Latest Cybersecurity News and Articles


5,000 Current and Former Okta Employees' Data Compromised in Third-Party Vendor Breach

03 November 2023
The breach at third-party vendor Rightway Healthcare comes as the latest in a series of security issues for Okta, underscoring the need for robust security measures and ongoing vigilance.

Cybersecurity Habits and Behaviors Executives Need to be Aware of

03 November 2023
According to a new report, many executives exhibit risky behaviors such as sharing passwords, using easy-to-guess password hacks, and accessing unauthorized work files, posing significant security risks.

Industry Reactions to SEC Charging SolarWinds and Its CISO: Feedback Friday

03 November 2023
SEC charges SolarWinds and its CISO over cybersecurity and risk handling practices before the massive hack that came to light in late 2020.   The post Industry Reactions to SEC Charging SolarWinds and Its CISO: Feedback Friday appeared first on SecurityWeek.

Cisco Patches 27 Vulnerabilities in Network Security Products

03 November 2023
The most severe vulnerability, CVE-2023-20048, is a command injection bug in the Firepower Management Center (FMC) that could allow authenticated attackers to execute configuration commands on targeted devices.

Six Steps to Accelerate Cybersecurity Incident Response

03 November 2023
Effective incident response requires preparation, training, and a clear response strategy that includes educating personnel and updating training regularly. SANS Institute defines a framework with six steps to a successful incident response.

CanesSpy Spyware Discovered in Modified WhatsApp Versions

03 November 2023
Cybersecurity researchers have unearthed a number of WhatsApp mods for Android that come fitted with a spyware module dubbed CanesSpy. These modified versions of the instant messaging app have been observed propagated via sketchy websites advertising such software as well as Telegram channels used primarily by Arabic and Azerbaijani speakers, one of which boasts 2 million users. "The trojanized

Connecticut AG Demands Answers From 23andMe After Data Breach

03 November 2023
Connecticut Attorney General William Tong has demanded answers from 23andMe regarding the breach, citing potential risks to individuals with Ashkenazi Jewish and Chinese heritage and questioning the company's compliance with data privacy regulations.

Update: Ace Hardware Says 1,202 Devices Were Hit During Cyberattack

03 November 2023
The Ace Hardware CEO reported that out of Ace Hardware's 1,400 servers and 3,500 networked devices, 1,202 were affected by the incident. The restoration process is underway, particularly for the 196 servers crucial for the logistics operations.

Global Government Coalition Launching New Ransomware Efforts

03 November 2023
The initiative discourages ransom payments and aims to provide assistance to member governments and critical sectors affected by ransomware, while also implementing measures such as a shared blacklist of crypto wallets used for extortion payments.

Update: Atlassian Warns of Exploit for Confluence Data Wiping Bug, Get Patching

03 November 2023
Atlassian has issued a warning to administrators about a critical security flaw in Confluence software. The flaw, known as CVE-2023-22518, allows attackers to exploit improper authorization and potentially destroy data on vulnerable servers.

Accenture Buys Innotec Security to Expand Footprint in Spain

03 November 2023
The integration of Innotec's technology into Accenture's framework will enable the company to provide around-the-clock managed services and drive revenue and headcount growth in the Spanish market.

48 Malicious npm Packages Found Deploying Reverse Shells on Developer Systems

03 November 2023
A new set of 48 malicious npm packages have been discovered in the npm repository with capabilities to deploy a reverse shell on compromised systems. "These packages, deceptively named to appear legitimate, contained obfuscated JavaScript designed to initiate a reverse shell on package install," software supply chain security firm Phylum said. All the counterfeit packages have been published by

Russian Reshipping Service ‘SWAT USA Drop’ Exposed

02 November 2023
One of the largest cybercrime services for laundering stolen merchandise was hacked recently, exposing its internal operations, finances and organizational structure. Here’s a closer look at the Russia-based SWAT USA Drop Service, which currently employs more than 1,200 people across the United States who are knowingly or unwittingly involved in reshipping expensive consumer goods purchased with stolen credit cards.

Researchers Discover 117 Vulnerabilities in Microsoft 365 Apps via the SketchUp 3D Library

02 November 2023
By developing a SketchUp fuzzing harness and using a dumb file format fuzzer, 20 unique vulnerabilities, including use-after-free and stack buffer overflow, were discovered in just one month.

Medical Firm Reaches $100,000 Settlement With HHS Over 2017 Ransomware Attack

02 November 2023
The company failed to adequately protect electronic protected health information, violated HIPAA laws, and lacked sufficient monitoring and policies to prevent and address cyberattacks.

Major Mexican Airport Confirms Experts are Working to Address Cyberattack

02 November 2023
Querétaro Intercontinental Airport in Mexico has experienced a cyberattack, with an employee downloading a file containing malware, but the airport's operational security was not compromised and the attack has been contained and isolated.

Iran's MuddyWater Targets Israel in New Spear-Phishing Cyber Campaign

02 November 2023
MuddyWater's tactics have evolved over time, with the group now utilizing a new file-sharing service called Storyblok and a new command-and-control framework called MuddyC2Go.

After Major Cloud Hacks, Microsoft Unveils ‘Secure Future Initiative’

02 November 2023
In response to a spate of embarrassing hacks, Redmond pushes ‘Secure Future Initiative’ promising faster cloud patches, better management of identity signing keys and products with a higher default security bar. The post After Major Cloud Hacks, Microsoft Unveils ‘Secure Future Initiative’ appeared first on SecurityWeek.

California Community College Río Hondo Dealing With Cybersecurity Incident

02 November 2023
Río Hondo College in Southern California experienced a cybersecurity incident that disrupted campus functions and financial aid disbursements, potentially indicating a ransomware attack.

Medical Research Executive Hit in SIM-Swapping Attack by ALPHV Gang

02 November 2023
Ransomware gang Alphv, also known as BlackCat, claims to have stolen data from Advarra, a firm that assists with medical trials. The criminals gained access to an executive's accounts by SIM swapping their cellphone number.