Latest Cybersecurity News and Articles


Critical Atlassian Confluence Bug Under Attack; Patch Now

05 October 2023
Upgrading alone will not remove attackers from compromised instances, and organizations must take steps to detect compromises, remove unauthorized admins, and assess any potential damage.

Apple Rolls Out Security Patches for Actively Exploited iOS Zero-Day Flaw

04 October 2023
Apple on Wednesday rolled out security patches to address a new zero-day flaw in iOS and iPadOS that it said has come under active exploitation in the wild. Tracked as CVE-2023-42824, the kernel vulnerability could be abused by a local attacker to elevate their privileges. The iPhone maker said it addressed the problem with improved checks. "Apple is aware of a report that this issue may have

Atlassian Confluence Hit by Newly Actively Exploited Zero-Day – Patch Now

04 October 2023
Atlassian has released fixes to contain an actively exploited critical zero-day flaw impacting publicly accessible Confluence Data Center and Server instances. The vulnerability, tracked as CVE-2023-22515, is remotely exploitable and allows external attackers to create unauthorized Confluence administrator accounts and access Confluence servers. It does not impact Confluence versions prior to

Mozilla Warns of Fake Thunderbird Downloads Delivering Ransomware

04 October 2023
The Snatch cybercrime group has been using paid Google ads to distribute their malware, posing as trusted software like Adobe Reader, Discord, Microsoft Teams, and Mozilla Thunderbird.

69% of generative AI users are concerned their data might be misused

04 October 2023
A recent Malwarebytes report found that online threats are affecting consumer behavior as 70% have experienced a cybersecurity threat while online.

Arietis Health Announces MOVEit Data Breach Impacting Patients of NorthStar Anesthesia Facilities

04 October 2023
The breach was discovered on May 31, 2023, and unauthorized actors were able to access Arietis Health's MOVEit server, potentially acquiring confidential files belonging to patients at NorthStar Anesthesia.

Northern Ireland Police Issue “Quishing” Email Warning

04 October 2023
Originally published by the Police Service of Northern Ireland (PSNI) Cyber Crime Centre, the notice urges all local businesses to ensure staff cybersecurity awareness training is updated so employees can spot the threat.

Lyca Mobile Suffers Disruptive Cyberattack; Investigates Ransomware Possibility

04 October 2023
The cyberattack caused disruptions to national and international calling, as well as customers' and retailers' access to top-ups, indicating a potential ransomware attack.

Sony Confirms Data Breach Impacting Thousands of US Employees

04 October 2023
The breach, caused by the Clop ransomware gang, occurred in late June but was only publicly acknowledged by Sony recently, with the company taking immediate action to remediate the vulnerability and launch an investigation.

Researchers Link DragonEgg Android Spyware to LightSpy iOS Surveillanceware

04 October 2023
New findings have identified connections between an Android spyware called DragonEgg and another sophisticated modular iOS surveillanceware tool named LightSpy. DragonEgg, alongside WyrmSpy (aka AndroidControl), was first disclosed by Lookout in July 2023 as a strain of malware capable of gathering sensitive data from Android devices. It was attributed to the Chinese nation-state group APT41. On

Ransomware double-extortion attacks increased 72%

04 October 2023
Malware, ransomware attacks and network security trends were analyzed in a recent report by WatchGuard, finding a rise in double-extortion attacks.

Typosquatting Campaign Delivers R77 Rootkit Through Malicious JavaScript Package

04 October 2023
The typosquatting attack involved a malicious package called node-hide-console-windows that downloaded a Discord bot, which then planted an open-source rootkit called r77.

Dead Grandma Locket Request Tricks Bing Chat’s AI Into Solving Security Puzzle

04 October 2023
This incident highlights a new type of vulnerability, similar to prompt injection, where users can bypass the constraints of the AI model. Microsoft is likely to address this issue in future versions of Bing Chat.

Dark Web Sale of FBI LEEP Classified Data Sparks Concerns Over National Security

04 October 2023
The sale of these credentials puts sensitive information at risk of being misused by cybercriminals. It is unclear how many credentials are being sold or if they are genuine.

NATO Investigates Alleged Cyberattack Affecting Some Unclassified Websites

04 October 2023
NATO is currently investigating claims that data was stolen from its unclassified websites by the hacking group SiegedSec. The group allegedly stole 9 GB of data, including documents from various NATO portals.

San Francisco Metropolitan Transportation Commission Leaves 26,000 Files Publicly Accessible

04 October 2023
A misconfiguration in the Metropolitan Transportation Commission (MTC) systems resulted in the exposure of over 26,000 files, including clients' home addresses and vehicle plate numbers.

Wing Disrupts the Market by Introducing Affordable SaaS Security

04 October 2023
Today, mid-sized companies and their CISOs are struggling to handle the growing threat of SaaS security with limited manpower and tight budgets. Now, this may be changing. By focusing on the critical SaaS security needs of these companies, a new approach has emerged that can be launched for $1,500 a year. If the name Wing Security (Wing) rings a bell, it is probably because earlier this year,

Chinese APT41 Actors Target WeChat Users via Trojanized App Version

04 October 2023
APT41, previously associated with web application attacks, has shifted its tactics to develop mobile-specific malware, including the DragonEgg and LightSpy surveillance malware, which share similar configuration patterns and runtime structures.

Predator Spyware Linked to Madagascar Government Ahead of Election

04 October 2023
The Madagascar government likely used the Cytrox-developed Predator spyware to conduct political domestic surveillance ahead of the country’s presidential election, according to research by Sekoia.

EvilProxy Phishing Attack Targets Indeed

04 October 2023
Menlo Labs discovered a July to August phishing campaign targeting executives in banking, insurance, real estate, and manufacturing, using the complex EvilProxy phishing kit. The campaign highlights the escalating threats that organizations face from threat actors due to the use of sophisticated tools and trusted platforms to hoodwink their targets.