Latest Cybersecurity News and Articles


Harmonic Lands $7M Funding to Secure Generative AI Deployments

23 October 2023
The company aims to provide businesses with a comprehensive understanding of AI adoption within their enterprises, offering risk assessments for all AI applications and identifying compliance, security, and privacy issues.

Update: War Crimes Tribunal Says September Cyberattack was an Act of Espionage

23 October 2023
The attack is seen as an attempt to undermine the Court's mandate. Dutch law enforcement authorities are currently investigating the incident, but it is unclear if any information was stolen.

Exploitation of Cisco IOS XE vulnerabilities affecting UK organisations

22 October 2023
Organisations are encouraged to take action to mitigate vulnerabilities affecting Cisco IOS XE (CVE-2023-20198 and CVE-2023-20273) and follow the latest vendor advice.

Europol Dismantles Ragnar Locker Ransomware Infrastructure, Nabs Key Developer

21 October 2023
Europol on Friday announced the takedown of the infrastructure associated with Ragnar Locker ransomware, alongside the arrest of a "key target" in France. "In an action carried out between 16 and 20 October, searches were conducted in Czechia, Spain, and Latvia," the agency said. "The main perpetrator, suspected of being a developer of the Ragnar group, has been brought in front of the examining

Okta's Support System Breach Exposes Customer Data to Unidentified Threat Actors

21 October 2023
Identity services provider Okta on Friday disclosed a new security incident that allowed unidentified threat actors to leverage stolen credentials to access its support case management system. "The threat actor was able to view files uploaded by certain Okta customers as part of recent support cases," David Bradbury, Okta's chief security officer, said. "It should be noted that the Okta

Cisco Zero-Day Exploited to Implant Malicious Lua Backdoor on Thousands of Devices

21 October 2023
The vulnerability, tracked as CVE-2023-20273, allows for privilege escalation through the Web UI. It has been used alongside another vulnerability, CVE-2023-20198, in an exploit chain to deploy a malicious implant.

Critical RCE Flaws Found in Solarwinds Access Audit Solution

21 October 2023
The vulnerabilities, which have been patched in version 2023.2.1, could be exploited by remote unauthenticated attackers to execute arbitrary code in the context of SYSTEM without authentication.

Business-Oriented Threat Involving ‘Several Types of Malware All at Once’ Remains Active

21 October 2023
The campaign involves various types of malware, including cryptominers and keyloggers, and primarily targets enterprises that provide business-to-business (B2B) products and services.

FBI: Thousands of Remote IT Workers Sent Wages to North Korea to Help Fund Weapons Program

21 October 2023
The workers used false identities to secure remote IT jobs and funneled their earnings to North Korea, while also infiltrating and stealing information from the companies they worked for.

Cisco Zero-Day Exploited to Implant Malicious Lua Backdoor on Thousands of Devices

20 October 2023
Cisco has warned of a new zero-day flaw in IOS XE that has been actively exploited by an unknown threat actor to deploy a malicious Lua-based implant on susceptible devices. Tracked as CVE-2023-20273 (CVSS score: 7.2), the issue relates to a privilege escalation flaw in the web UI feature and is said to have been used alongside CVE-2023-20198 as part of an exploit chain. "The attacker first

23andMe announce data breach

20 October 2023
23andMe announced that customer profile information was accessed without user consent, including DNA Relatives profiles for individual accounts.

Okta Support System Hacked, Sensitive Customer Data Stolen

20 October 2023
Okta warns that hackers broke into its support case management system and stole sensitive data that can be used to impersonate valid users. The post Okta Support System Hacked, Sensitive Customer Data Stolen appeared first on SecurityWeek.

48% of organizations predict cyberattack recovery to take weeks

20 October 2023
According to a cloud adoption report, 72% of respondents are using generative AI and 74% leveraging public cloud AI and analytics services.

Hackers Stole Access Tokens from Okta’s Support Unit

20 October 2023
Okta, a company that provides identity tools like multi-factor authentication and single sign-on to thousands of businesses, has suffered a security breach involving a compromise of its customer support unit, KrebsOnSecurity has learned. Okta says the incident affected a "very small number" of customers, however it appears the hackers responsible had access to Okta's support platform for at least two weeks before the company fully contained the intrusion.

In Other News: Energy Services Firm Hacked, Tech CEO Gets Prison Time, X Glitch Leads to CIA Channel Hijack

20 October 2023
Summary of notable cybersecurity news stories that may be top headlines, but are important for the week of October 16, 2023. The post In Other News: Energy Services Firm Hacked, Tech CEO Gets Prison Time, X Glitch Leads to CIA Channel Hijack appeared first on SecurityWeek.

India Targets Microsoft, Amazon Tech Support Scammers in Nationwide Crackdown

20 October 2023
India's Central Bureau of Investigation (CBI) conducted raids at 76 locations across the country as part of Operation Chakra-II, targeting cybercrime operations involved in tech support scams and cryptocurrency fraud.

Exploited SSH Servers Offered in the Dark web as Proxy Pools

20 October 2023
Researchers at Aqua Nautilus have uncovered a threat to SSH in cloud environments. Attackers are using SSH tunneling to exploit SSH servers and gain access to organizations' networks.

CISA, NSA, FBI, MS-ISAC Publish Guide on Preventing Phishing Intrusions

20 October 2023
The guide categorizes phishing into two common tactics: obtaining login credentials and deploying malware, and provides details on techniques used by malicious actors, such as impersonation and spoofing, to carry out these attacks.

Almost 42,000 Cisco IOS XE Devices Exploited, No Patch Available

20 October 2023
Security researchers have discovered tens of thousands of exploited devices with a backdoor installed due to a critical zero-day vulnerability in Cisco IOS XE software's web user interface.

CISA Launches New Phase of Secure by Design to Push Global Industry on Software Security

20 October 2023
CISA plans to issue a request for information to address Secure by Design engineering and is urging software manufacturers to demonstrate evidence of security incorporation through artifacts.