Latest Cybersecurity News and Articles


Lorenz Ransomware Group Attacks Allcare Pharmacy in Major Cyber Assault

03 October 2023
The Allcare Pharmacy data breach, claimed by the Lorenz ransomware group, has exposed sensitive customer information, including Social Security Numbers, raising concerns about data security and patient privacy in the healthcare sector.

Hackers Seen Exploiting Bugs in Browsers and Popular File Transfer Tool

03 October 2023
The Cybersecurity and Infrastructure Security Agency (CISA) warned on Monday that hackers are exploiting CVE-2023-5217 — a vulnerability affecting Google Chrome, Mozilla Firefox, and more.

Over 3 Dozen Data-Stealing Malicious npm Packages Found Targeting Developers

03 October 2023
Nearly three dozen counterfeit packages have been discovered in the npm package repository that are designed to exfiltrate sensitive data from developer systems, according to findings from Fortinet FortiGuard Labs. One set of packages – named @expue/webpack, @expue/core, @expue/vue3-renderer, @fixedwidthtable/fixedwidthtable, and @virtualsearchtable/virtualsearchtable – harbored an obfuscated

New Wave of Mirai Botnet Variants Like hailBot, kiraiBot, and catDDoS Mount a Fierce Onslaught

03 October 2023
These variants utilize different tactics such as modifying go-live processes, introducing new encryption algorithms, and incorporating OpenNIC domains to evade detection and enhance their malicious activities.

Android’s October 2023 Security Updates Patch Two Exploited Vulnerabilities

03 October 2023
Google on Monday announced the release of patches for 51 vulnerabilities as part of the October 2023 security updates for Android, including fixes for two zero-day flaws exploited in malicious attacks.

Medusa Ransomware Group Claims Intrusions at Two New Victims, Sets Ransom Deadline

03 October 2023
The Medusa ransomware group has recently targeted two companies, Karam Chand Thapar & Bros. (Coal Sales) Ltd in India and the Sweden-based Windak Group, demanding significant ransoms for the release of encrypted data.

Update: Some Prospect Medical Hospitals in Dire State, Post-Attack

03 October 2023
The hospitals are facing financial difficulties and are struggling to pay vendors. This incident highlights the vulnerability of financially unstable hospitals to cyberattacks and the potential risks to patient care.

BlackCat Ransomware Gang Allegedly Stole Over 24 Million Files From Motel One

03 October 2023
Motel One has been given a five-day deadline to pay the ransom or risk the public release of the stolen data, which would result in significant reputational and legal consequences for the company.

CISA kicks off 20th Cybersecurity Awareness Month

03 October 2023
Cybersecurity and Infrastructure Security Agency announced the kickoff of the 20th Cybersecurity Awareness Month.

API Security Trends 2023 – Have Organizations Improved their Security Posture?

03 October 2023
APIs, also known as application programming interfaces, serve as the backbone of modern software applications, enabling seamless communication and data exchange between different systems and platforms. They provide developers with an interface to interact with external services, allowing them to integrate various functionalities into their own applications. However, this increased reliance on

Protecting your IT infrastructure with Security Configuration Assessment (SCA)

03 October 2023
Security Configuration Assessment (SCA) is critical to an organization's cybersecurity strategy. SCA aims to discover vulnerabilities and misconfigurations that malicious actors exploit to gain unauthorized access to systems and data. Regular security configuration assessments are essential in maintaining a secure and compliant environment, as this minimizes the risk of cyber attacks. The

Global Events Fuel DDoS Attack Campaigns

03 October 2023
Cybercriminals launched around 7.9 million DDoS attacks in the first half of 2023, a 31% increase compared to the previous year, according to NETSCOUT. These attacks have been driven by global events such as the Russia-Ukraine war and NATO bids.

FDA Cyber Mandates for Medical Devices Goes Into Effect

03 October 2023
New FDA regulations require medical device vendors to enhance security features and address vulnerabilities, aiming to reduce the risk of compromised devices reaching consumers.

Chalk: Open-Source Software Security and Infrastructure Visibility Tool

03 October 2023
Chalk offers convenience for compliance by producing SBOMs, embedding code provenance details and digitally signing reports, addressing regulatory requirements, and saving costs on unnecessary tools licenses.

Arm Issues Patch for Mali GPU Kernel Driver Vulnerability Amidst Ongoing Exploitation

03 October 2023
The issue, credited to Maddie Stone of Google's Threat Analysis Group (TAG) and Jann Horn of Google Project Zero, has been addressed in Bifrost, Valhall and Arm 5th Gen GPU Architecture Kernel Driver r43p0.

Researcher Reveals New Techniques to Bypass Cloudflare's Firewall and DDoS Protection

03 October 2023
Firewall and distributed denial-of-service (DDoS) attack prevention mechanisms in Cloudflare can be circumvented by exploiting gaps in cross-tenant security controls, defeating the very purpose of these safeguards, it has emerged. "Attackers can utilize their own Cloudflare accounts to abuse the per-design trust-relationship between Cloudflare and the customers' websites, rendering the

Chertoff Group Arm to Buy Trustwave from Singtel for $205M

03 October 2023
The acquisition of Trustwave by The Chertoff Group's affiliate MC2 Security Fund signifies the private equity firm's continued investment in cybersecurity and its recognition of the potential value in Trustwave's offerings.

Virginia School District Open Despite Lockbit Ransomware Attack

03 October 2023
The LockBit ransomware gang claimed responsibility for the attack and demanded an undisclosed ransom, but the impact on student and staff information was minimal, and the school district has remained fully operational.

Exim Patches Three of Six Zero-Day Bugs Disclosed Last Week

03 October 2023
One of the vulnerabilities allows remote unauthenticated attackers to execute code in the context of the service account. The other two vulnerabilities patched include a remote code execution bug and an information disclosure issue.

Cyber Investments on Pace to Reach $215B in 2024: Gartner

03 October 2023
A survey by Moody's reveals that cybersecurity spending has increased by 70% from 2019 to 2023, with organizations allocating a larger share of their technology budgets to cybersecurity.