Latest Cybersecurity News and Articles


Multiple Cybercrime Groups Join in on the Israel-Hamas Conflict

12 October 2023
Amid the Israeli-Palestinian conflict, cybercriminals from both sides have turned to cyberattacks in the form of distributed DDoS and also targeting bugs in ICS and SCADA systems. Several Israeli and Palestine organizations have left their Modbus, a SCADA communications protocol, exposed. To mitigate these threats, entities should bolster their security measures, focusing on patching exposed SCADA systems and ensuring stringent access controls for critical communication protocols.

LinkedIn Smart Links Abused in Phishing Campaign Targeting Microsoft Accounts

12 October 2023
A recently observed phishing campaign targeting Microsoft accounts is using LinkedIn smart links to bypass defenses. The post LinkedIn Smart Links Abused in Phishing Campaign Targeting Microsoft Accounts appeared first on SecurityWeek.

Endpoint Malware Attacks Decline as Campaigns Spread Wider

12 October 2023
As per a recent report by WatchGuard, in Q2 2023, 95% of malware is delivered through encrypted connections, highlighting the importance of inspecting SSL/TLS traffic to detect hidden threats.

'Stayin’ Alive' Campaign Targets Telecom Companies and Government Ministries in Asia

12 October 2023
The main tool used in the campaign is a backdoor called CurKeep, which collects information about infected machines and allows remote control. The campaign also utilizes other loaders and downloaders, all connected to the same infrastructure.

ShellBot Uses Hex IPs to Evade Detection in Attacks on Linux SSH Servers

12 October 2023
The threat actors behind ShellBot are leveraging IP addresses transformed into its hexadecimal notation to infiltrate poorly managed Linux SSH servers and deploy the DDoS malware. "The overall flow remains the same, but the download URL used by the threat actor to install ShellBot has changed from a regular IP address to a hexadecimal value," the AhnLab Security Emergency response Center (ASEC)

Unpatched Vulnerabilities Expose Yifan Industrial Routers to Attacks

12 October 2023
Industrial routers made by Chinese company Yifan are affected by several critical vulnerabilities that can expose organizations to attacks.  The post Unpatched Vulnerabilities Expose Yifan Industrial Routers to Attacks appeared first on SecurityWeek.

CISO Pay Increases Are Slowing – a Look Behind the Figures

12 October 2023
How much do CISOs make? Survey provides compensation trends for Chief Information Security Officers, but don't take surveys at full face value. The post CISO Pay Increases Are Slowing – a Look Behind the Figures appeared first on SecurityWeek.

Knight Ransomware Group Takes Responsibility for Cyberattack on India's National Health Mission

12 October 2023
The Knight ransomware group has openly claimed responsibility for the recent cyberattack on India's National Health Mission. The group shared screenshots of the attack on their dark web site.

LinkedIn Smart Links Fuel Credential Phishing Campaign

12 October 2023
This recent phishing campaign targeted various industries, with the finance sector being the primary target, and highlights the importance of employee training to combat phishing attacks.

How to Guard Your Data from Exposure in ChatGPT

12 October 2023
ChatGPT has transformed the way businesses generate textual content, which can potentially result in a quantum leap in productivity. However, Generative AI innovation also introduces a new dimension of data exposure risk, when employees inadvertently type or paste sensitive business data into ChatGPT, or similar applications. DLP solutions, the go-to solution for similar challenges, are

Microsoft Defender Thwarts Large-Scale Akira Ransomware Attack

12 October 2023
Microsoft on Wednesday said that a user containment feature in Microsoft Defender for Endpoint helped thwart a "large-scale remote encryption attempt" made by Akira ransomware actors targeting an unknown industrial organization in early June 2023. The tech giant's threat intelligence team is tracking the operator as Storm-1567. The attack leveraged devices that were not onboarded to Microsoft

Simpson Manufacturing Takes Systems Offline Following Cyberattack

12 October 2023
Simpson Manufacturing is experiencing disruptions after taking IT systems offline following a cyberattack. The post Simpson Manufacturing Takes Systems Offline Following Cyberattack appeared first on SecurityWeek.

Savvy Israel-Linked Hacking Group Reemerges Amid Gaza Fighting

12 October 2023
The reemergence of the hacking group Predatory Sparrow, believed to have links to the Israeli government, highlights the potential role of cyber operations in the ongoing conflict between Israel and Hamas.

SYN Ventures Announces $75 Million Seed Fund for US Cybersecurity Firms

12 October 2023
Venture capital firm SYN Ventures announces first closing of $75 million cybersecurity seed fund for US cybersecurity companies. The post SYN Ventures Announces $75 Million Seed Fund for US Cybersecurity Firms appeared first on SecurityWeek.

D-Link WiFi Range Extender Vulnerable to Command Injection Attacks

12 October 2023
Owners of the D-Link DAP-X1860 extender should limit manual network scans, be cautious of sudden disconnections, and consider isolating IoT devices and range extenders from sensitive devices.

AnonGhost Hackers Send Fake Nuclear Attack Warning via Israeli Red Alert App

12 October 2023
The hackers found a way to spam users of the app and claimed their attack left users' phones disconnected from the internet and broken. While the hack caused concern, it is unlikely that it actually damaged users' devices.

Researchers Uncover Malware Posing as WordPress Caching Plugin

12 October 2023
Cybersecurity researchers have shed light on a new sophisticated strain of malware that masquerades a WordPress plugin to stealthily create administrator accounts and remotely control a compromised site. "Complete with a professional looking opening comment implying it is a caching plugin, this rogue code contains numerous functions, adds filters to prevent itself from being included in the list

Threat Actor Deploys Athena Agent in Advanced Spear Phishing Attack

12 October 2023
The Athena Agent, part of the Mythic C2 framework, is a cross-platform tool with diverse functionalities, making it highly valuable for threat actors seeking to gain control over compromised systems.

Cyber Investments Aim to Paint Broader View of Digital Threats, Official Says

12 October 2023
The federal government is investing in the infrastructure to improve collaboration and data sharing with the private sector in order to strengthen the nation's digital infrastructure against cyber threats.

Half of CISOs Now Report to CEO as Influence Grows

12 October 2023
According to a Splunk report, nearly half (47%) of global CISOs now report to their CEO, and the vast majority (78%) are backed by a board-level cybersecurity committee, signaling the growing influence of cyber risk management in organizations.