Latest Cybersecurity News and Articles


Kazakhstan-Associated Yorotrooper Disguises Origin of Attacks as Azerbaijan

25 October 2023
The threat actor attempts to disguise their origin by hosting infrastructure in Azerbaijan and using the Azerbaijani language in their operations, despite not being fluent in Azerbaijani.

Ukrainian Cyber Officials Warn of Surge in SmokeLoader Attacks on Financial, Government Entities

25 October 2023
Smokeloader malware is a highly complex tool that can perform various malicious functions, such as stealing credentials and executing DDoS attacks, with prices ranging from $400 to $1,650 depending on the package.

CoinFlip Data Breach Exposes Personal Information of Over 36,000 Customers

25 October 2023
The breach, which occurred on August 7, 2023, was discovered a day later and the cybercriminals were removed from CoinFlip's systems with the assistance of their IT team.

Mandiant Intelligence Chief Raises Alarm Over China’s ‘Volt Typhoon’ Hackers in US Critical Infrastructure

25 October 2023
Mandiant's Chief analyst urges critical infrastructure defenders to work on finding and removing traces of Volt Typhoon, a Chinese government-backed hacking team caught in a series of eyebrow-raising attacks against targets in Guam and the United States. The post Mandiant Intelligence Chief Raises Alarm Over China’s ‘Volt Typhoon’ Hackers in US Critical Infrastructure appeared first on SecurityWeek.

Hackers Earn $400k on First Day at Pwn2Own Toronto 2023

25 October 2023
NAS devices, printers, IP cameras, speakers, and mobile phones were hacked on the first day at Pwn2Own Toronto 2023. The post Hackers Earn $400k on First Day at Pwn2Own Toronto 2023 appeared first on SecurityWeek.

Russian Hackers Caught Exploiting Roundcube Webmail Zero-Day

25 October 2023
Russian APT Winter Vivern exploits a zero-day in the Roundcube webmail server in attacks targeting European governments. The post Russian Hackers Caught Exploiting Roundcube Webmail Zero-Day appeared first on SecurityWeek.

Winter Vivern Exploits Zero-Day Vulnerability in Roundcube Webmail Servers

25 October 2023
The vulnerability, assigned CVE-2023-5631, allowed attackers to execute arbitrary JavaScript code in the context of a Roundcube user's browser window through a specially crafted email.

New England Biolabs Exposes Sensitive Data via Environment Files

25 October 2023
The two exposed environment files contained sensitive information such as database credentials, SMTP server login details, and payment processing information, according to Cybernews researchers.

Bracing for AI-Enabled Ransomware and Cyber Extortion Attacks

25 October 2023
Ransomware groups are likely to leverage AI-enabled tools, such as chatbots and voice cloning, to enhance their social engineering tactics and technical skills, posing a greater threat to public and private organizations.

Connecting the wars: Intel analysis of Israel-Hamas and Russia-Ukraine

25 October 2023
In Episode 17 of the Cybersecurity & Geopolitical Discussion from Security magazine, Ian Thornton-Trump, Philip Ingram and Lisa Forte analyze the Russia-Ukraine and Israel-Hamas wars.

CISA Working on Updated National Cyber Incident Response Plan

25 October 2023
The updated plan will involve collaboration with industry stakeholders, government agencies, and critical infrastructure organizations, recognizing the private sector's role as the first responder to many cyber incidents.

New Project Analyzes and Catalogs Vendor Support for Secure PLC Coding

25 October 2023
A new project aims to make it easier for PLC programmers to implement secure coding practices by cataloging useful files and functions from each vendor. The post New Project Analyzes and Catalogs Vendor Support for Secure PLC Coding appeared first on SecurityWeek.

Accenture Expands Cybersecurity Services Capabilities in Latin America With Acquisition of MNEMO Mexico

25 October 2023
MNEMO Mexico's expertise in advanced cyber defense, generative AI-powered cyber intelligence, and a 24/7 security operations center will enhance Accenture's capabilities in helping organizations build cyber-resilient businesses.

Keyfactor Earns $1.3B Valuation After Sale of Minority Stake

25 October 2023
With the investment from Sixth Street Growth, Keyfactor aims to continue its trajectory of hypergrowth, leveraging their experience, financial prowess, and strategic network to empower the company in the next chapter of its development.

Censys Banks $75M for Attack Surface Management Technology

25 October 2023
Michigan startup raises $75 million in new funding as venture capital investors bet big on attack surface management technologies. The post Censys Banks $75M for Attack Surface Management Technology appeared first on SecurityWeek.

Cybercriminals Run Malicious Ads via Facebook

25 October 2023
Criminals are hijacking business accounts on Facebook and running their own advertising campaigns, causing financial damage and reputational harm to legitimate account holders.

Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

25 October 2023
The threat actor known as Winter Vivern has been observed exploiting a zero-day flaw in Roundcube webmail software on October 11, 2023, to harvest email messages from victims' accounts. "Winter Vivern has stepped up its operations by using a zero-day vulnerability in Roundcube," ESET security researcher Matthieu Faou said in a new report published today. Previously, it was using known

Cyber Operations Linked to Israel-Hamas Fighting Gain Momentum

25 October 2023
The escalating reliance on information operations by these groups aims to influence the global perception of the conflict, with strategic campaigns designed to manipulate social media platforms and influence media outlets.

The Cybersecurity Resilience Quotient: Measuring Security Effectiveness

25 October 2023
The Cybersecurity Resilience Quotient empowers organizations to assess their security posture comprehensively, considering asset exposure, vulnerabilities, and criticality alongside process and network architecture and disaster recovery plans. The post The Cybersecurity Resilience Quotient: Measuring Security Effectiveness appeared first on SecurityWeek.

Critical OAuth Flaws Uncovered in Grammarly, Vidio, and Bukalapak Platforms

25 October 2023
Critical security flaws have been disclosed in the Open Authorization (OAuth) implementation of popular online services such as Grammarly, Vidio, and Bukalapak, building upon previous shortcomings uncovered in Booking[.]com and Expo. The weaknesses, now addressed by the respective companies following responsible disclosure between February and April 2023, could have allowed malicious actors to