Latest Cybersecurity News and Articles


Update: 23andMe Scraping Incident Leaked Data on 1.3 Million Users of Ashkenazi and Chinese Descent

10 October 2023
23andMe initially denied the legitimacy of the data but later acknowledged that unauthorized access to individual accounts may have occurred, highlighting the vulnerability of customer data even without deep network breaches.

North Korea-Linked Lazarus APT Laundered Over $900 Million Through Cross-Chain Crime

10 October 2023
The use of cross-chain bridges and asset-hopping typologies have contributed to a significant increase in funds sent via such services, making it a recognized money laundering typology.

libcue Library Flaw Opens GNOME Linux Systems Vulnerable to RCE Attacks

10 October 2023
A new security flaw has been disclosed in the libcue library impacting GNOME Linux systems that could be exploited to achieve remote code execution (RCE) on affected hosts. Tracked as CVE-2023-43641 (CVSS score: 8.8), the issue is described as a case of memory corruption in libcue, a library designed for parsing cue sheet files. It impacts versions 2.2.1 and prior. libcue is incorporated into

Citrix Devices Under Attack: NetScaler Flaw Exploited to Capture User Credentials

10 October 2023
A recently disclosed critical flaw in Citrix NetScaler ADC and Gateway devices is being exploited by threat actors to conduct a credential harvesting campaign. IBM X-Force, which uncovered the activity last month, said adversaries exploited "CVE-2023-3519 to attack unpatched NetScaler Gateways to insert a malicious script into the HTML content of the authentication web page to capture user

The evolving cyber threat landscape

10 October 2023
Common targets of cyberattacks in Q2 2023

Phishers Spoof USPS, 12 Other Natl’ Postal Services

09 October 2023
Recent weeks have seen a sizable uptick in the number of phishing scams targeting U.S. Postal Service (USPS) customers. Here's a look at an extensive SMS phishing operation that tries to steal personal and financial data by spoofing the USPS, as well as postal services in at least a dozen other countries worldwide.

FTC finds that social media scams lead to more losses than other scams

09 October 2023
The Federal Trade Commission (FTC) released data finding that social media-based scams account for more losses than any other contact method. 

Latest Balada Injector Campaign Targets Unpatched tagDiv Plugin

09 October 2023
A group of experts noted a rapid evolution in Balada Injector's infrastructure and attack methods, which resulted in a significant number of compromised WordPress sites. Balada malware injection attacks have been found exploiting a vulnerable tagDiv premium theme plugin to target Newspaper and Newsmag websites. It is recommended to remove all unwanted admin users and redundant plugins to stay safe.

Ahmed Fessi joins Medius as Chief Transformation & Information Officer

09 October 2023
Ahmed Fessi was hired as Chief Transformation & Information Officer at Medius. Fessi brings 15 years' of experience with AI, data and cybersecurity.

PEACHPIT: Massive Ad Fraud Botnet Powered by Millions of Hacked Android and iOS

09 October 2023
An ad fraud botnet dubbed PEACHPIT leveraged an army of hundreds of thousands of Android and iOS devices to generate illicit profits for the threat actors behind the scheme. The botnet is part of a larger China-based operation codenamed BADBOX, which also entails selling off-brand mobile and connected TV (CTV) devices on popular online retailers and resale sites that are backdoored with an 

MGM Resorts cyberattack cost could exceed $100M

09 October 2023
In a filing with the Securities and Exchange Commission, MGM Resorts reported that a recent cyberattack is expected to cost the company an estimated $100 million.

MGM Resort cyberattack cost could exceed $100M

09 October 2023
In a filing with the Securities and Exchange Commission, MGM Resorts reported that a recent cyberattack is expected to cost the company an estimated $100 million.

AI's role in future advanced social engineering attacks

09 October 2023
The combination of AI's adaptive algorithms and data processing capabilities has empowered mal actors to develop complex social engineering attacks.

Recently Patched TagDiv Plugin Flaw Exploited to Hack Thousands of WordPress Sites

09 October 2023
Recently patched TagDiv Composer plugin vulnerability exploited to hack thousands of WordPress sites as part of the Balada Injector campaign. The post Recently Patched TagDiv Plugin Flaw Exploited to Hack Thousands of WordPress Sites appeared first on SecurityWeek.

Multiple Hacker Groups Join in on Israel-Hamas War With Disruptive Cyberattacks

09 October 2023
Various hacker groups from around the world, including Ghosts of Palestine and Garuna, have joined the cyber conflict, targeting private and public infrastructure in Israel and the Palestinian territories.

High-Severity Flaws in ConnectedIO's 3G/4G Routers Raise Concerns for IoT Security

09 October 2023
The flaws in 3G/4G routers could expose internal networks to severe threats, enabling attackers to intercept traffic, seize control, and infiltrate Extended Internet of Things (XIoT) devices.

Credential Harvesting Campaign Targets Unpatched NetScaler Instances

09 October 2023
Threat actors are targeting Citrix NetScaler instances unpatched against CVE-2023-3519 to steal user credentials. The post Credential Harvesting Campaign Targets Unpatched NetScaler Instances appeared first on SecurityWeek.

Security Patch for Two New Flaws in Curl Library Arriving on October 11

09 October 2023
Organizations are advised to inventory and scan all systems using Curl and libcurl to identify potentially vulnerable versions once the details are released with the new version 8.4.0 on October 11.

Amazon Prime Email Scammer Snatches Defeat From the Jaws of Victory

09 October 2023
Researchers discovered a failed phishing attempt through a spam email. The email claimed to be from Amazon, stating that the recipient's Prime benefits were on hold due to a billing issue.

Cybercriminals Using EvilProxy Phishing Kit to Target Senior Executives in U.S. Firms

09 October 2023
Senior executives working in U.S.-based organizations are being targeted by a new phishing campaign that leverages a popular adversary-in-the-middle (AiTM) phishing toolkit named EvilProxy to conduct credential harvesting and account takeover attacks. Menlo Security said the activity started in July 2023, primarily singling out banking and financial services, insurance, property management and