Latest Cybersecurity News and Articles
23 October 2023
A 22-year-old New Jersey man has been sentenced to more than 13 years in prison for participating in a firebombing and a shooting at homes in Pennsylvania last year. Patrick McGovern-Allen was the subject of a Sept. 4, 2022 story here about the emergence of "violence-as-a-service" offerings, where random people from the Internet hire themselves out to perform a variety of local, physical attacks, including firebombing a home, "bricking" windows, slashing tires, or performing a drive-by shooting at someone's residence.
23 October 2023
Quasar RAT, an open-source remote access trojan also known as CinaRAT or Yggdrasil, has been spotted leveraging a new Microsoft file as part of its DLL sideloading process to stealthily drop malicious payloads on compromised Windows systems. Once the Quasar RAT payload is executed in the computer's memory, it further employs the process hollowing technique that allows it to conceal its malicious intent and make detection more challenging.
23 October 2023
The personal information of D.C. voters, including partial Social Security numbers and driver's license numbers, may have been exposed in a data breach affecting the Board of Elections' voter roll.
23 October 2023
Cisco has found a second zero-day vulnerability that has been exploited in recent attacks as the number of hacked devices has started dropping.
The post Cisco Finds Second Zero-Day as Number of Hacked Devices Apparently Drops appeared first on SecurityWeek.
23 October 2023
The attack chain involves renaming legitimate files, injecting malicious code, and leveraging DLL sideloading to ultimately deploy the Quasar RAT payload, highlighting the sophistication of the attack.
23 October 2023
A recent report from WithSecure has highlighted a surge in DarkGate malware infection attempts. Multiple Vietnamese threat groups have been found to deploy info-stealer campaigns using Malware-as-a-Service (MaaS), honing in on specific sectors or groups. Their modus operandi displays notable similarities, with recurring themes in lures and delivery methods.
23 October 2023
The cyberattack caused outages in the company's phone service, building connectivity, and online services, impacting customers' ability to pay bills and file claims online.
23 October 2023
The threat actor known as DoNot Team has been linked to the use of a novel .NET-based backdoor called Firebird targeting a handful of victims in Pakistan and Afghanistan.
Cybersecurity company Kaspersky, which disclosed the findings in its APT trends report Q3 2023, said the attack chains are also configured to deliver a downloader named CSVtyrei, so named for its resemblance to Vtyrei.
"Some
23 October 2023
With the record-setting growth of consumer-focused AI productivity tools like ChatGPT, artificial intelligence—formerly the realm of data science and engineering teams—has become a resource available to every employee.
From a productivity perspective, that’s fantastic. Unfortunately for IT and security teams, it also means you may have hundreds of people in your organization using a new tool in
23 October 2023
According to a report by cybersecurity company Nixu, over 80% of organizations in northern Europe prioritize business resilience as the main driver for their cybersecurity investments.
23 October 2023
The attack involves the deployment of a trojanized version of the UTetris application, which acts as a loader for malware and facilitates the spread of the attack to potentially air-gapped systems.
23 October 2023
The increased investment in security, driven by concerns associated with AI and risk, is expected to be the top category for increased spending, with 4 in 5 CIOs planning to increase security investments, according to Gartner.
23 October 2023
It is speculated that the threat actors behind the attacks may be deploying an update to hide their presence, or a grey-hat hacker could be rebooting the devices to clear the implant.
23 October 2023
A recent study by Commvault shows that many senior executives are not actively involved in their company's cybersecurity initiatives. Only 33% of CEOs and 21% of other senior leaders are heavily engaged in cyber preparedness.
23 October 2023
The infrastructure of the Al-Qassam Brigades website has been moved between different providers to keep it online amidst Israeli airstrikes and constant attacks from hackers.
23 October 2023
Law enforcement agencies from 11 countries collaborated to arrest a key member of the Ragnar Locker ransomware group, leading to the takedown of their infrastructure and data leak website.
23 October 2023
Venture capital investments in cybersecurity firms have decreased, with $1.9 billion raised in the third quarter, a 30% drop from the previous year, according to new data released by Crunchbase.
23 October 2023
Hackers gained access to Okta's customer support management system, allowing them to view private customer information, including sensitive data such as cookies and session tokens.
23 October 2023
Organisations are encouraged to take action to mitigate vulnerabilities affecting Cisco IOS XE (CVE-2023-20198 and CVE-2023-20273) and follow the latest vendor advice.
23 October 2023
The open-source remote access trojan known as Quasar RAT has been observed leveraging DLL side-loading to fly under the radar and stealthily siphon data from compromised Windows hosts.
"This technique capitalizes on the inherent trust these files command within the Windows environment," Uptycs researchers Tejaswini Sandapolla and Karthickkumar Kathiresan said in a report published last week,