Latest Cybersecurity News and Articles


Apple Emergency Updates Fix Three New Zero-Days Exploited in Attacks

22 September 2023
Apple released emergency security updates to patch three new zero-day vulnerabilities exploited in attacks targeting iPhone and Mac users, for a total of 16 zero-days fixed this year.

Rising OT/ICS Cybersecurity Incidents Reveal Alarming Trend

22 September 2023
Approximately 60% of cyberattacks on the industrial sector are carried out by state-affiliated actors, often with the unintentional assistance of internal personnel (about 33% of the time), according to Rockwell Automation.

Air Canada Says Hackers Accessed Limited Employee Records During Cyberattack

22 September 2023
Canada’s largest airline, Air Canada, announced a data breach this week that involved the information of employees, but said its operations and customer data were not impacted.

Chinese-speaking Users Targeted with ValleyRAT and Sainbox RAT

22 September 2023
Proofpoint has identified a notable rise in cybercrime activity aimed at Chinese-speaking individuals. It noted that ValleyRAT and a Gh0stRAt variant named Sainbox RAT targeted global organizations with Chinese operations. These are being distributed via Excel and PDF attachments containing infected URLs. To learn what's brewing in the cybersecurity world and what are some quick actions to take to mitigate threats, situational and strategical awareness is a must.

How to Interpret the 2023 MITRE ATT&CK Evaluation Results

22 September 2023
Thorough, independent tests are a vital resource for analyzing provider’s capabilities to guard against increasingly sophisticated threats to their organization. And perhaps no assessment is more widely trusted than the annual MITRE Engenuity ATT&CK Evaluation.  This testing is critical for evaluating vendors because it’s virtually impossible to evaluate cybersecurity vendors based on their own

Security Concerns and Outages Elevate Observability From IT Niche to Business Essential

22 September 2023
A new report from SolarWinds highlights the benefits of observability for enterprises. The report states that companies that implement observability experience increased operational efficiency, faster innovation, and better business outcomes.

Legit Security Lands $40M to Lock Down Apps and Dev Environments

22 September 2023
Legit Security, a cybersecurity company developing a platform to identify app vulnerabilities from code, has raised $40 million in a Series B funding round led by CRV with participation from Cyberstarts, Bessemer Venture Partners, and TCV.

CISA Adds Owl Labs, Samsung, Realtek Bugs to Exploited Vulnerability List

22 September 2023
The CISA added eight bugs on Monday and another on Tuesday to its list of known exploited vulnerabilities, giving FCEB agencies three weeks to patch the issues that affect products from MinIO, Samsung, Realtek, Zyxel, Laravel, and Owl Labs.

High-Severity Flaws Uncovered in ISC BIND Server

22 September 2023
ISC has released fixes for two high-severity bugs affecting the Berkeley Internet Name Domain (BIND) 9 Domain Name System (DNS) software suite that could pave the way for a DoS condition.

Iranian Nation-State Actor OilRig Targets Israeli Organizations

22 September 2023
Israeli organizations were targeted as part of two different campaigns orchestrated by the Iranian nation-state actor known as OilRig in 2021 and 2022. The campaigns, dubbed Outer Space and Juicy Mix, entailed the use of two previously documented first-stage backdoors called Solar and Mango, which were deployed to collect sensitive information from major browsers and the Windows Credential

Atlassian Security Updates Patch High-Severity Vulnerabilities

22 September 2023
Tracked as CVE-2023-22513 (CVSS score of 8.5), the most severe of these issues is described as a remote code execution (RCE) bug in Bitbucket that could impact confidentiality, integrity, and availability.

Update: MGM Resorts Computers Back Up After 10 Days as Analysts Eye Effects of Casino Cyberattacks

22 September 2023
“We are pleased that all of our hotels and casinos are operating normally,” the Las Vegas-based company posted on X, the platform formerly known as Twitter. It was reported last week that the attack was detected on September 10.

Signal Adds Quantum-Resistant Encryption to its E2EE Messaging Protocol

22 September 2023
Signal plans to continue adapting and upgrading its encryption mechanism to ensure quantum-resistant end-to-end encryption in the face of emerging challenges and ongoing research.

High-Severity Flaws Uncovered in Atlassian Products and ISC BIND Server

22 September 2023
Atlassian and the Internet Systems Consortium (ISC) have disclosed several security flaws impacting their products that could be exploited to achieve denial-of-service (DoS) and remote code execution. The Australian software services provider said that the four high-severity flaws were fixed in new versions shipped last month. This includes - CVE-2022-25647 (CVSS score: 7.5) - A deserialization

Space and Defense Tech Maker Exail Technologies Exposes Database Access

22 September 2023
The exposure of the company's web server version and operating system flavor poses a risk as attackers could target specific vulnerabilities associated with the operating system.

Apple Rushes to Patch 3 New Zero-Day Flaws: iOS, macOS, Safari, and More Vulnerable

21 September 2023
Apple has released yet another round of security patches to address three actively exploited zero-day flaws impacting iOS, iPadOS, macOS, watchOS, and Safari, taking the total tally of zero-day bugs discovered in its software this year to 16. The list of security vulnerabilities is as follows - CVE-2023-41991 - A certificate validation issue in the Security framework that could allow a

97% of organizations take over a month to respond to bot attacks

21 September 2023
A recent report by Netacea analyzed the affect of bot attacks and found that the average business loses 4.3%, of online revenues every year to bots.

Mysterious 'Sandman' Threat Actor Targets Telecom Providers Across Three Continents

21 September 2023
A previously undocumented threat actor dubbed Sandman has been attributed to a set of cyber attacks targeting telecommunic koation providers in the Middle East, Western Europe, and the South Asian subcontinent. Notably, the intrusions leverage a just-in-time (JIT) compiler for the Lua programming language known as LuaJIT as a vehicle to deploy a novel implant called LuaDream. "The activities we

19% of organizations are prioritizing data visibility and remediation

21 September 2023
According to a SpyCloud ransomware report, infostealer infections were 22% of ransomware attacks for North American and European companies.

Singapore Police Warn of New Scam Campaign Spreading Android Malware

21 September 2023
The Singapore police, on Wednesday, issued an advisory about a new variant of Android malware scams, where scammers would initiate a factory reset on infected devices after the malware executes unauthorized transactions on the phone’s i-banking app.