Latest Cybersecurity News and Articles


Tech Giants Launch Post-Quantum Cryptography Coalition

27 September 2023
The PQC Coalition features Microsoft, IBM Quantum, MITRE, PQShield, SandboxAQ, and the University of Waterloo among its founding members. The goal will be to improve the uptake of PQC in commercial and open-source technologies.

Update: Sony Investigating After Hackers Offer to Sell Stolen Data

27 September 2023
The majority of the leaked files seem to originate from servers associated with Creators Cloud, and the hackers have not provided evidence that all Sony systems have been compromised.

Microsoft Brings Passkeys, Bad Code Protection to Windows 11

27 September 2023
Microsoft updated Windows 11 on Tuesday to simplify passwordless adoption, protect against malicious code, and have the ability to refresh configuration in the event of tampering.

Critical libwebp Vulnerability Under Active Exploitation - Gets Maximum CVSS Score

27 September 2023
The vulnerability in libwebp, which stems from an issue in the Huffman coding algorithm, can result in out-of-bounds data writing to the heap when processing specially crafted WebP lossless files.

CommonSpirit Details Financial Fallout of $160M Cyberattack

27 September 2023
The cyberattack on the entity on October 2, 2022, resulted in about $160 million in damages, including lost revenue, remediation costs, and related expenses, not counting insurance recoveries, according to CommonSpirit.

New ZeroFont Phishing Tricks Outlook Into Showing Fake AV-Scans

27 September 2023
The ZeroFont phishing technique exploits flaws in AI and natural language processing systems to insert hidden words or characters in emails, evading security filters and tricking recipients.

Critical libwebp Vulnerability Under Active Exploitation - Gets Maximum CVSS Score

27 September 2023
Google has assigned a new CVE identifier for a critical security flaw in the libwebp image library for rendering images in the WebP format that has come under active exploitation in the wild. Tracked as CVE-2023-5129, the issue has been given the maximum severity score of 10.0 on the CVSS rating system. It has been described as an issue rooted in the Huffman coding algorithm - With a specially

Xenomorph Android Malware Reappears in a New Campaign Targeting U.S. Banks

27 September 2023
A new Xenomorph malware campaign was detected in August 2023. It appears to have widened its target scope, including financial institutions and crypto-wallet apps, with each sample aiming at over 100 different targets. This Android malware leverages its Automated Transfer System for versatile actions based on specific conditions. With the emergence of this variant, researchers anticipate more attacks in the future.

ALPHV Ransomware Group Targets Clarion, Phil-Data Business Systems, and MNGI Digestive Health

26 September 2023
The ALPHV ransomware group, also known as the BlackCat hacker collective, has recently targeted three new victims in their cyberattacks. The group has demonstrated adaptability and employed advanced technical methods in their attacks.

Microsoft is Rolling out Support for Passkeys in Windows 11

26 September 2023
Microsoft is officially rolling out support for passkeys in Windows 11 today as part of a major update to the desktop operating system. The feature allows users to login to websites and applications without having to provide a username and password, instead relying on their device PIN or biometric information to complete the step. Based on FIDO standards, Passkeys were first announced in May

Smishing Triad Stretches its Tentacles into the United Arab Emirates

26 September 2023
"Smishing Triad" is leveraging compromised Apple iCloud accounts and illegally obtained databases containing personally identifiable information (PII) to carry out their attacks.

Decade Worth of Newborn Child Registry Data Stolen in MOVEit Hack at BORN Ontario

26 September 2023
The stolen data includes names, addresses, health card numbers, and clinical information related to fertility, pregnancy, newborn, and child healthcare, with potential impacts on individuals from January 2010 to May 2023.

ShadowSyndicate: A New Cybercrime Group Linked to 7 Ransomware Families

26 September 2023
Cybersecurity experts have shed light on a new cybercrime group known as ShadowSyndicate (formerly Infra Storm) that may have leveraged as many as seven different ransomware families over the past year. "ShadowSyndicate is a threat actor that works with various ransomware groups and affiliates of ransomware programs," Group-IB and Bridewell said in a new joint report. The actor, active since

Hackers Actively Exploiting Openfire Flaw to Encrypt Servers

26 September 2023
The flaw, CVE-2023-32315, allows attackers to bypass authentication and create new admin accounts, enabling them to install malicious Java plugins and execute arbitrary code on compromised servers.

Kuwait Isolates Some Government Systems Following Attack on its Finance Ministry

26 September 2023
The attack started on September 18, and officials immediately took steps to isolate and shut down affected systems. The Ministry of Finance assured that payment and payroll systems were on a separate network and that workers would be paid.

Report shows cybersecurity budgets increased 6% for 2022-2023 cycle

26 September 2023
A new report shows despite economic uncertainty and inflation, security budgets generally continued to rise but at a lower rate than prior years.

Stratascale Acquires VECTOR0 To Strengthen Its Cybersecurity Services

26 September 2023
Through the acquisition, Stratascale professionals and their customers gain visibility of attack vectors and points of vulnerability, enhancing Stratascale’s ability to deliver proactive cybersecurity services.

85% of IT anticipate leaving their role due to burnout

26 September 2023
According to a report, a majority of IT security leaders say that stress has caused them and others to make errors that led to data breaches.

ShadowSyndicate Hackers Linked to Multiple Ransomware Operations, 85 Servers

26 September 2023
ShadowSyndicate is believed to be an initial access broker (IAB) or an affiliate working with multiple ransomware operations, including Quantum, Nokoyawa, BlackCat/ALPHV, Clop, Royal, Cactus, and Play, based on evidence found by researchers.

40% of organizations have hybrid cloud environments

26 September 2023
According to a recent report, 75% of respondents are extremely or very concerned about cloud security and 40% have hybrid cloud environments.