Latest Cybersecurity News and Articles


Black Friday bargain hunters warned of enhanced online scams after millions lost last year

08 November 2023
Latest Cyber Aware campaign aims to help shoppers protect themselves online in the run up to the festive period.

Japan Aviation Electronics Says Servers Accessed During Cyberattack

08 November 2023
On Monday evening, the maker of electronics and aerospace products replaced its website with a static message indicating some of its servers were accessed by hackers last Thursday.

Offense Intended: How Adversarial Emulation Went From State Secret To Board Bullet Point

08 November 2023
Offensive Security does not focus on discreet attacks, singular actors, or Indicators of compromise, but understands the entirety of both sides of the battlefield. The post Offense Intended: How Adversarial Emulation Went From State Secret To Board Bullet Point appeared first on SecurityWeek.

90% of cybersecurity professionals work on vacation

08 November 2023
Work-life balance compromises continue to be a challenge as a new report shows  a majority of cybersecurity professionals check email, Slack and other forms of work communication even when on vacation.

Hacker Leaks 35 Million Scraped LinkedIn User Records

08 November 2023
The contents of the leaked database on BreachForums, as observed by Hackread.com, include publicly available information from LinkedIn profiles, containing full names and profile bios.

Researchers Uncover Undetectable Crypto Mining Technique on Azure Automation

08 November 2023
Cybersecurity researchers have developed what's the first fully undetectable cloud-based cryptocurrency miner leveraging the Microsoft Azure Automation service without racking up any charges. Cybersecurity company SafeBreach said it discovered three different methods to run the miner, including one that can be executed on a victim's environment without attracting any attention. "While this

WhatsApp Introduces New Privacy Feature to Protect IP Address in Calls

08 November 2023
Meta-owned WhatsApp is officially rolling out a new privacy feature in its messaging service called "Protect IP Address in Calls" that masks users' IP addresses to other parties by relaying the calls through its servers. "Calls are end-to-end encrypted, so even if a call is relayed through WhatsApp servers, WhatsApp cannot listen to your calls," the company said in a statement shared with The

Report: Business see rise in cyber insurance costs and requirements

08 November 2023
A new report reveals that more than 40% of businesses have reported an increased requirement from insurers for cybersecurity tools.

Sumo Logic Urges Users to Change Credentials Due to Security Breach

08 November 2023
Cloud monitoring and SIEM firm Sumo Logic is urging users to rotate credentials following the discovery of a security breach. The post Sumo Logic Urges Users to Change Credentials Due to Security Breach appeared first on SecurityWeek.

Beware, Developers: BlazeStealer Malware Discovered in Python Packages on PyPI

08 November 2023
A new set of malicious Python packages has slithered their way to the Python Package Index (PyPI) repository with the ultimate aim of stealing sensitive information from compromised developer systems. The packages masquerade as seemingly innocuous obfuscation tools, but harbor a piece of malware called BlazeStealer, Checkmarx said in a report shared with The Hacker News. "[BlazeStealer]

Experts Expose Farnetwork's Ransomware-as-a-Service Business Model

08 November 2023
Farnetwork has been linked to the development and management of various ransomware strains, including JSWORM, Nefilim, Karma, Nemty, and their own program based on the Nokoyawa ransomware.

Shared IT Service Provider Says Ransomware Data Breach Affects 267,000 Patients

08 November 2023
The hackers responsible for the attack, known as the DAIXIN Team, have gradually leaked samples of the stolen patient data and expressed interest in selling it to data brokers.

FBI Highlights Emerging Initial Access Methods Used by Ransomware Groups 

08 November 2023
FBI warns that ransomware operators continue to abuse third-party vendors and services as an attack vector. The post FBI Highlights Emerging Initial Access Methods Used by Ransomware Groups  appeared first on SecurityWeek.

Data Breach at Singapore's Marina Bay Sands Affects 665,000 Customers

08 November 2023
According to a statement published by the resort, the incident occurred on October 19-20 and involved unauthorized third-party access to its non-casino customers’ loyalty program membership data.

Guide: How vCISOs, MSPs and MSSPs Can Keep their Customers Safe from Gen AI Risks

08 November 2023
Download the free guide, "It's a Generative AI World: How vCISOs, MSPs and MSSPs Can Keep their Customers Safe from Gen AI Risks." ChatGPT now boasts anywhere from 1.5 to 2 billion visits per month. Countless sales, marketing, HR, IT executive, technical support, operations, finance and other functions are feeding data prompts and queries into generative AI engines. They use these tools to write

Marina Bay Sands Discloses Data Breach Impacting 665k Customers

08 November 2023
Singapore’s Marina Bay Sands luxury resort has disclosed a data breach impacting the information of 665,000 customers.  The post Marina Bay Sands Discloses Data Breach Impacting 665k Customers appeared first on SecurityWeek.

Outdated Cryptographic Protocols Put Vast Amounts of Network Traffic at Risk

08 November 2023
A recent study by Quantum Xchange reveals that a large percentage of network traffic has encryption flaws due to the use of older protocols like TLS 1.0 and SSL v3 and is unencrypted, posing a significant risk to businesses.

Kubescape 3.0 Elevates Open-Source Kubernetes Security

08 November 2023
The platform provides comprehensive visibility into the security posture of all images in a cluster, prioritizing remediation efforts and highlighting high-risk workloads.

Visa Launches Cybersecurity Training Program

08 November 2023
Visa has launched a payments learning program to address the shortage of skilled cybersecurity professionals and create a diverse talent pipeline in response to the White House's call for more pathways in cybersecurity.

Dropper Service Bypassing Android Security Restrictions to Install Malware

08 November 2023
ThreatFabric warns of a dropper service bypassing recent Android security restrictions to install spyware and banking trojans. The post Dropper Service Bypassing Android Security Restrictions to Install Malware appeared first on SecurityWeek.