Latest Cybersecurity News and Articles


1Password Detects “Suspicious Activity” in its Internal Okta Account

24 October 2023
The breach occurred in Okta's customer support management system, allowing an unknown attacker to access files uploaded by some Okta customers. 1Password is the second known Okta customer to be targeted in a follow-on attack.

Enterprise Browser Startup Island Banks $100M in Funding

24 October 2023
The company said the investment was led by Prysm Capital at a valuation of $1.5 billion. Existing backers Canapi Ventures, Insight Partners, Stripes, Sequoia, Cyberstarts, and Georgian also expanded equity positions.

University of Michigan Warns That Personal Information was Leaked During Cyberattack

24 October 2023
The hackers gained access to Social Security numbers, driver's license numbers, financial account information, health records, and other sensitive data, potentially impacting a large number of individuals.

Backdoor Implant on Hacked Cisco Devices Modified to Evade Detection

24 October 2023
The backdoor implanted on Cisco devices by exploiting a pair of zero-day flaws in IOS XE software has been modified by the threat actor so as to escape visibility via previous fingerprinting methods. "Investigated network traffic to a compromised device has shown that the threat actor has upgraded the implant to do an extra header check," NCC Group's Fox-IT team said. "Thus, for a lot of devices

1Password Detects Suspicious Activity Following Okta Support Breach

24 October 2023
Popular password management solution 1Password said it detected suspicious activity on its Okta instance on September 29 following the support system breach, but reiterated that no user data was accessed. "We immediately terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or user-facing," Pedro Canahuati, 1Password CTO, 

China Crackdown on Cyber Scams in Southeast Asia Nets Thousands but Leaves Networks Intact

23 October 2023
Chinese authorities have netted thousands of people in a crackdown on cyber scams, but the criminal networks remain intact. The post China Crackdown on Cyber Scams in Southeast Asia Nets Thousands but Leaves Networks Intact appeared first on SecurityWeek.

Blockaid Emerges From Stealth With $33 Million Investment

23 October 2023
Blockaid raises a Series A funding round to build technology to secure blockchain applications from hacks and scams. The post Blockaid Emerges From Stealth With $33 Million Investment appeared first on SecurityWeek.

Casio Says Personal Information Accessed in Web Application Server Hack

23 October 2023
Hackers access the personal information of Casio customers after compromising the server for an education web application. The post Casio Says Personal Information Accessed in Web Application Server Hack appeared first on SecurityWeek.

City of Philadelphia discloses data breach

23 October 2023
The city of Philadelphia released a notice regarding a data breach that occurred between May and July of 2023, including suspicious email activity. 

Rockwell Automation to Acquire ICS/OT Security Firm Verve Industrial

23 October 2023
Rockwell Automation agreed to acquire ICS/OT cybersecurity firm Verve Industrial Protection to expand its offerings. The post Rockwell Automation to Acquire ICS/OT Security Firm Verve Industrial appeared first on SecurityWeek.

SolarWinds Patches High-Severity Flaws in Access Rights Manager

23 October 2023
SolarWinds patches high-severity flaws in its Access Rights Manager product, including three unauthenticated remote code execution issues. The post SolarWinds Patches High-Severity Flaws in Access Rights Manager appeared first on SecurityWeek.

DoNot Team's New Firebird Backdoor Hits Pakistan and Afghanistan

23 October 2023
Researchers have linked DoNot Team, a threat actor believed to be of Indian origin, to a .NET-based backdoor called Firebird. The backdoor has been used to target victims in Pakistan and Afghanistan.

Threat Actor Found Selling Access to Facebook and Instagram’s Police Portal

23 October 2023
Researchers suspect that Meta was either tricked into providing access to the threat actor or the threat actor obtained credentials for a legitimate law enforcement account.

Enterprise Browser Startup Island Banks $100M in Funding

23 October 2023
Since 2020, Island has raised a total of $325 million to help protect corporate data flowing through SaaS and internal web applications. The post Enterprise Browser Startup Island Banks $100M in Funding appeared first on SecurityWeek.

QNAP Takes Down Server Behind Widespread Brute-Force Attacks

23 October 2023
QNAP urges customers to implement security measures such as changing default access port numbers, using strong passwords, and updating firmware to protect against future attacks.

Report: CISOs’ big worry in new role is inaccurate data on security posture

23 October 2023
A new report reveals more than half of senior cybersecurity decision makers find the biggest concern when taking on a new CISO role is receiving an inaccurate audit of the company's security posture.

DC Board of Elections Says Full Voter Roll Compromised in Data Breach

23 October 2023
The District of Columbia Board of Elections says full voter roll compromised in a recent data breach at hosting provider DataNet. The post DC Board of Elections Says Full Voter Roll Compromised in Data Breach appeared first on SecurityWeek.

FTC works to reduce cross-border fraud

23 October 2023
The FTC sent a report to congress in an attempt to extend the Undertaking Spam, Spyware and Fraud Enforcement With Enforcers Beyond Borders Act.

From Copacabana to Barcelona: The Cross-Continental Threat of Brazilian Banking Malware

23 October 2023
Proofpoint researchers have discovered a new version of the Grandoreiro malware that is targeting victims in both Mexico and Spain. This is unusual as the malware has historically only targeted Portuguese and Spanish speakers in Brazil and Mexico.

City of Philadelphia Discloses Data Breach After Five Months

23 October 2023
A potential data breach in Philadelphia's email system may have exposed protected health information, including names, addresses, birth dates, Social Security numbers, medical information, and some financial information.