Latest Cybersecurity News and Articles


Meta Launches Paid Ad-Free Subscription in Europe to Satisfy Privacy Laws

31 October 2023
Meta on Monday announced plans to offer an ad-free option to access Facebook and Instagram for users in the European Union (EU), European Economic Area (EEA), and Switzerland to comply with "evolving" data protection regulations in the region. The ad-free subscription, which costs €9.99/month on the web or €12.99/month on iOS and Android, is expected to be officially available starting next

SEC Charges SolarWinds and Its CISO With Fraud and Cybersecurity Failures

30 October 2023
The SEC filed charges against SolarWinds and its CISO over misleading investors about its cybersecurity practices and known risks. The post SEC Charges SolarWinds and Its CISO With Fraud and Cybersecurity Failures appeared first on SecurityWeek.

NASCO notifies individuals of a data breach through MOVEit

30 October 2023
NASCO announced a data breach. NASCO utilized MOVEit software, which was accessed in late May and the breach was discovered in mid-July.

FTC says financial institutions must disclose data breaches in 30 days

30 October 2023
The Federal Trade Commission (FTC) has amended the Safeguards Rule requiring non-banking financial institutions to report data breaches.

Remcos RAT Disguises as Payslip to Infect Users

30 October 2023
Researchers uncovered a phishing campaign distributing the Remcos remote access trojan. Cybercriminals disguised the malware as a payslip in a deceptive email. Remcos RAT can perform a range of malicious activities, including keylogging, capturing screenshots, controlling webcams and microphones, and extracting browser histories and passwords.

Canada Bans WeChat and Kaspersky on Government Phones

30 October 2023
The Chief Information Officer of Canada determined that WeChat and Kaspersky applications present an unacceptable level of risk to privacy and security. The post Canada Bans WeChat and Kaspersky on Government Phones appeared first on SecurityWeek.

QR Code-based Phishing Attains 587% Hike, Reports Check Point

30 October 2023
QR code phishing attacks, including quishing and QRLJacking, have seen a dramatic 587% increase from August to September 2023, with threat actors extracting login information from users. This social engineering tactic takes advantage of the trust in QR codes and the routine nature of security updates. The prevalence of quishing is a testament to the ever-evolving nature of cyber threats. 

Huawei, Vivo Phones Tag Google App as TrojanSMS-PA Malware

30 October 2023
Huawei, Honor, and Vivo devices are displaying false security alerts urging the deletion of the Google app due to a supposed TrojanSMS-PA malware, but Google denies that its app triggered the alerts.

Attackers Can Use Modified Wikipedia Pages to Mount Redirection Attacks on Slack

30 October 2023
The Wiki-Slack attack relies on crafting a legitimate footnote in a Wikipedia article and exploiting Slack's rendering of the shared page's preview to generate a hidden malicious link.

Pro-Hamas Hacktivists Targeting Israeli Entities with Wiper Malware

30 October 2023
A pro-Hamas hacktivist group has been observed using a new Linux-based wiper malware dubbed BiBi-Linux Wiper, targeting Israeli entities amidst the ongoing Israeli-Hamas war. "This malware is an x64 ELF executable, lacking obfuscation or protective measures," Security Joes said in a new report published today. "It allows attackers to specify target folders and can potentially destroy an entire

Toronto Public Library Facing Disruptions Due to Cyberattack

30 October 2023
The organization has confirmed that it is a cybersecurity incident, and while there is no evidence of compromised personal information, it may take several days to fully restore normal operations.

45% of Americans avoid accessing sensitive information on public Wi-Fi

30 October 2023
According to a public Wi-Fi security survey by NordVPN, almost 70% of U.S. respondents prefer mobile internet for public online activities.

IoT Security Threats Highlight the Need for Zero Trust Principles

30 October 2023
The manufacturing sector is particularly vulnerable to IoT malware attacks, experiencing an average of 6,000 attacks per week according to Zscaler, which can disrupt critical OT processes and pose long-term challenges for security teams.

White House Issues Sweeping Executive Order to Secure AI

30 October 2023
The order directs the National Institute of Standards and Technology to establish new standards for red-team testing and the Department of Health and Human Services to create a safety program for AI in healthcare.

Florida SIM Swapper Sentenced to Prison for Cryptocurrency Theft

30 October 2023
A 20-year-old Floridian was sentenced to prison for his role in a hacking scheme that led to the theft of $1 million in cryptocurrency. The post Florida SIM Swapper Sentenced to Prison for Cryptocurrency Theft appeared first on SecurityWeek.

Malvertising via Dynamic Search Ads Delivers Malware Bonanza

30 October 2023
The compromised website injected malicious content, including overlays promoting software serial keys, which resulted in misleading ads being automatically generated by Google Ads.

Proofpoint to Acquire Tessian for AI-Powered Email Security Tech

30 October 2023
Proofpoint removes a formidable competitor from the crowded email security market and adds technology to address risk from misdirected emails. The post Proofpoint to Acquire Tessian for AI-Powered Email Security Tech appeared first on SecurityWeek.

Boeing Investigating Ransomware Attack Claims

30 October 2023
The LockBit ransomware gang claims to have stolen large amounts of data from aerospace giant Boeing. The post Boeing Investigating Ransomware Attack Claims appeared first on SecurityWeek.

Apple Improves iMessage Security With Contact Key Verification

30 October 2023
New capability detects attacks on iMessage servers and allows users to verify a conversation partner’s identity. The post Apple Improves iMessage Security With Contact Key Verification appeared first on SecurityWeek.

EleKtra-Leak Cryptojacking Attacks Exploit AWS IAM Credentials Exposed on GitHub

30 October 2023
The threat actor behind the campaign quickly scans and clones GitHub repositories to capture exposed keys, highlighting the importance of promptly removing and revoking any compromised credentials.