Latest Cybersecurity News and Articles


Cisco Devices Hacked via IOS XE Zero-Day Vulnerability

17 October 2023
Cisco is warning customers that a new IOS XE zero-day vulnerability tracked as CVE-2023-20198 is being exploited to hack devices.  The post Cisco Devices Hacked via IOS XE Zero-Day Vulnerability appeared first on SecurityWeek.

WordPress Websites Hacked via Royal Elementor Plugin Zero-Day

17 October 2023
A critical vulnerability in the Royal Elementor WordPress plugin has been exploited as a zero-day since August 30. The post WordPress Websites Hacked via Royal Elementor Plugin Zero-Day appeared first on SecurityWeek.

Void Rabisu Targets Women Political Leaders with New RomCom 4.0 Variant

17 October 2023
Void Rabisu has been found deploying the new RomCom 4.0 backdoor against participants of the Women Political Leaders (WPL) Summit in Brussels. According to researchers, the latest variant has undergone some significant changes in its architecture, making it lighter and stealthier. Organizations are advised to stay protected by staying updated on the RomCom attack trends and making use of the IoCs shared by Trend Micro.

UK Appoints Neal-Hopes as Commander of National Cyber Force

17 October 2023
Air Vice-Marshal Tim Neal-Hopes has been appointed as the new commander of the United Kingdom's National Cyber Force (NCF). He joins the NCF from Strategic Command, where he served as the director for cyber, intelligence, and information integration.

Hackers Exploit Critical Flaw in WordPress Royal Elementor Plugin

17 October 2023
The vendor has released a patch (version 1.3.79) to fix the flaw (CVE-2023-5360), and users are recommended to upgrade as soon as possible, but a website cleanup may be necessary to remove any infections or malicious files.

Signal Debunks Zero-Day Vulnerability Reports, Finds No Evidence

17 October 2023
The company conducted a thorough investigation and found no indication that the vulnerability is real. Signal also reached out to the US government, which provided no information to support the claim.

CISA, FBI, and MS-ISAC Warn of Threat Actors Exploiting Atlassian Confluence Flaw for Initial Access to Networks

17 October 2023
The recently disclosed flaw (CVE-2023-22515) in Atlassian Confluence Data Center and Server allows malicious actors to create unauthorized administrator accounts, leading to widespread exploitation and the need for immediate application of upgrades.

US Treasury Inks Cybersecurity Agreement With United Arab Emirates

17 October 2023
The agreement between the US and the UAE comes ahead of the International Counter Ransomware Initiative summit, where governments are expected to pledge not to pay ransoms to cybercriminals.

Unpatched Cisco Zero-Day Vulnerability Actively Targeted in the Wild

17 October 2023
The vulnerability affects enterprise networking gear with the Web UI feature enabled and exposed to the internet or untrusted networks, and it is recommended to disable the HTTP server feature as a mitigation.

CERT-UA Reports: 11 Ukrainian Telecom Providers Hit by Cyberattacks

17 October 2023
The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed that threat actors "interfered" with at least 11 telecommunication service providers in the country between May and September 2023. The agency is tracking the activity under the name UAC-0165, stating the intrusions led to service interruptions for customers. The starting point of the attacks is a reconnaissance phase in

Warning: Unpatched Cisco Zero-Day Vulnerability Actively Targeted in the Wild

17 October 2023
Cisco has warned of a critical, unpatched security flaw impacting IOS XE software that’s under active exploitation in the wild. Rooted in the web UI feature, the zero-day vulnerability is assigned as CVE-2023-20198 and has been assigned the maximum severity rating of 10.0 on the CVSS scoring system. It’s worth pointing out that the shortcoming only affects enterprise networking gear that have

Henry Schein announces data breach

16 October 2023
Henry Schein announced that a part of the company's manufacturing and distribution business suffered a data breach on October 14, 2023.

Dozens of Squid Proxy Vulnerabilities Remain Unpatched Two Years After Disclosure

16 October 2023
Dozens of vulnerabilities in the Squid caching and forwarding web proxy, a widely used open-source proxy, remain unpatched two years after being discovered by researcher Joshua Rogers.

Data privacy among top concerns for workplace generative AI use

16 October 2023
Generative artificial intelligence use within the workplace was analyzed in a recent report, finding 9% of organizations feel prepared for the threat.

EPA Withdraws Water Sector Cybersecurity Rules Due to Lawsuits

16 October 2023
The US EPA has withdrawn cybersecurity rules for public water systems due to lawsuits filed by states and non-profit water associations, citing concerns about financial burden and cybersecurity vulnerabilities.

Milesight Industrial Router Vulnerability Possibly Exploited in Attacks

16 October 2023
The vulnerability exposes system log files containing passwords, which can be used by attackers to gain unauthorized access. Security firm VulnCheck discovered evidence of small-scale exploitation of the vulnerability.

Fake ‘RedAlert’ Rocket Alert App for Israel Installs Android Spyware

16 October 2023
Users should carefully review app permissions and ensure they are using the latest version of the app to minimize the risk of being targeted by spyware or fake notifications.

Pro-Russian Hackers Exploiting Recent WinRAR Vulnerability in New Campaign

16 October 2023
The attackers exploit a recent flaw in WinRAR to execute malicious code and gain remote access to compromised systems. They also use a PowerShell script to steal data, including login credentials, from Google Chrome and Microsoft Edge browsers.

92% of business plan to move to passwordless technology

16 October 2023
A recent report found that 55% of IT leaders surveyed feel they need more education on how passwordless technology works and/or how to deploy it.

Update: LockBit Ransomware Gang Demanded an $80 Million Ransom From CDW

16 October 2023
The ransomware group demanded an $80 million ransom, but CDW only offered $1 million. CDW states that the affected servers are isolated and not customer-facing, and its systems remain fully operational.