Latest Cybersecurity News and Articles


Unmasking New AsyncRAT Infection Chain

03 November 2023
AsyncRAT is being distributed through a malicious HTML file and uses various file types like PowerShell, WSF, and VBScript to bypass detection. The infection chain begins with a spam email containing a malicious URL to download the HTML file.

Okta Hack Blamed on Employee Using Personal Google Account on Company Laptop

03 November 2023
Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop. The post Okta Hack Blamed on Employee Using Personal Google Account on Company Laptop appeared first on SecurityWeek.

New DarkGate Variant Uses a New Loading Approach

03 November 2023
DarkGate is a versatile malware that includes features such as keylogging, information stealing, and downloading and executing other payloads. The DarkGate malware has been involved in multiple campaigns and continues to evolve.

Mortgage Giant Mr. Cooper Shuts Down Systems Following Cyberattack

03 November 2023
Mr. Cooper suspends operations, including payments, after a cyberattack forced it to take systems offline. The post Mortgage Giant Mr. Cooper Shuts Down Systems Following Cyberattack appeared first on SecurityWeek.

In Other News: Airport Taxi Hacking, Post-Quantum Crypto Guidance, Stanford Breach

03 November 2023
Noteworthy stories that might have slipped under the radar: US airport taxi hacking by Russians, Stanford ransomware attack, and post-quantum crypto guidance.  The post In Other News: Airport Taxi Hacking, Post-Quantum Crypto Guidance, Stanford Breach appeared first on SecurityWeek.

Russian Reshipping Service ‘SWAT USA Drop’ Exposed

03 November 2023
The Russia-based criminal reshipping service SWAT USA Drop was hacked, exposing its operations and revealing the involvement of over 1,200 people in reshipping stolen goods purchased with stolen credit cards.

FusionAuth Snags $65 Million Investment for Customer Identity Tech

03 November 2023
The Denver-based customer authentication and authorization company FusionAuth has secured a $65 million investment in its first external funding round, led by Updata Partners.

North Korean Hackers Use New ‘KandyKorn’ macOS Malware in Attacks

03 November 2023
Security researchers uncover new macOS and Windows malware associated with the North Korea-linked Lazarus Group. The post North Korean Hackers Use New ‘KandyKorn’ macOS Malware in Attacks appeared first on SecurityWeek.

Blackcat Ransomware Gang Claims Breach of Healthcare Giant Henry Schein

03 November 2023
Healthcare giant Henry Schein has been targeted by the BlackCat ransomware gang, who claim to have breached the company's network and stolen 35 terabytes of data, including sensitive files such as payroll data and shareholder information.

AP News Site Hit by Apparent Denial-of-Service Attack

03 November 2023
A hacker group called Anonymous Sudan, which is believed to be linked to Russia, claimed responsibility for the attack on the AP and other news sites, but the connection has not been verified.

Kinsing Actors Exploiting Recent Linux Flaw to Breach Cloud Environments

03 November 2023
The threat actors linked to Kinsing have been observed attempting to exploit the recently disclosed Linux privilege escalation flaw called Looney Tunables as part of a "new experimental campaign" designed to breach cloud environments. "Intriguingly, the attacker is also broadening the horizons of their cloud-native attacks by extracting credentials from the Cloud Service Provider (CSP)," cloud

Xage Security Raises $20M More to Expand its Security Platform

03 November 2023
Science Applications International Corporation (SAIC), along with existing investors Piva Capital, March Capital, SCF Partners, Overture Climate Fund, Valor Equity Partners, and Chevron Technology Ventures took part in the round.

Apache ActiveMQ Vulnerability Exploited as Zero-Day

03 November 2023
The recently patched Apache ActiveMQ vulnerability tracked as CVE-2023-46604 has been exploited as a zero-day since at least October 10. The post Apache ActiveMQ Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.

48 Malicious npm Packages Found Deploying Reverse Shells on Developer Systems

03 November 2023
These packages, disguised to appear legitimate, contain obfuscated JavaScript that can deploy a reverse shell on compromised systems. The packages were published by an npm user named hktalent, with 39 still available for download.

NodeStealer Malware Hijacking Facebook Business Accounts for Malicious Ads

03 November 2023
Compromised Facebook business accounts are being used to run bogus ads that employ "revealing photos of young women" as lures to trick victims into downloading an updated version of a malware called NodeStealer. "Clicking on ads immediately downloads an archive containing a malicious .exe 'Photo Album' file which also drops a second executable written in .NET – this payload is in charge of

Mortgage and Loan Giant Mr. Cooper Blames Cyberattack for Ongoing Outage

03 November 2023
The company is actively investigating the incident to determine if any data has been compromised, but they assure customers that no fees, penalties, or negative credit reporting will be incurred.

MITRE Releases Latest Version of ATT&CK Framework

03 November 2023
MITRE has released the latest version of its investigation framework, MITRE ATT&CK v14. The new version includes expanded coverage of activities adjacent to direct network interactions, such as deceptive practices and social engineering techniques.

Predictive AI in Cybersecurity: Outcomes Demonstrate All AI is Not Created Equally

03 November 2023
Here is what matters most when it comes to artificial intelligence (AI) in cybersecurity: Outcomes.  As the threat landscape evolves and generative AI is added to the toolsets available to defenders and attackers alike, evaluating the relative effectiveness of various AI-based security offerings is increasingly important — and difficult. Asking the right questions can help you spot solutions

Cyberattack Disrupts Ace Hardware’s Operations

03 November 2023
Cyberattack cripples Ace Hardware’s internal systems, resulting in shipment delays, suspended online orders. The post Cyberattack Disrupts Ace Hardware’s Operations appeared first on SecurityWeek.

Atlassian Issues Second Warning on Potential Exploitation of Critical Confluence Flaw 

03 November 2023
Atlassian warns that ‘critical information’ released on the Confluence bug CVE-2023-22518 increases the risk of exploitation. The post Atlassian Issues Second Warning on Potential Exploitation of Critical Confluence Flaw  appeared first on SecurityWeek.