Latest Cybersecurity News and Articles


Mozi Botnet Likely Killed by Its Creators

01 November 2023
The recent shutdown of the Mozi botnet is believed to have been carried out by its creators, possibly forced by Chinese authorities.  The post Mozi Botnet Likely Killed by Its Creators appeared first on SecurityWeek.

Dozens of Kernel Drivers Allow Attackers to Alter Firmware, Escalate Privileges

01 November 2023
VMware Carbon Black's Threat Analysis Unit (TAU) has discovered numerous previously unknown vulnerable kernel drivers that could be exploited by hackers to modify firmware or gain elevated privileges.

Samsung Galaxy Gets New Auto Blocker Anti-Malware Feature

01 November 2023
Auto Blocker prevents the installation of risky apps downloaded from outside the official app stores to protect users from malware and spyware. It also blocks unauthorized commands and software installations via the USB port.

Public Exposure of Data Breaches is Becoming Inevitable

01 November 2023
The number of cyber breaches becoming public is increasing, with companies facing financial and reputational consequences and being more likely to pay ransoms for stolen data.

Dozens of Kernel Drivers Allow Attackers to Alter Firmware, Escalate Privileges

01 November 2023
VMware’s Threat Analysis Unit finds 34 new vulnerable kernel drivers that can be exploited to alter or erase firmware and escalate privileges. The post Dozens of Kernel Drivers Allow Attackers to Alter Firmware, Escalate Privileges appeared first on SecurityWeek.

UserSec Takes Credit for Gatwick Cyberattack Post DDoS Assault on Manchester Airport

01 November 2023
The attacks were likely DDoS attacks, disrupting websites but not impacting airport operations or flights. The UK's NCSC is investigating the attacks, while Gatwick Airport officials are also dealing with spoofed Twitter accounts in their name.

Researchers Expose Prolific Puma's Underground Link Shortening Service

01 November 2023
A threat actor known as Prolific Puma has been maintaining a low profile and operating an underground link shortening service that's offered to other threat actors for at least over the past four years. Prolific Puma creates "domain names with an RDGA [registered domain generation algorithm] and use these domains to provide a link shortening service to other malicious actors, helping them evade

Supply Chain Startup Chainguard Scores $61 Million Series B

01 November 2023
Washington startup Chainguard banks $61 million in new financing as investors make hefty wagers on software supply chain security companies. The post Supply Chain Startup Chainguard Scores $61 Million Series B appeared first on SecurityWeek.

Malware 'Meal Kits' Serve Up No-Fuss RAT Attacks

01 November 2023
The Parallax RAT has seen a significant increase in usage, particularly through infected DLLs in seemingly legitimate invoices, making it harder for users to detect the attack.

North Korean Hackers Target Crypto Experts with KANDYKORN macOS Malware

01 November 2023
The attackers impersonate blockchain engineers on Discord, using social engineering tactics to trick victims into downloading and executing a ZIP archive containing malicious code.

Iranian Cyber Spies Use ‘LionTail’ Malware in Latest Attacks

01 November 2023
Check Point reports that an Iranian APT has been observed using a new malware framework in targeted attacks in the Middle East. The post Iranian Cyber Spies Use ‘LionTail’ Malware in Latest Attacks appeared first on SecurityWeek.

Four Dozen Countries Declare They Won’t Pay Ransomware Ransoms

01 November 2023
The United States and 48 other countries, along with the European Union and Interpol, are set to pledge this week that they will no longer pay ransoms as part of ransomware attacks.

British Library Knocked Offline by Cyberattack During the Weekend

01 November 2023
The library is working with the UK's National Cyber Security Centre (NCSC) and cybersecurity specialists to investigate the incident, but the nature of the attack and how the systems were breached are still unknown.

Joint security guidance offered to data centre operators and users

01 November 2023
New guidance from the NCSC and CPNI sets out a holistic security strategy for data centres to the keep the UK's online assets secure.

Joint security guidance offered to data centre operators and users

01 November 2023
New guidance from the NCSC and CPNI sets out a holistic security strategy for data centres to the keep the UK's online assets secure.

Mass Exploitation of ‘Citrix Bleed’ Vulnerability Underway

01 November 2023
Multiple threat actors are exploiting CVE-2023-4966, aka Citrix Bleed, a critical vulnerability in NetScaler ADC and Gateway. The post Mass Exploitation of ‘Citrix Bleed’ Vulnerability Underway appeared first on SecurityWeek.

Chrome 119 Patches 15 Vulnerabilities

01 November 2023
Chrome 119 is rolling out to Linux, macOS, and Windows users with patches for 15 vulnerabilities. The post Chrome 119 Patches 15 Vulnerabilities appeared first on SecurityWeek.

FBI ‘Keeping a Close Eye’ on Iranian Hackers as Israel-Hamas War Intensifies

01 November 2023
The FBI Director Christopher Wray warned that cyberattacks against the US by Iran and non-state actors could escalate if the conflict intensifies. He stated that Iran has a history of targeting American interests and critical infrastructure.

World's Largest Hardware Retail Cooperative Hit by Cyberattack

01 November 2023
Ace Hardware is currently experiencing a cyberattack that has disrupted its IT systems. While in-store payment systems and credit card processing are unaffected, online services such as placing orders are currently unavailable.

Cryptojackers Use IAM Credential Within Five Minutes of Discovery

01 November 2023
EleKtra-Leak, an ongoing cryptojacking campaign, exploits exposed IAM credentials on GitHub to mine Monero. The attackers are said to have used each stolen credential within five minutes of its discovery. The payloads are delivered via a Google Drive URL, another widely used application, to evade detection. It is recommended to audit the GitHub repository cloning events for any suspicious operations and secure the exposed keys.