Latest Cybersecurity News and Articles


Canadian organizations unprepared for AI-driven cyber threats

06 October 2023
A new survey reveals that Canadian organizations are unprepared to handle and recover from new cyber threats including artificial intelligence.

TA505 Hacker Group Deploys Sneaky RMS Tool in Phishing Campaign

06 October 2023
The attackers are using a Remote Management System (RMS) executable to trick victims into downloading malware disguised as banned applications like ExpressVPN, WeChat, and Skype.

Data Breach at Melbourne’s Royal Women’s Hospital Puts Patient Information at Risk

06 October 2023
The Royal Women's Hospital in Melbourne has experienced a data breach, potentially compromising the personal information of 192 patients. The breach occurred when cybercriminals gained unauthorized access to a staff member's private email account.

Qakbot-Affiliated Actors Distribute Ransom Knight Malware Despite Infrastructure Takedown

06 October 2023
Qakbot malware operators have continued their malicious activities, distributing Ransom Knight ransomware and the Remcos backdoor via phishing emails, despite the recent infrastructure takedown.

Study: 37% intimidated, 39% frustrated with online security

06 October 2023
A new survey reveals 39% of participants express frustration and 37% feel intimidated by the process of staying secure online.

Microsoft Releases New Report on Cybercrime, State-Sponsored Cyber Operations

06 October 2023
US, Ukraine, and Israel remain the most heavily attacked by cyberespionage and cybercrime threat actors, Microsoft says. The post Microsoft Releases New Report on Cybercrime, State-Sponsored Cyber Operations appeared first on SecurityWeek.

GoldDigger: New Android Trojan Targeting Dozens of Vietnamese Banks

06 October 2023
Researchers have discovered a new Android Trojan called GoldDigger that can primarily target users of over 50 Vietnamese banking apps, as well as e-wallets and crypto-wallets. GoldDigger's reach may extend beyond Vietnam. Countering them demands client-side fraud protection solutions that emphasize real-time protection, adaptability, and a focus on behavioral indicators.

Nonprofit Service Provider Blackbaud Settles Data Breach Case for $49.5M With States

06 October 2023
The breach involved health information, Social Security numbers, and financial data of donors and clients, prompting Blackbaud to pay a ransom to the intruder in exchange for deleting the stolen data.

Commerical Construction Insurer Builders Mutual Discloses Data Breach

06 October 2023
Builders Mutual Insurance Co. experienced a data breach that compromised the personal information of over 64,000 customers and employees, including sensitive data like Social Security numbers and medical information.

Chinese Hackers Target Semiconductor Firms in East Asia with Cobalt Strike

06 October 2023
Threat actors have been observed targeting semiconductor companies in East Asia with lures masquerading as Taiwan Semiconductor Manufacturing Company (TSMC) that are designed to deliver Cobalt Strike beacons. The intrusion set, per EclecticIQ, leverages a backdoor called HyperBro, which is then used as a conduit to deploy the commercial attack simulation software and post-exploitation toolkit.

CISA Pivots Focus to China-Linked Threats Against Critical Infrastructure

06 October 2023
The CISA is focusing on the growing threat activity from China, which has become the top nation-state cyber adversary to the U.S., particularly targeting critical infrastructure like rail transportation and energy sectors.

In Other News: Funding Increase, Abuse of Smartphone Location Data, Legal Matters

06 October 2023
Noteworthy stories that might have slipped under the radar: cybersecurity funding increases, new laws, and government’s illegal use of smartphone location data. The post In Other News: Funding Increase, Abuse of Smartphone Location Data, Legal Matters appeared first on SecurityWeek.

Privacy Nonprofit Calls on FTC To Investigate Grindr’s Data Practices

06 October 2023
The Electronic Privacy Information Center (EPIC) has filed a complaint urging the FTC to investigate Grindr for potentially illegally storing and disclosing users' sensitive data, including HIV and vaccination status.

Organizations Warned of Top 10 Cybersecurity Misconfigurations Seen by CISA, NSA

06 October 2023
CISA and the NSA are urging network defenders and software developers to address the top ten cybersecurity misconfigurations. The post Organizations Warned of Top 10 Cybersecurity Misconfigurations Seen by CISA, NSA appeared first on SecurityWeek.

Nonprofit Service Provider Blackbaud Settles Data Breach Case for $49.5M With States

06 October 2023
The fundraising software company Blackbaud has agreed to pay $49.5 million to settle claims brought by the attorneys general of 49 states and Washington, D.C., related to a 2020 data breach. The post Nonprofit Service Provider Blackbaud Settles Data Breach Case for $49.5M With States appeared first on SecurityWeek.

Lorenz Ransomware Embroiled in its Own Two-Year Data Leak

06 October 2023
The leaked data from a misconfigured web server includes names, email addresses, and subject lines of individuals who sought information from Lorenz, spanning from June 2021 to September 2023.

New OS Tool Tells You Who Has Access to What Data

06 October 2023
Ensuring sensitive data remains confidential, protected from unauthorized access, and compliant with data privacy regulations is paramount. Data breaches result in financial and reputational damage but also lead to legal consequences. Therefore, robust data access security measures are essential to safeguard an organization’s assets, maintain customer trust, and meet regulatory requirements.  A

Factors Leading to Organizations Losing Control Over IT and Security Environments

06 October 2023
IT and security teams are facing new responsibilities, such as ensuring security for remote and hybrid workers, managing applications in public cloud environments, and securing data in SaaS environments.

CISA Reverses Course on Malicious Exploitation of Video Conferencing Device Flaws

06 October 2023
CISA has removed from its KEV catalog five Owl Labs video conferencing flaws that require the attacker to be in Bluetooth range. The post CISA Reverses Course on Malicious Exploitation of Video Conferencing Device Flaws appeared first on SecurityWeek.

CISA Warns of Active Exploitation of JetBrains and Windows Vulnerabilities

06 October 2023
The authentication bypass vulnerability in JetBrains TeamCity has already seen exploitation attempts from 74 unique IP addresses, while the privilege escalation flaw in Microsoft Windows CNG Key Isolation Service has no documented exploitation.