Latest Cybersecurity News and Articles


The Fake Browser Update Scam Gets a Makeover

18 October 2023
One of the oldest malware tricks in the book -- hacked websites claiming visitors need to update their Web browser before they can view any content -- has roared back to life in the past few months. New research shows the attackers behind one such scheme have developed an ingenious way of keeping their malware from being taken down by security experts or law enforcement: By hosting the malicious files on a decentralized, anonymous cryptocurrency blockchain.

Amazon Adds Passkey Support as New Passwordless Login Option

18 October 2023
Amazon has added passkey support as a passwordless login option, offering better protection against malware and phishing attacks. Passkeys make it easier for users to log in without the need for password managers or memorizing passwords.

Chilean Government Warns of Black Basta Ransomware Attacks After Customs Incident

18 October 2023
The country's Computer Security Incident Response Team (CSIRT) confirmed the attack and urged all government agencies to take preventive measures, such as protecting backup copies of systems and limiting administrative permissions.

D-Link Says Hacker Exaggerated Data Breach Claims

18 October 2023
Hacker claims to have breached D-Link’s network in Taiwan and is offering to sell stolen data, but the company says the claims are exaggerated. The post D-Link Says Hacker Exaggerated Data Breach Claims appeared first on SecurityWeek.

ClearFake Enters the Fake Browser Update Arena to Deliver Malware

18 October 2023
SEKOIA identified a threat called ClearFake that uses compromised WordPress sites to distribute malicious fake browser updates. This threat is likely operated by the same group behind SocGholish. It is to be noted that SocGholish operators had successfully leveraged this technique in 2022, which indicates that the same threat group is likely behind the new ClearFake malware. The IOCs associated with the threat have been made available to understand attackers’ infrastructure, attack pattern, and their activities.

D-Link Confirms Data Breach: Employee Falls Victim to Phishing Attack

18 October 2023
The breach occurred through an old D-View 6 system that reached its end of life in 2015. The compromised data was used for registration purposes and does not contain user IDs or financial information.

Critical Citrix NetScaler Flaw Exploited to Target from Government, Tech Firms

18 October 2023
Citrix is warning of exploitation of a recently disclosed critical security flaw in NetScaler ADC and Gateway appliances that could result in exposure of sensitive information. Tracked as CVE-2023-4966 (CVSS score: 9.4), the vulnerability impacts the following supported versions - NetScaler ADC and NetScaler Gateway 14.1 before 14.1-8.50 NetScaler ADC and NetScaler Gateway 13.1 before

FBI Warns of Extortion Groups Targeting Plastic Surgery Offices

18 October 2023
The FBI has issued a warning about cybercriminals targeting plastic surgery offices through phishing attacks. These attackers gain access to the networks and steal sensitive data, including personal information and medical records.

Fraud Prevention Firm Fingerprint Raises $33 Million

18 October 2023
Fingerprint has raised $33 million in a Series C funding round to expand presence into the enterprise market. The post Fraud Prevention Firm Fingerprint Raises $33 Million appeared first on SecurityWeek.

Qubitstrike Targets Jupyter Notebooks with Crypto Mining and Rootkit Campaign

18 October 2023
A threat actor, presumably from Tunisia, has been linked to a new campaign targeting exposed Jupyter Notebooks in a two-fold attempt to illicitly mine cryptocurrency and breach cloud environments. Dubbed Qubitstrike by Cado, the intrusion set utilizes Telegram API to exfiltrate cloud service provider credentials following a successful compromise. "The payloads for the Qubitstrike campaign are

Unraveling Real-Life Attack Paths – Key Lessons Learned

18 October 2023
In the ever-evolving landscape of cybersecurity, attackers are always searching for vulnerabilities and exploits within organizational environments. They don't just target single weaknesses; they're on the hunt for combinations of exposures and attack methods that can lead them to their desired objective. Despite the presence of numerous security tools, organizations often have to deal with two

Report: Only a Third of Organizations Prepared to Comply with NIS2 Directive

18 October 2023
Just 34% of organizations in the UK, France, and Germany are prepared for the EU's updated Network and Information Security Directive (NIS2), according to a survey by cybersecurity firm Sailpoint.

BLOODALCHEMY Provides Backdoor to Southeast Asian Nations' Secrets

18 October 2023
Security researchers have discovered a backdoor called BLOODALCHEMY that is part of the REF5961 intrusion set, believed to be linked to a group with ties to China, targeting governments and organizations in the ASEAN region.

Oracle Patches 185 Vulnerabilities With October 2023 CPU

18 October 2023
Oracle on Tuesday released 387 new security patches that address 185 vulnerabilities in its code and third-party components. The post Oracle Patches 185 Vulnerabilities With October 2023 CPU appeared first on SecurityWeek.

Lost and Stolen Devices: A Gateway to Data Breaches and Leaks

18 October 2023
By implementing strong security practices,, organizations can significantly reduce the risks associated with lost and stolen computers and safeguard their sensitive information. The post Lost and Stolen Devices: A Gateway to Data Breaches and Leaks appeared first on SecurityWeek.

Federal Agencies are Falling Behind on Meeting Key Privacy Goal Set Five Years Ago

18 October 2023
The slow progress in implementing privacy requirements and the lack of resources and guidance for emerging technologies pose significant challenges for the government in addressing privacy risks.

Cybersecurity M&A Roundup for First Half of October 2023

18 October 2023
More than a dozen cybersecurity-related M&A deals were announced in the first half of October 2023. The post Cybersecurity M&A Roundup for First Half of October 2023 appeared first on SecurityWeek.

Malvertising Campaign Uses Fake Notepad++ Ads on Google

18 October 2023
The campaign involves malicious ads that redirect users to a fake Notepad++ website, where a system fingerprinting process takes place. If the user passes the checks, they are assigned a unique ID and given a time-sensitive download link.

Recent NetScaler Vulnerability Exploited as Zero-Day Since August

18 October 2023
Mandiant says the recently patched Citrix NetScaler vulnerability CVE-2023-4966 had been exploited as zero-day since August. The post Recent NetScaler Vulnerability Exploited as Zero-Day Since August appeared first on SecurityWeek.

Tens of Thousands of Cisco Devices Hacked via Zero-Day Vulnerability

18 October 2023
Tens of thousands of Cisco devices have reportedly been hacked via the exploitation of the zero-day vulnerability CVE-2023-20198. The post Tens of Thousands of Cisco Devices Hacked via Zero-Day Vulnerability appeared first on SecurityWeek.