Latest Cybersecurity News and Articles


Russian Flight Booking System Leonardo Suffers Massive DDoS Attack

29 September 2023
The attack caused delays at airports and affected several Russian air carriers, including Aeroflot. The Ukrainian hacktivist group IT Army claimed responsibility for the attack.

Lazarus Group Impersonates Recruiter from Meta to Target Spanish Aerospace Firm

29 September 2023
The North Korea-linked Lazarus Group has been linked to a cyber espionage attack targeting an unnamed aerospace company in Spain in which employees of the firm were approached by the threat actor posing as a recruiter for Meta. "Employees of the targeted company were contacted by a fake recruiter via LinkedIn and tricked into opening a malicious executable file presenting itself as a coding

Progress Software Says Business Impact ‘Minimal’ From MOVEit Attack Spree

29 September 2023
While the financial consequences for Progress have been minimal so far, potential litigation and class-action lawsuits related to the vulnerability could still have an impact in the future.

Post-Quantum Cryptography: Finally Real in Consumer Apps?

29 September 2023
Most people are barely thinking about basic cybersecurity, let alone post-quantum cryptography. But the impact of a post-quantum world is coming for them regardless of whether or not it's keeping them up tonight.  Today, many rely on encryption in their daily lives to protect their fundamental digital privacy and security, whether for messaging friends and family, storing files and photos, or

Malicious Ads Served Inside Bing's AI Chatbot to Infect Victims with Malware

29 September 2023
Ads are now being inserted into Bing Chat conversations, which poses a risk for users searching for software downloads. Malicious actors can trick users into visiting malicious sites and installing malware.

NSA is Creating a Hub for AI Security, Nakasone Says

29 September 2023
The center will focus on leveraging foreign intelligence insights, developing best practices, and creating risk frameworks to protect against digital attacks and prevent the theft of innovative AI capabilities.

Budworm: APT Group Uses Updated Custom Tool in Attacks on Government and Telecoms Organization

29 September 2023
The Budworm APT group continues to actively develop its toolset, as evidenced by its recent use of an updated version of its SysUpdate backdoor to target organizations in the Middle East and Asia.

Asian Banks are a Favorite Target of Cybercooks, and Malicious Bots Their Preferred Tool

29 September 2023
Asia-Pacific is the second-most targeted region for malicious bot requests against financial services, with global hubs Singapore, Australia, and Japan the region's top three most targeted, accounting for the bulk of web application and API attacks.

Stealing Credentials Through Legitimate Dropbox Pages

29 September 2023
Cybercriminals are using Dropbox to launch phishing attacks. They create a free Dropbox account, share a document with someone, and the recipient receives a legitimate-looking email from Dropbox with a link.

Security Researcher Stopped at US Border for Investigating Crypto Scam

29 September 2023
The researcher's role in investigating the scam led to a grand jury subpoena, highlighting the potential legal risks faced by ethical hackers and defenders involved in similar work.

Booking.com Customers Hit by Phishing Campaign Delivered Via Compromised Hotels Accounts

29 September 2023
The phishing attacks are highly convincing, using personalized messages and a meticulously crafted phishing page that mimics the Booking.com interface, leading victims to unknowingly provide their credit card or bank information.

Microsoft's AI-Powered Bing Chat Ads May Lead Users to Malware-Distributing Sites

29 September 2023
Malicious ads served inside Microsoft Bing's artificial intelligence (AI) chatbot are being used to distribute malware when searching for popular tools. The findings come from Malwarebytes, which revealed that unsuspecting users can be tricked into visiting booby-trapped sites and installing malware directly from Bing Chat conversations. Introduced by Microsoft in February 2023, Bing Chat is an 

Infusion Firm Faces Lawsuit After Hackers Hit Parent Company

29 September 2023
The incident highlights the growing trend of private health data breach lawsuits and the increasing role of the Federal Trade Commission in enforcing health privacy laws.

Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts

29 September 2023
The vulnerability is a result of insufficient validation of attributes in the GDOI and G-IKEv2 protocols, making it possible for an attacker to compromise a key server or modify the configuration of a group member.

Nord Security Raises $100M on $3B Valuation to Go After M&A

29 September 2023
Warburg Pincus, the lead investor in this funding round, sees Nord Security's business model and strategy as well-aligned with the cybersecurity sector, positioning the company for further momentum in the complex market environment.

BlackTech APT Breaks in Cisco Routers, Targets U.S. and Japanese Companies

29 September 2023
A Chinese state-sponsored APT called BlackTech has been found breaking into network routers to remain undetected and stealthily move across a variety of organizations. BlackTech actors often focus on branch routers (typically smaller appliances used at remote branch offices) and take advantage of the trusted connections between a victim and other entities to expand their access to the targeted networks. 

Progress Software Patches Critical Pre-Auth Flaws in WS_FTP Server Product

29 September 2023
The company identified eight flaws that could be exploited remotely, with two of them (CVE-2023-40044 and CVE-2023-42657) rated as critical due to the risk of pre-authenticated remote command execution attacks.

Progress Software Releases Urgent Hotfixes for Multiple Security Flaws in WS_FTP Server

29 September 2023
Progress Software has released hotfixes for a critical security vulnerability, alongside seven other flaws, in the WS_FTP Server Ad hoc Transfer Module and in the WS_FTP Server manager interface. Tracked as CVE-2023-40044, the flaw has a CVSS score of 10.0, indicating maximum severity. All versions of the software are impacted by the flaw. "In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a

Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts

28 September 2023
Cisco is warning of attempted exploitation of a security flaw in its IOS Software and IOS XE Software that could permit an authenticated remote attacker to achieve remote code execution on affected systems. The medium-severity vulnerability is tracked as CVE-2023-20109, and has a CVSS score of 6.6. It impacts all versions of the software that have the GDOI or G-IKEv2 protocol enabled. The

UK and US host international dialogue to advance cyber support for groups that strengthen democracy

28 September 2023
Agency heads from nine countries share insights and approaches to help improve collective cyber resilience of global democracy.