Latest Cybersecurity News and Articles


Critical JetBrains TeamCity Flaw Could Expose Source Code and Build Pipelines to Attackers

26 September 2023
A critical security vulnerability in the JetBrains TeamCity continuous integration and continuous deployment (CI/CD) software could be exploited by unauthenticated attackers to achieve remote code execution on affected systems. The flaw, tracked as CVE-2023-42793, carries a CVSS score of 9.8 and has been addressed in TeamCity version 2023.05.4 following responsible disclosure on September 6,

WatchGuard Announces its Acquisition of CyGlass

25 September 2023
The acquisition will offer WatchGuard's partners and customers access to cutting-edge security solutions, improved XDR insights, and simplified compliance with regulatory and cyber-insurance requirements.

Personal Data of 25,000 Hongkongers at Risk After Cyberattack Against Consumer Council

25 September 2023
The council has restored its computer systems but anticipates delays in addressing complaints, and is taking extra precautions by notifying individuals who may have been affected by the data leak.

Report: 79% of organizations confident in ransomware defenses

25 September 2023
A recently released ransomware defense report analyzes how security leaders and practitioners view the threat of ransomware and their organizations’ cyber readiness.

For Security to Benefit From AI, Companies Need to Shore up Their Data

25 September 2023
CISOs and cybersecurity practitioners should focus on addressing the challenges of data structure, management, and curation to fully leverage the benefits of AI for cyber defense.

Fake Celebrity Photo Leak Videos Flood TikTok With Temu Referral Codes

25 September 2023
Scammers have started creating videos implying leaked sensitive photos of celebrities and urging viewers to download the Temu app and enter their referral number to view the content. These scams have been targeting multiple celebrities.

Incomplete Disclosures by Apple and Google Create “Huge Blindspot” for Zero-Day Hunters

25 September 2023
Google's limited disclosure and the separate CVE designations for the vulnerability by Apple, Google, and Citizen Lab have hindered the detection and patching of the critical vulnerability in other software relying on libwebp.

Average Insider Cyberthreat Cost Spikes 40% in Four Years: Report

25 September 2023
Containment and remediation after an insider incident are the most expensive areas, with an average cost of $179,209 and $125,221 per incident respectively, and the average time to contain an incident has increased to 86 days.

Hong Kong-Based Cryptocurrency Firm Mixin Says Hackers Stole $200 Million in Assets

25 September 2023
The incident follows a recent trend of cryptocurrency hacks, with North Korean hackers being suspected in multiple attacks, highlighting the growing threat posed by cybercriminals targeting the industry.

Nigerian Man Pleads Guilty to Attempted $6 Million BEC Email Heist

25 September 2023
Kosi Goodness Simon-Ebo, a Nigerian national, pleaded guilty to wire fraud and money laundering through business email compromise (BEC) schemes, resulting in millions of dollars in losses.

Xenomorph Malware Returns to Strike Customers of Over 30 American Banks

25 September 2023
The Xenomorph malware family, known for its advanced capabilities and distribution campaigns, has resurfaced with new overlays targeting institutions and crypto wallets in the United States and Portugal.

SANS Survey Shows Drop in 2023 ICS/OT Security Budgets

25 September 2023
The budgets allocated for the security of industrial control systems (ICS) and operational technology (OT) have decreased in 2023 compared to the previous year, with over 21% of organizations reporting not having a cybersecurity budget at all.

Ukrainian Military Targeted in Phishing Campaign Leveraging Drone Manuals

25 September 2023
Ukrainian military entities are the target of a phishing campaign that leverages drone manuals as lures to deliver a Go-based open-source post-exploitation toolkit called Merlin.

Tim Roemer hired as Chief Security Officer at Global Market Innovators

25 September 2023
Tim Roemer has been hired as CSO at Global Market Innovators. Roemer previously served as the Director of the Arizona Department of Homeland Security.

CISA and NFL Collaborate to Secure Super Bowl LVIII

25 September 2023
The US Cybersecurity and Infrastructure Security Agency (CISA) and the NFL conducted a cybersecurity tabletop exercise to assess and improve response capabilities for potential cyber-attacks during Super Bowl LVIII.

New Modular Deadglyph Backdoor Used in a Government Attack

25 September 2023
Security researchers have identified a highly advanced modular backdoor, named Deadglyph, believed to be linked to the Stealth Falcon cyber espionage group. It was discovered during an investigation into a cyberespionage incident in the Middle East. Organizations are advised to leverage the IOCs associated with the malware to protect endpoints or networks vulnerable to attacks.

Python Malware Targets Tatar-Language Users: TA866 Threat Actor Strikes Again

25 September 2023
The threat actor behind this campaign is the TA866 group, known for targeting Tatar language speakers. The attackers use phishing emails with a malicious RAR file that contains a video file and a Python-based executable disguised as an image file.

Ukrainian Military Targeted in Phishing Campaign Leveraging Drone Manuals

25 September 2023
Ukrainian military entities are the target of a phishing campaign that leverages drone manuals as lures to deliver a Go-based open-source post-exploitation toolkit called Merlin. "Since drones or Unmanned Aerial Vehicles (UAVs) have been an integral tool used by the Ukrainian military, malware-laced lure files themed as UAVs service manuals have begun to surface," Securonix researchers Den

Cyber Insurance Claims Spiked in First Half of 2023 as Ransomware Attacks Surged: Report

25 September 2023
Large companies with over $100 million in revenues have been particularly targeted, experiencing a rise in both the frequency and severity of cyber incidents. Funds transfer fraud has also become a prevalent issue.

EvilBamboo Targets Tibetans, Uyghurs, and Taiwanese People and Organizations

25 September 2023
"The attacker has created fake Tibetan websites, along with social media profiles, likely used to deploy browser-based exploits against targeted users," Volexity security researchers said in a report published last week.