Latest Cybersecurity News and Articles


Government shutdown averted: What security leaders can learn

02 October 2023
Here security leaders discuss what a government shutdown would mean for security professionals and how it could affect the security industry.

New LostTrust Ransomware is a Likely Rebrand of the MetaEncryptor Gang

02 October 2023
The LostTrust encryptor disables various Windows services and appends the ".losttrustencoded" extension to encrypted files, with ransom demands ranging from $100,000 to millions.

Financial Crime Compliance Costs Exceed $206 Billion

02 October 2023
AI and advanced analytics are being employed by 72% of financial crime professionals to enhance compliance procedures, but challenges such as data quality and legacy systems persist, according to LexisNexis Risk Solutions.

LUCR-3: Scattered Spider Getting SaaS-y in the Cloud

02 October 2023
LUCR-3 overlaps with groups such as Scattered Spider, Oktapus, UNC3944, and STORM-0875 and is a financially motivated attacker that leverages the Identity Provider (IDP) as initial access into an environment with the goal of stealing Intellectual Property (IP) for extortion. LUCR-3 targets Fortune 2000 companies across various sectors, including but not limited to Software, Retail, Hospitality,

APIs: Unveiling the Silent Killer of Cyber Security Risk Across Industries

02 October 2023
Introduction In today's interconnected digital ecosystem, Application Programming Interfaces (APIs) play a pivotal role in enabling seamless communication and data exchange between various software applications and systems. APIs act as bridges, facilitating the sharing of information and functionalities. However, as the use of APIs continues to rise, they have become an increasingly attractive

Silent Skimmer: A Year-Long Web Skimming Campaign Targeting Online Payment Businesses

02 October 2023
A financially motivated campaign has been targeting online payment businesses in the Asia Pacific, North America, and Latin America with web skimmers for more than a year. The BlackBerry Research and Intelligence Team is tracking the activity under the name Silent Skimmer, attributing it to an actor who is knowledgeable in the Chinese language. Prominent victims include online businesses and

Ransomware Attack Leads to Payroll Issues at 21 Pinal County School Districts

02 October 2023
Efforts are underway to restore access to data and distribute paychecks, with some school districts providing emergency loans and food assistance to affected staff members.

Phishing, Smishing Surge Targets USPS

02 October 2023
Recent weeks have witnessed a significant increase in cyberattacks targeting the US Postal Service (USPS), mainly through phishing and smishing campaigns, according to DomainTools researchers who shared their findings in an advisory last week.

Russian Company Offers $20m For Non-NATO Mobile Exploits

02 October 2023
The Russian firm Operation Zero unveiled this increased payout on X (formerly Twitter) last week, aiming to attract top-tier researchers and developer teams to collaborate with their platform.

Norway Wants Europe-Wide Ban on Facebook Behavioral Ads

02 October 2023
Norway is urging the European Data Protection Board (EDPB) to ban Meta (formerly Facebook) from harvesting user data for advertising purposes permanently and extend the ban across Europe.

UK Privacy Regulator Orders End to Spreadsheet FOI Responses

02 October 2023
The UK's data protection regulator issued an advisory notice to all public authorities in the wake of a hugely damaging leak at the Police Service of Northern Ireland (PSNI) last month.

Post-Quantum Cryptography: Finally Real in Consumer Apps?

02 October 2023
Post-quantum cryptography (PQC) offers a solution by providing algorithms that are resistant to both classical and quantum computer attacks, ensuring the security of data in a quantum computing era.

OpenRefine's Zip Slip Vulnerability Could Let Attackers Execute Malicious Code

02 October 2023
Tracked as CVE-2023-37476 (CVSS score: 7.8), the vulnerability is a Zip Slip vulnerability that could have adverse impacts when importing a specially crafted project in versions 3.7.3 and below.

OpenRefine's Zip Slip Vulnerability Could Let Attackers Execute Malicious Code

02 October 2023
A high-severity security flaw has been disclosed in the open-source OpenRefine data cleanup and transformation tool that could result in arbitrary code execution on affected systems. Tracked as CVE-2023-37476 (CVSS score: 7.8), the vulnerability is a Zip Slip vulnerability that could have adverse impacts when importing a specially crafted project in versions 3.7.3 and below. "Although OpenRefine

New BunnyLoader Malware-as-a-Service Threat Emerges in the Cybercrime Underground

02 October 2023
The BunnyLoader malware incorporates anti-sandbox and antivirus evasion techniques and has been continuously developed since September 2023, with updates addressing critical flaws.

Study Reveals Conti Affiliates Money Laundering Practices

02 October 2023
Contrary to the popular notion that ransomware hackers are sophisticated launderers of their stolen money, research shows they use straightforward mechanisms to transfer their bitcoin - allowing researchers to follow their money trail.

BunnyLoader: New Malware-as-a-Service Threat Emerges in the Cybercrime Underground

02 October 2023
Cybersecurity experts have discovered yet another malware-as-a-service (MaaS) threat called BunnyLoader that's being advertised for sale on the cybercrime underground. "BunnyLoader provides various functionalities such as downloading and executing a second-stage payload, stealing browser credentials and system information, and much more," Zscaler ThreatLabz researchers Niraj Shivtarkar and

Zanubis Android Banking Trojan Poses as Peruvian Government App to Target Users

02 October 2023
An emerging Android banking trojan called Zanubis is now masquerading as a Peruvian government app to trick unsuspecting users into installing the malware. "Zanubis's main infection path is through impersonating legitimate Peruvian Android applications and then tricking the user into enabling the Accessibility permissions in order to take full control of the device," Kaspersky said in an

A Closer Look at the Snatch Data Ransom Group

30 September 2023
Earlier this week, KrebsOnSecurity revealed that the darknet website for the Snatch ransomware group was leaking data about its users and the crime gang's internal operations. Today, we'll take a closer look at the history of Snatch, its alleged founder, and their claims that everyone has confused them with a different, older ransomware group by the same name.

FBI Warns of Rising Trend of Dual Ransomware Attacks Targeting U.S. Companies

30 September 2023
The U.S. Federal Bureau of Investigation (FBI) is warning of a new trend of dual ransomware attacks targeting the same victims, at least since July 2023. "During these attacks, cyber threat actors deployed two different ransomware variants against victim companies from the following variants: AvosLocker, Diamond, Hive, Karakurt, LockBit, Quantum, and Royal," the FBI said in an alert. "Variants