical infrastructure organizations. The post DHS Launches New Critical Infrastructure Security and Resilience Campaign appeared first on SecurityWeek.

Chinese APTs Targeting Cambodian Government

08 November 2023
By monitoring telemetry associated with two prominent Chinese APT groups, researchers observed network connections predominately originating from Cambodia, including inbound connections originating from at least 24 Cambodian government organizations.