Latest Cybersecurity News and Articles
03 October 2023
The cyberattack has had ripple effects on Clorox's operations, potentially impacting quarterly earnings and allowing rival firms to gain a foothold with consumers. The company is now focusing on ramping up production to replenish inventories.
03 October 2023
Some packages exfiltrate data via webhooks or file-sharing links, while others scan for sensitive files and directories. Users are advised to be cautious and watch for suspicious install scripts.
03 October 2023
Arm has released security patches to contain a security flaw in the Mali GPU Kernel Driver that has come under active exploitation in the wild.
Tracked as CVE-2023-4211, the shortcoming impacts the following driver versions -
Midgard GPU Kernel Driver: All versions from r12p0 - r32p0
Bifrost GPU Kernel Driver: All versions from r0p0 - r42p0
Valhall GPU Kernel Driver: All versions from r19p0 -
02 October 2023
Five tax preparation companies have been warned by the FTC in regards to what information can and can't be shared for outside purposes.
02 October 2023
According to a Juniper Research report, the rate of digital identity verification checks is on the rise in response to increased identity theft.
02 October 2023
Cloudflare has been found to have vulnerabilities in its Firewall and DDoS prevention system. Hackers can exploit these flaws by creating a free Cloudflare account and knowing the IP address of a targeted web server.
02 October 2023
The Android banking Trojan Zanubis has taken on a new guise, posing as the official app for the Peruvian governmental organization SUNAT (Superintendencia Nacional de Aduanas y de Administración Tributaria).
02 October 2023
Threat actors are selling a new crypter and loader called ASMCrypt, which is an evolved version of the DoubleFinger loader. It allows them to build payloads for their campaigns by establishing contact with a backend service over the TOR network.
02 October 2023
ETSI has taken immediate action, involving France's cybersecurity agency, ANSSI, to investigate and fix the vulnerability that led to the attack and has strengthened its IT security procedures.
02 October 2023
According to the recent KnowBe4 report, healthcare is the top infrastructure topic for ransomware attacks with an increase in cyberattack frequency.
02 October 2023
The FBI warned about a new scam called the "Phantom Hacker" scam, which is specifically targeting senior citizens. It involves imposters posing as tech support, financial institutions, and government representatives to gain the trust of victims.
02 October 2023
Many organizations — including quite a few Fortune 500 firms — have exposed web links that allow anyone to initiate a Zoom video conference meeting as a valid employee. These company-specific Zoom links, which include a permanent user ID number and an embedded passcode, can work indefinitely and expose an organization’s employees, customers or partners to phishing and other social engineering attacks.
02 October 2023
The publicly accessible AWS S3 buckets contained personal data, invoices, and internal documents, potentially disrupting trade and operations of India's ports and leading to significant ransom demands.
02 October 2023
Progress Software released fixes for eight vulnerabilities in WS_FTP, including one with a maximum severity score, but evidence of exploitation was discovered shortly after.
02 October 2023
LUCR-3 is a financially motivated attacker that targets Fortune 2000 companies, using compromised credentials and leveraging SaaS applications to steal Intellectual Property for extortion.
02 October 2023
As AI technology evolves rapidly, organizations need to stay vigilant, monitor the AI landscape, and adapt their cybersecurity programs to effectively defend against new threats posed by cybercriminals.
02 October 2023
According to reports, the official website of the UK’s royal family was taken offline by a DDoS attack on Sunday. The Royal.uk site was unavailable for around 90 minutes, starting at 10 am local time, according to The Independent.
02 October 2023
Cloud computing giant AWS says an internal threat intel decoy system called MadPot has been used successfully to trap malicious activity, including nation-state-backed APTs like Volt Typhoon and Sandworm.
02 October 2023
In-the-wild exploitation of a critical vulnerability in JetBrains’ TeamCity continuous integration and continuous deployment (CI/CD) server started just days after the availability of a patch was announced.
02 October 2023
According to research from IANS and Artico Search, security budgets as a share of IT budgets are increasing, indicating a moderate impact on security spending compared to overall IT spending.