Latest Cybersecurity News and Articles
30 October 2023
The vulnerabilities, tracked as CVE-2022-4886, CVE-2023-5043, and CVE-2023-5044, include path sanitization bypass, annotation injection for arbitrary command execution, and code injection via the permanent-redirect annotation.
30 October 2023
Though it shares strong similarities, Hunters International denies being the same group as Hive, claiming to have purchased the source code from them, and focuses on stealing data rather than encryption.
30 October 2023
Three unpatched high-severity security flaws have been disclosed in the NGINX Ingress controller for Kubernetes that could be weaponized by a threat actor to steal secret credentials from the cluster.
The vulnerabilities are as follows -
CVE-2022-4886 (CVSS score: 8.8) - Ingress-nginx path sanitization can be bypassed to obtain the credentials of the ingress-nginx controller
CVE-2023-5043 (
30 October 2023
A new cyber attack campaign has been observed using spurious MSIX Windows app package files for popular software such as Google Chrome, Microsoft Edge, Brave, Grammarly, and Cisco Webex to distribute a novel malware loader dubbed GHOSTPULSE.
"MSIX is a Windows app package format that developers can leverage to package, distribute, and install their applications to Windows users," Elastic
28 October 2023
New findings have shed light on what's said to be a lawful attempt to covertly intercept traffic originating from jabber[.]ru (aka xmpp[.]ru), an XMPP-based instant messaging service, via servers hosted on Hetzner and Linode (a subsidiary of Akamai) in Germany.
"The attacker has issued several new TLS certificates using Let's Encrypt service which were used to hijack encrypted STARTTLS
28 October 2023
The hackers exploited a vulnerability in the MOVEit file transfer tool, used by CCleaner, to access sensitive data. The stolen information includes names, contact details, and product purchase information. Less than 2% of users were affected.
28 October 2023
The outage has hindered electronic filings, payment processing, case management, public access to records, and applications for various legal services, leading to delays and a reliance on paper-based processes.
28 October 2023
The LockBit group has a history of listing companies as victims, even if it was actually a vendor to the compromised company, so further investigation is needed to confirm the extent of the breach.
28 October 2023
Stanford University is currently investigating a cybersecurity incident within its Department of Public Safety after a ransomware gang claimed to have attacked the school. The Akira ransomware gang has claimed to have stolen 430 GB of data.
27 October 2023
Small business cybersecurity was analyzed in a recent Comcast report, finding that daily malware activity in 2023 roughly doubled since 2022.
27 October 2023
Federal civilian agencies have remediated over 7 million Known Exploited Vulnerabilities findings this year, resulting in a 72% decrease in the percentage of vulnerabilities exposed for 45 or more days.
27 October 2023
The group compromised a software vendor by exploiting known security flaws in another popular software. They deployed malware such as SIGNBT and LPEClient to gain control over the victims' systems.
27 October 2023
The U.K NCSC's PDNS for Schools service will be rolled out for free over the next year, and it will provide metrics about network health and support for resolving issues.
27 October 2023
StripedFly features TOR-based traffic concealing mechanisms, automated updating, worm-like spreading capabilities, and an EternalBlue SMBv1 exploit created before the flaw was disclosed.
27 October 2023
Genetics testing firm 23andMe is facing multiple class action lawsuits and congressional scrutiny following a credential-stuffing hacking incident that exposed sensitive customer data.
27 October 2023
The breach, which occurred from August 12 to September 26, involved the theft of personal information such as names, Social Security numbers, driver's license numbers, medical information, and health insurance policy numbers.
27 October 2023
A recent survey by ISACA revealed that the biggest risk associated with generative AI is misinformation and disinformation. This has led to concerns about privacy violations, social engineering, intellectual property loss, and job displacement.
27 October 2023
Reeds Spring School District discovered in late September that threat actors had gained access to files between April 26, 2023 and May 18, 2023.
27 October 2023
The North Korea-aligned Lazarus Group has been attributed as behind a new campaign in which an unnamed software vendor was compromised through the exploitation of known security flaws in another high-profile software.
The attack sequences, according to Kaspersky, culminated in the deployment of malware families such as SIGNBT and LPEClient, a known hacking tool used by the threat actor for
27 October 2023
DuckTail is a highly elusive form of malicious software that evades detection, collects information about victims, communicates with a Command and Control server through a Telegram Bot, and exfiltrates data through ZIP archives.