Latest Cybersecurity News and Articles
10 October 2023
23andMe initially denied the legitimacy of the data but later acknowledged that unauthorized access to individual accounts may have occurred, highlighting the vulnerability of customer data even without deep network breaches.
10 October 2023
The use of cross-chain bridges and asset-hopping typologies have contributed to a significant increase in funds sent via such services, making it a recognized money laundering typology.
10 October 2023
A new security flaw has been disclosed in the libcue library impacting GNOME Linux systems that could be exploited to achieve remote code execution (RCE) on affected hosts.
Tracked as CVE-2023-43641 (CVSS score: 8.8), the issue is described as a case of memory corruption in libcue, a library designed for parsing cue sheet files. It impacts versions 2.2.1 and prior.
libcue is incorporated into
10 October 2023
A recently disclosed critical flaw in Citrix NetScaler ADC and Gateway devices is being exploited by threat actors to conduct a credential harvesting campaign.
IBM X-Force, which uncovered the activity last month, said adversaries exploited "CVE-2023-3519 to attack unpatched NetScaler Gateways to insert a malicious script into the HTML content of the authentication web page to capture user
10 October 2023
Common targets of cyberattacks in Q2 2023
09 October 2023
Recent weeks have seen a sizable uptick in the number of phishing scams targeting U.S. Postal Service (USPS) customers. Here's a look at an extensive SMS phishing operation that tries to steal personal and financial data by spoofing the USPS, as well as postal services in at least a dozen other countries worldwide.
09 October 2023
The Federal Trade Commission (FTC) released data finding that social media-based scams account for more losses than any other contact method.
09 October 2023
A group of experts noted a rapid evolution in Balada Injector's infrastructure and attack methods, which resulted in a significant number of compromised WordPress sites. Balada malware injection attacks have been found exploiting a vulnerable tagDiv premium theme plugin to target Newspaper and Newsmag websites. It is recommended to remove all unwanted admin users and redundant plugins to stay safe.
09 October 2023
Ahmed Fessi was hired as Chief Transformation & Information Officer at Medius. Fessi brings 15 years' of experience with AI, data and cybersecurity.
09 October 2023
An ad fraud botnet dubbed PEACHPIT leveraged an army of hundreds of thousands of Android and iOS devices to generate illicit profits for the threat actors behind the scheme.
The botnet is part of a larger China-based operation codenamed BADBOX, which also entails selling off-brand mobile and connected TV (CTV) devices on popular online retailers and resale sites that are backdoored with an
09 October 2023
In a filing with the Securities and Exchange Commission, MGM Resorts reported that a recent cyberattack is expected to cost the company an estimated $100 million.
09 October 2023
In a filing with the Securities and Exchange Commission, MGM Resorts reported that a recent cyberattack is expected to cost the company an estimated $100 million.
09 October 2023
The combination of AI's adaptive algorithms and data processing capabilities has empowered mal actors to develop complex social engineering attacks.
09 October 2023
Recently patched TagDiv Composer plugin vulnerability exploited to hack thousands of WordPress sites as part of the Balada Injector campaign.
The post Recently Patched TagDiv Plugin Flaw Exploited to Hack Thousands of WordPress Sites appeared first on SecurityWeek.
09 October 2023
Various hacker groups from around the world, including Ghosts of Palestine and Garuna, have joined the cyber conflict, targeting private and public infrastructure in Israel and the Palestinian territories.
09 October 2023
The flaws in 3G/4G routers could expose internal networks to severe threats, enabling attackers to intercept traffic, seize control, and infiltrate Extended Internet of Things (XIoT) devices.
09 October 2023
Threat actors are targeting Citrix NetScaler instances unpatched against CVE-2023-3519 to steal user credentials.
The post Credential Harvesting Campaign Targets Unpatched NetScaler Instances appeared first on SecurityWeek.
09 October 2023
Organizations are advised to inventory and scan all systems using Curl and libcurl to identify potentially vulnerable versions once the details are released with the new version 8.4.0 on October 11.
09 October 2023
Researchers discovered a failed phishing attempt through a spam email. The email claimed to be from Amazon, stating that the recipient's Prime benefits were on hold due to a billing issue.
09 October 2023
Senior executives working in U.S.-based organizations are being targeted by a new phishing campaign that leverages a popular adversary-in-the-middle (AiTM) phishing toolkit named EvilProxy to conduct credential harvesting and account takeover attacks.
Menlo Security said the activity started in July 2023, primarily singling out banking and financial services, insurance, property management and