Latest Cybersecurity News and Articles
18 October 2023
One of the oldest malware tricks in the book -- hacked websites claiming visitors need to update their Web browser before they can view any content -- has roared back to life in the past few months. New research shows the attackers behind one such scheme have developed an ingenious way of keeping their malware from being taken down by security experts or law enforcement: By hosting the malicious files on a decentralized, anonymous cryptocurrency blockchain.
18 October 2023
Amazon has added passkey support as a passwordless login option, offering better protection against malware and phishing attacks. Passkeys make it easier for users to log in without the need for password managers or memorizing passwords.
18 October 2023
The country's Computer Security Incident Response Team (CSIRT) confirmed the attack and urged all government agencies to take preventive measures, such as protecting backup copies of systems and limiting administrative permissions.
18 October 2023
Hacker claims to have breached D-Link’s network in Taiwan and is offering to sell stolen data, but the company says the claims are exaggerated.
The post D-Link Says Hacker Exaggerated Data Breach Claims appeared first on SecurityWeek.
18 October 2023
SEKOIA identified a threat called ClearFake that uses compromised WordPress sites to distribute malicious fake browser updates. This threat is likely operated by the same group behind SocGholish. It is to be noted that SocGholish operators had successfully leveraged this technique in 2022, which indicates that the same threat group is likely behind the new ClearFake malware. The IOCs associated with the threat have been made available to understand attackers’ infrastructure, attack pattern, and their activities.
18 October 2023
The breach occurred through an old D-View 6 system that reached its end of life in 2015. The compromised data was used for registration purposes and does not contain user IDs or financial information.
18 October 2023
Citrix is warning of exploitation of a recently disclosed critical security flaw in NetScaler ADC and Gateway appliances that could result in exposure of sensitive information.
Tracked as CVE-2023-4966 (CVSS score: 9.4), the vulnerability impacts the following supported versions -
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-8.50
NetScaler ADC and NetScaler Gateway 13.1 before
18 October 2023
The FBI has issued a warning about cybercriminals targeting plastic surgery offices through phishing attacks. These attackers gain access to the networks and steal sensitive data, including personal information and medical records.
18 October 2023
Fingerprint has raised $33 million in a Series C funding round to expand presence into the enterprise market.
The post Fraud Prevention Firm Fingerprint Raises $33 Million appeared first on SecurityWeek.
18 October 2023
A threat actor, presumably from Tunisia, has been linked to a new campaign targeting exposed Jupyter Notebooks in a two-fold attempt to illicitly mine cryptocurrency and breach cloud environments.
Dubbed Qubitstrike by Cado, the intrusion set utilizes Telegram API to exfiltrate cloud service provider credentials following a successful compromise.
"The payloads for the Qubitstrike campaign are
18 October 2023
In the ever-evolving landscape of cybersecurity, attackers are always searching for vulnerabilities and exploits within organizational environments. They don't just target single weaknesses; they're on the hunt for combinations of exposures and attack methods that can lead them to their desired objective.
Despite the presence of numerous security tools, organizations often have to deal with two
18 October 2023
Just 34% of organizations in the UK, France, and Germany are prepared for the EU's updated Network and Information Security Directive (NIS2), according to a survey by cybersecurity firm Sailpoint.
18 October 2023
Security researchers have discovered a backdoor called BLOODALCHEMY that is part of the REF5961 intrusion set, believed to be linked to a group with ties to China, targeting governments and organizations in the ASEAN region.
18 October 2023
Oracle on Tuesday released 387 new security patches that address 185 vulnerabilities in its code and third-party components.
The post Oracle Patches 185 Vulnerabilities With October 2023 CPU appeared first on SecurityWeek.
18 October 2023
By implementing strong security practices,, organizations can significantly reduce the risks associated with lost and stolen computers and safeguard their sensitive information.
The post Lost and Stolen Devices: A Gateway to Data Breaches and Leaks appeared first on SecurityWeek.
18 October 2023
The slow progress in implementing privacy requirements and the lack of resources and guidance for emerging technologies pose significant challenges for the government in addressing privacy risks.
18 October 2023
More than a dozen cybersecurity-related M&A deals were announced in the first half of October 2023.
The post Cybersecurity M&A Roundup for First Half of October 2023 appeared first on SecurityWeek.
18 October 2023
The campaign involves malicious ads that redirect users to a fake Notepad++ website, where a system fingerprinting process takes place. If the user passes the checks, they are assigned a unique ID and given a time-sensitive download link.
18 October 2023
Mandiant says the recently patched Citrix NetScaler vulnerability CVE-2023-4966 had been exploited as zero-day since August.
The post Recent NetScaler Vulnerability Exploited as Zero-Day Since August appeared first on SecurityWeek.
18 October 2023
Tens of thousands of Cisco devices have reportedly been hacked via the exploitation of the zero-day vulnerability CVE-2023-20198.
The post Tens of Thousands of Cisco Devices Hacked via Zero-Day Vulnerability appeared first on SecurityWeek.