Latest Cybersecurity News and Articles
20 October 2023
The Philippine defense chief ordered the 163,000-member military to stop using applications that harness AI to generate personal portraits, saying they could pose security risks.
The post Philippine Military Ordered to Stop Using Artificial Intelligence Apps Due to Security Risks appeared first on SecurityWeek.
20 October 2023
Vietnamese cybercrime groups are targeting the digital marketing sectors in the United Kingdom, United States, and India with various malware strains, including the DarkGate information stealer.
20 October 2023
The Viking Line cyberattack, believed to be a DDoS attack, caused major disruptions to shipping company websites and emphasizes the urgent need for robust cybersecurity measures in the industry.
20 October 2023
According to an email security report, 233.9 million malicious emails were detected in Q3 2023. 150,000 emails displayed previously unknown behaviors.
20 October 2023
Using outdated software is the main reason for website compromise. In one case, an e-commerce store running on an old version of OpenCart led to credit card theft and fraud.
20 October 2023
The RagnarLocker ransomware group’s dark web leak site has been seized in a coordinated law enforcement operation.
The post Authorities Seize Control of RagnarLocker Ransomware Dark Web Site appeared first on SecurityWeek.
20 October 2023
Cybersecurity firm Spec has successfully closed a $15M Series A funding round led by SignalFire, with participation from Legion Capital and Rally Ventures, enabling the company to advance its platform and expand its threat labs.
20 October 2023
Silicon Valley fraud detection startup attracts $15 million in new financing from SignalFire, Legion Capital and Rally Ventures.
The post Fraud Detection Firm Spec Raises $15 Million appeared first on SecurityWeek.
20 October 2023
Cultivating a strong cybersecurity culture and empowering employees to make informed security decisions is crucial for SMBs to protect themselves and gain customer trust.
20 October 2023
The Play ransomware group has threatened Associated Wholesale Grocers (AWG) with a cyberattack, stating their intention to release sensitive data stolen from the firm on October 22, 2023.
20 October 2023
Details have emerged about a malvertising campaign that leverages Google Ads to direct users searching for popular software to fictitious landing pages and distribute next-stage payloads.
Malwarebytes, which discovered the activity, said it's "unique in its way to fingerprint users and distribute time sensitive payloads."
The attack singles out users searching for Notepad++ and PDF converters to
20 October 2023
Ransomware attacks can cost victim organizations millions of dollars, leading to significant financial and reputational damage, particularly for small and mid-sized businesses.
20 October 2023
Quishing involves circulating QR codes embedded with malicious links or malware downloads, while QRLJacking exploits the login with QR code feature to trick users into logging into fake websites and steal their sensitive data.
20 October 2023
Attacks leveraging the DarkGate commodity malware targeting entities in the U.K., the U.S., and India have been linked to Vietnamese actors associated with the use of the infamous Ducktail stealer.
"The overlap of tools and campaigns is very likely due to the effects of a cybercrime marketplace," WithSecure said in a report published today. "Threat actors are able to acquire and use multiple
20 October 2023
The U.S. Defense Department has received a report from the RAND Corporation on the creation of a new lead cyber policy chief. The report will inform decisions on the organizational structure and workforce of the new office.
20 October 2023
ExelaStealer, written in Python, is designed to capture sensitive data from compromised Windows systems. It can steal passwords, Discord tokens, credit card information, cookies, keystrokes, screenshots, and clipboard content. As this remains a prevalent threat, organizations are recommended to protect their critical assets and infrastructure with strong security measures.
20 October 2023
Iran-linked hacking group Crambus spent eight months inside a compromised network of a Middle Eastern government, Broadcom’s Symantec cybersecurity unit reports.
The post Iranian Hackers Lurked for 8 Months in Government Network appeared first on SecurityWeek.
20 October 2023
RagnarLocker, known for its double extortion tactic and refusal to negotiate ransom demands, has been a significant threat to critical infrastructure organizations, with 52 successful attacks reported.
20 October 2023
Due to the rapid evolution of technology, the Internet of Things (IoT) is changing the way business is conducted around the world. This advancement and the power of the IoT have been nothing short of transformational in making data-driven decisions, accelerating efficiencies, and streamlining operations to meet the demands of a competitive global marketplace.
IoT At a Crossroads
IoT, in its most
20 October 2023
The initial infection vector of ExelaStealer is not known, but it can be deployed through a decoy document and collects various data from infected systems, including screenshots and system information.