Latest Cybersecurity News and Articles
28 September 2023
The CACTUS ransomware group employs unique encryption techniques, including hiding the decryption key within a file named ntuser.dat, to evade detection by anti-virus software.
28 September 2023
Improper configuration of third-party software like TeslaMate can result in privacy breaches, compromising the owner's daily routine and posing risks such as planned robberies.
28 September 2023
A new malicious campaign has been observed hijacking GitHub accounts and committing malicious code disguised as Dependabot contributions with an aim to steal passwords from developers.
"The malicious code exfiltrates the GitHub project's defined secrets to a malicious C2 server and modify any existing javascript files in the attacked project with a web-form password-stealer malware code
28 September 2023
Prompt injection attacks manipulate LLMs by introducing malicious commands into free text inputs, posing a significant threat to cybersecurity and potentially leading to unauthorized activities or data leaks.
28 September 2023
A recent analysis by Censys has uncovered about 314,000 internet-connected devices and web servers that are exposing millions of files, potentially containing sensitive data.
28 September 2023
The Cybersecurity and Infrastructure Security Agency (CISA) has launched a national public service campaign called "Secure our World" to raise awareness of cybersecurity in local communities.
28 September 2023
The attackers utilized typosquatting and code modifications to trick developers into installing malicious packages and continuously refined their techniques to evade detection.
28 September 2023
At least four separate plaintiffs allege the company was negligent for allowing their sensitive personal data to be stolen in a social engineering attack by criminal threat groups.
28 September 2023
Ukrainian cybersecurity officials have reported that the recent espionage campaigns targeted entities involved in investigating war crimes, such as the prosecutor general's office and courts.
28 September 2023
Cybersecurity agencies from Japan and the U.S. have warned of attacks mounted by a state-backed hacking group from China to stealthily tamper with branch routers and use them as jumping-off points to access the networks of various companies in the two countries.
The attacks have been tied to a malicious cyber actor dubbed BlackTech by the U.S. National Security Agency (NSA), Federal Bureau of
28 September 2023
The attacks have caused significant problems for retailers, with issues such as inventory management and order fulfillment still not resolved. Retailers have reported glitches and loss of sales due to the cyberattack.
28 September 2023
The incident did not affect systems that connect with customers or suppliers, and the company is working with its insurer to make claims under its cyber insurance coverage.
28 September 2023
The campaign targets luxury resorts and hotel chains, using reconnaissance emails and instant messages to trick employees into responding and downloading malicious files from trusted cloud domains.
28 September 2023
Ricardo Villadiego, Lumu’s founder and CEO, says that the new cash will be put toward growing Lumu’s sales team in the U.S., supporting its go-to-market strategy, and increasing the startup’s investments in R&D.
28 September 2023
Threat actors meticulously fabricated commit messages to mimic Dependabot's automated contributions to mask the malevolent activities they were indulging in. Between July 8 and July 11, an unidentified threat actor began compromising a multitude of GitHub repositories, affecting both public and private sectors, with a significant number of victims originating from Indonesia. The attackers skillfully manipulated commit messages, leading developers to believe that the real Dependabot had made these contributions.
28 September 2023
A recent security report reveals a drop in phishing and ransomware attacks, but fallout from the Las Vegas attacks underscores the massive social engineering vulnerabilities still plaguing businesses.
28 September 2023
The encryption method, known as PKCS#1 v1.5 padding scheme, was previously thought to be immune to attacks, but a new paper reveals that many software implementations of the scheme are actually vulnerable.
28 September 2023
Security leaders discuss recently released unclassified summary of the Department of Defense's classified 2023 Cyber Strategy.
28 September 2023
The conference will discuss topics such as protecting critical infrastructure, ransomware, and the U.S. national cyber strategy, aiming to establish a long-lasting relationship with the region on cyber issues.
28 September 2023
A Chinese state-sponsored APT called BlackTech has been caught hacking into network edge devices and using firmware implants to stay hidden and silently hop around the corporate networks of U.S. and Japanese multinational companies.