Latest Cybersecurity News and Articles


Update: Royal Lurked in Dallas’ Systems Weeks Before Ransomware Attack

26 September 2023
The Royal ransomware group infiltrated Dallas' systems, surveilled and exfiltrated data for a month before launching a ransomware attack, causing widespread disruption to critical city services.

75% who didn't report cyber attack to leadership, felt guilty about it

26 September 2023
Research finds 40% of organizations have experienced a cybersecurity incident, yet 48% didn't disclose those incidents to the appropriate authorities.

Sandman APT Brings LuaDream, Targets Telcos in Middle East

26 September 2023
SentinelOne found the Sandman APT group targeting telecommunications companies in the Middle East, Western Europe, and South Asia using a novel backdoor called LuaDream. The researchers noted that the campaign began in August and demonstrates advanced tactics. With this, the Middle East is once again under cyberespionage scrutiny.

Despite Rising Insider Risk Costs, Budgets are Being Wasted in the Wrong Places

26 September 2023
The cost of insider risks for organizations is at an all-time high, with the average annual cost reaching $16.2 million, a 40% increase in four years, according to DTEX Systems.

Chinese Hackers TAG-74 Targets South Korean Organizations in a Multi-Year Campaign

26 September 2023
Social engineering attacks mounted by the adversary make use of Microsoft CHM file lures to drop a custom variant of an open-source Visual Basic Script backdoor called ReVBShell, which subsequently serves to deploy the Bisonal remote access trojan.

Security leaders weigh in on latest MOVEit data breach

26 September 2023
A U.S. educational nonprofit has announced that nearly 900 schools using the organization’s services may have been affected by a recent data breach.

Essential Guide to Cybersecurity Compliance

26 September 2023
SOC 2, ISO, HIPAA, Cyber Essentials – all the security frameworks and certifications today are an acronym soup that can make even a compliance expert’s head spin. If you’re embarking on your compliance journey, read on to discover the differences between standards, which is best for your business, and how vulnerability management can aid compliance. What is cybersecurity compliance?

Xenomorph Banking Trojan: A New Variant Targeting 35+ U.S. Financial Institutions

26 September 2023
An updated version of an Android banking trojan called Xenomorph has set its sights on more than 35 financial institutions in the U.S. The campaign, according to Dutch security firm ThreatFabric, leverages phishing web pages that are designed to entice victims into installing malicious Android apps that target a broader list of apps than its predecessors. Some of the other targeted prominent

BinDiff: Open-Source Comparison Tool for Binary Files

26 September 2023
The latest release includes various updates such as support for IDA Pro 8.3, improvements in handling functions without names, and faster Abseil maps in the differ engine. BinDiff is available for download on GitHub.

Product Leasing Giant Warns That Sensitive Information was Stolen During Cyberattack

26 September 2023
The company has engaged cybersecurity experts and law enforcement to investigate the incident and is taking steps to notify affected individuals and regulatory authorities.

Current Ransomware Defensive Efforts are not Working

26 September 2023
According to SpyCloud, info-stealer malware, such as Raccoon, Vidar, and Redline, is a common precursor to ransomware attacks, with 76% of infections involving Raccoon info-stealer malware.

Threat Report: The High Tech Industry Targeted the Most with 46% of NLX-Tagged Attack Traffic

26 September 2023
How To Use This Report Enhance situational awareness of techniques used by threat actors Identify potential attacks targeting your industry Gain insights to help improve and accelerate your organization’s threat response Summary of Findings The Network Effect Threat Report offers insights based on unique data from Fastly’s Next-Gen WAF from Q2 2023 (April 1, 2023 to June 30, 2023). This report

ZenRAT Malware Brings More Chaos Than Calm

26 September 2023
ZenRAT is a new malware targeting Windows users and being distributed via fake Bitwarden installation packages. The malware redirects non-Windows users to a benign webpage while stealing information from Windows users.

Balancing Cybersecurity With Convenience and Progress

26 September 2023
Organizations must find a balance between excessive cybersecurity measures that hinder progress and relaxed measures that can lead to serious incidents with potentially greater negative impacts.

Chinese Hackers TAG-74 Targets South Korean Organizations in a Multi-Year Campaign

26 September 2023
A "multi-year" Chinese state-sponsored cyber espionage campaign has been observed targeting South Korean academic, political, and government organizations. Recorded Future's Insikt Group, which is tracking the activity under the moniker TAG-74, said the adversary has been linked to "Chinese military intelligence and poses a significant threat to academic, aerospace and defense, government,

Hands-on Threat Simulations: Empower Cybersecurity Teams to Confidently Combat Threats

26 September 2023
Cybersecurity teams must prioritize developing their defense skills to effectively identify and stop potential cyberattacks, as automated technologies cannot detect every threat.

Update: MGM Resorts Warns Customers of Fraud as It Faces Class Action Lawsuits

26 September 2023
MGM Resorts is facing class action litigation in two separate lawsuits filed in U.S. District Court in Nevada in connection with the cyberattack launched against the company earlier this month.

Update: Data Breach Toll Tied to Clop Group's MOVEit Attacks Surges

26 September 2023
Security firm Emsisoft on Friday estimated that at least 2,054 organizations have been affected by the MOVEit software attacks. That's a sharp rise from one week ago when its count of affected organizations stood at about 1,190.

Critical JetBrains TeamCity Flaw Could Expose Source Code and Build Pipelines to Attackers

26 September 2023
The flaw, tracked as CVE-2023-42793, carries a CVSS score of 9.8 and has been addressed in TeamCity version 2023.05.4 following responsible disclosure on September 6, 2023.

‘All Of Sony Systems’ Allegedly Hacked by New Ransomware Group

26 September 2023
A new gang on the dark web, known as Ransomed.vc, claims to have breached all of Sony's systems in a ransomware attack. The hackers allegedly uncovered screenshots, internal documents, and thousands of files, some of which are in Japanese.