Latest Cybersecurity News and Articles


Cyber Mavens Slam Europe's Cyber Resilience Act

05 October 2023
According to some experts, the proposed EU mandate for software publishers to disclose zero-day exploits within 24 hours risks compromising cybersecurity efforts by giving government agencies access to a real-time database of vulnerabilities.

AWS Kicks off Cloud Race to Mandate MFA by Default

05 October 2023
The move towards MFA by default aligns with the push for secure-by-default tactics recommended by cyber authorities and highlights the shared responsibility model in cloud security.

Microsoft Warns of Cyberattacks Attempting to Breach Cloud via SQL Server Instance

05 October 2023
The attackers exploited a SQL injection vulnerability in an application, allowing them to gain access and elevated permissions on a Microsoft SQL Server instance deployed in an Azure Virtual Machine.

Red Cross Releases Wartime Hacktivist Rules

05 October 2023
Writing in the European Journal of International Law (EJIL), the ICRC warned that cyberattacks by civilians during wartime are causing disruption to non-military targets such as hospitals, pharmacies, and banks – impacting innocent civilians.

Attacker Deployed Hundreds of Rogue Python Packages with 75,000 Downloads to Steal Sensitive Data

05 October 2023
The malicious packages aim to steal sensitive data from systems, applications, browsers, and users. They also target cryptocurrency users by redirecting transactions to the attacker's account.

Coalition to give NGOs free access to cybersecurity services to protect against attacks

05 October 2023
The CyberPeace Institute, in collaboration with other organizations, will establish a portal to provide free training and support to help NGOs in the Netherlands enhance their cybersecurity resilience.

QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks

05 October 2023
Despite the disruption to its infrastructure, the threat actors behind the QakBot malware have been linked to an ongoing phishing campaign since early August 2023 that led to the delivery of Ransom Knight (aka Cyclops) ransomware and Remcos RAT. This indicates that “the law enforcement operation may not have impacted Qakbot operators’ spam delivery infrastructure but rather only their

Report: Ransomware dwell time hits low of 24 hours

05 October 2023
Analysis from new annual report shows ransomware median dwell time has dropped from 4.5 days to less than 24 hours in a year.

Banned Applications Used as a Lure to Target Russian Users

05 October 2023
Cyble identifies a phishing campaign targeting Russians with fake sites for ExpressVPN, WeChat, and Skype. Criminals aim to deliver a RMS, gain initial access, and deploy malware. Researchers cite that TA505 might be behind this campaign. It is recommended to implement application whitelisting to restrict the execution of unknown or unapproved applications. 

Cisco Releases Urgent Patch to Fix Critical Flaw in Emergency Responder Systems

05 October 2023
Cisco has released updates to address a critical security flaw impacting Emergency Responder that allows unauthenticated, remote attackers to sign into susceptible systems using hard-coded credentials. The vulnerability, tracked as CVE-2023-20101 (CVSS score: 9.8), is due to the presence of static user credentials for the root account that the company said is usually reserved for use during

Cyberattacks in Arizona, Missouri Limit Access to Community Services

05 October 2023
The limited access to patient information systems and critical tools used by doctors due to cyberattacks can have detrimental effects on patient care, potentially costing lives.

Analysis and Config Extraction of Lu0Bot, a Node.js Malware with Considerable Capabilities

05 October 2023
Nowadays, more malware developers are using unconventional programming languages to bypass advanced detection systems. The Node.js malware Lu0Bot is a testament to this trend. By targeting a platform-agnostic runtime environment common in modern web apps and employing multi-layer obfuscation, Lu0Bot is a serious threat to organizations and individuals. Although currently, the malware has low

Guyana Governmental Entity Hit by DinodasRAT in Cyber Espionage Attack

05 October 2023
A governmental entity in Guyana has been targeted as part of a cyber espionage campaign dubbed Operation Jacana. The activity, which was detected by ESET in February 2023, entailed a spear-phishing attack that led to the deployment of a hitherto undocumented implant written in C++ called DinodasRAT. The Slovak cybersecurity firm said it could link the intrusion to a known threat actor or group,

Google and Yahoo Say They Will Crack Down on Spam With New Measures

05 October 2023
Yahoo will implement rules requiring all bulk senders to use robust email authentication, while also pushing for one-click unsubscribe options. Google will require bulk senders to validate their identities and strongly authenticate their emails.

New Supermicro BMC Vulnerabilities Could Expose Many Servers to Remote Attacks

05 October 2023
Supermicro has released updates to address multiple vulnerabilities in Baseboard Management Controllers (BMC) IPMI firmware that could allow remote attackers to gain root access to the system.

GoldDigger Android Trojan Targets Banking Apps in Asia Pacific Countries

05 October 2023
A new Android banking trojan named GoldDigger has been found targeting several financial applications with an aim to siphon victims' funds and backdoor infected devices. "The malware targets more than 50 Vietnamese banking, e-wallet and crypto wallet applications," Group-IB said. "There are indications that this threat might be poised to extend its reach across the wider APAC region and to

Okta Buys Personal Password Manager Uno to Service Consumers

05 October 2023
Okta has acquired password manager Uno to enter the consumer identity market. Uno, founded by a former Google engineer, is known for its design-centric and user-friendly password management tools.

Cisco Fixes Hardcoded Root Credentials in Emergency Responder

05 October 2023
The vulnerability, which affects CER version 12.5(1)SU4, could be exploited to execute arbitrary commands as the root user. Admins are urged to update their vulnerable installations promptly, as there are no temporary workarounds available.

CISA Warns of Active Exploitation of JetBrains and Windows Vulnerabilities

05 October 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation, while removing five bugs from the list due to lack of adequate evidence. The vulnerabilities newly added are below - CVE-2023-42793 (CVSS score: 9.8) - JetBrains TeamCity Authentication Bypass Vulnerability

Apple Warns of Newly Exploited iOS 17 Kernel Zero-Day

05 October 2023
Apple has released a new patch to fix two serious vulnerabilities in its iOS platform, one of which has already been exploited as a zero-day. The exploited kernel vulnerability, CVE-2023-42824, allows for privilege escalation.