Latest Cybersecurity News and Articles


Cybersecurity Preparedness Pays Big Dividends for Businesses

06 October 2023
Businesses are investing more in cybersecurity resources and training, resulting in a decrease in phishing links clicked by workers and ransomware attacks, according to GetApp.

Analysis and Config Extraction of Lu0Bot, a Node.js Malware with Considerable Capabilities

06 October 2023
The Node.js malware Lu0Bot uses unconventional programming languages and multi-layer obfuscation. Lu0Bot utilizes a unique approach to domain connection and assembles various parts into a single entity within the JavaScript code.

GitHub's Secret Scanning Feature Now Covers AWS, Microsoft, Google, and Slack

06 October 2023
GitHub has announced an improvement to its secret scanning feature that extends validity checks to popular services such as Amazon Web Services (AWS), Microsoft, Google, and Slack. Validity checks, introduced by the Microsoft subsidiary earlier this year, alert users whether exposed tokens found by secret scanning are active, thereby allowing for effective remediation measures. It was first

Update: Clorox Warns of Quarterly Loss Related to August Cyberattack, Production Delays

06 October 2023
Clorox anticipates continued operational strain in the second quarter but hopes to benefit from restocking retailer inventory, while assessing the long-term impact on earnings.

Malware-Infected Devices Sold Through Major Retailers

06 October 2023
The scheme, known as BADBOX, deploys the Triada malware as a "backdoor" on various devices such as CTV boxes, smartphones, and tablets during the supply chain process in China.

Update: Cyberattack Against Johnson Controls Sparks Downstream Concerns

06 October 2023
The Department of Homeland Security is investigating the attack to determine if sensitive physical security information was compromised, but it was not a breach of any DHS network or system.

Researchers Warn of 100,000 Industrial Control Systems Exposed Online

06 October 2023
The United States, Canada, and Italy are the countries with the highest number of organizations with exposed ICSs, while sectors such as Education, Technology, and Government show the least secure ICS security.

Supermicro's BMC Firmware Found Vulnerable to Multiple Critical Vulnerabilities

06 October 2023
Multiple security vulnerabilities have been disclosed in the Intelligent Platform Management Interface (IPMI) firmware for Supermicro baseboard management controllers (BMCs) that could result in privilege escalation and execution of malicious code on affected systems. The seven flaws, tracked from CVE-2023-40284 through CVE-2023-40290, vary in severity from High to Critical, according to Binarly

Cisco Plugs Gaping Hole in Emergency Responder Software

05 October 2023
Cisco warns that unauthenticated, remote attackers can log into devices using root account, which has default, static credentials that cannot be changed or deleted. The post Cisco Plugs Gaping Hole in Emergency Responder Software appeared first on SecurityWeek.

New GoldDigger Android Trojan Drains Victim Bank Accounts

05 October 2023
The GoldDigger trojan has been active since at least June 2023 and is currently targeting users of over 50 Vietnamese banking apps, as well as e-wallets and crypto-wallets.

PLAY Ransomware Group Added Six New Organizations to its Victim List

05 October 2023
The organizations targeted by PLAY include Roof Management, Security Instrument Corp, Filtration Control Ltd, Cinépolis Cinemas, CHARMANT Group, and Stavanger Municipality.

Stream-Jacking Attacks on YouTube Steal From Victims via Cryptocurrency Scams

05 October 2023
Attackers redirect victims to scams that involve QR codes and phishing websites promising to double their cryptocurrency investments, often using deep fake videos of Elon Musk to add credibility.

Why Stream-Jacking is Taking Over YouTube: A Comprehensive Analysis

05 October 2023
Stream-jacking attacks on YouTube are increasing, targeting popular channels to spread deceptive content. Cybercriminals hijack these channels, often impersonating famous figures or brands like Elon Musk and Tesla, promoting scams like crypto doubling. Viewers should be cautious of videos with clickbait titles, especially those promoting financial opportunities.

Global CRM Provider Exposed Millions of Clients’ Files Online

05 October 2023
Really Simple Systems exposed a non-password-protected database with over 3 million records, including highly sensitive customer information such as medical records and tax documents.

Threats in Cloud Top List of Executive Cyber Concerns, Pwc Finds

05 October 2023
Despite the focus on cloud security, many organizations still have risk management lapses, such as not addressing disaster recovery and backup with their cloud service provider.

Operation Jacana Targets Governmental Entity in Guyana with DinodasRAT

05 October 2023
While the specific APT group behind the campaign could not be identified, there is medium confidence that it is a China-aligned threat group based on the use of a variant of Korplug, which is commonly associated with such groups.

GitHub Improves Secret Scanning Feature With Expanded Token Validity Checks

05 October 2023
GitHub beefs up its secret scanning feature, now allowing users to check the validity of exposed credentials for major cloud services. The post GitHub Improves Secret Scanning Feature With Expanded Token Validity Checks appeared first on SecurityWeek.

Scammers Impersonate Companies to Steal Cryptocurrency From Job Seekers

05 October 2023
Dubbed “WebWyrm” by CloudSEK, the operation has already targeted more than 100,000 individuals across over 50 countries by impersonating over 1000 companies across 10 industries. It has already potentially netted the scammers over $100m.

False Amazon callers one of the top phone scams in 2023

05 October 2023
Phone call fraud and spam callers were analyzed in a recent report by Hiya, finding Amazon impersonation scams in the top scams of 2023.

North Korean Hackers Target South Korean Naval Shipyards

05 October 2023
South Korea's National Intelligence Service said it is notifying shipbuilders of threats to their systems and networks and advising major shipyards to conduct independent security audits to plug security holes in digital infrastructure.