Latest Cybersecurity News and Articles


CISA holds cybersecurity exercise in preparation for Super Bowl LVIII

21 September 2023
CISA, NFL, Allegiant Stadium and Super Bowl LVIII partners held a tabletop exercise this week to enhance cybersecurity response capabilities, plans and procedures.

Cisco Acquiring Cybersecurity Company Splunk in Cash Deal Worth $28 Billion

21 September 2023
The acquisition is one of Cisco’s largest, and continues an acquisition streak that has built out the company’s cybersecurity offerings. The company will finance the deal with a combination of cash and debt, Cisco CEO Chuck Robbins said.

Canada Blames Border Airport Check-in and Electronic Gate Outages on DDoS Attack

21 September 2023
The Canada Border Services Agency (CBSA) confirmed to Recorded Future News that the connectivity issues that affected check-in kiosks and electronic gates at airports last week are the result of a distributed denial of service (DDoS) attack.

Balancing Budget and System Security: Approaches to Risk Tolerance

21 September 2023
Organizations should prioritize revisiting their security readiness and up-leveling their cyber vulnerability and risk management programs by learning from data breaches and understanding the potential impact of compromised data.

China Accuses U.S. of Decade-Long Cyber Espionage Campaign Against Huawei Servers

21 September 2023
China's Ministry of State Security (MSS) has accused the U.S. of breaking into Huawei's servers, stealing critical data, and implanting backdoors since 2009, amid mounting geopolitical tensions between the two countries.

Never Use Your Master Password as a Password on Other Accounts

21 September 2023
One in three Americans now use password managers, up from one in five in 2022, according to an online poll by Security.org that quizzed 1,051 American adults on how they use passwords and password managers.

Ukrainian Hacker Suspected to be Behind "Free Download Manager" Malware Attack

21 September 2023
FDM said its investigation uncovered a vulnerability in a script on its site that the hackers exploited to tamper with the download page and lead the site visitors to the fake domain deb.fdmpkg[.]org hosting the malicious .deb file.

Cloud adoption is driving up IT budgets

21 September 2023
The impact of cloud adoption on IT teams was analyzed in a report, finding that cloud platforms took up significant portions of IT budgets.

Cyber Experts Urge House Committee to Avoid Federal Shutdown

21 September 2023
Cybersecurity experts urged Congress to avoid a government shutdown on October 1 - the start of the new federal fiscal year - telling a House panel that a lapse would damage efforts to keep the nation secure.

Omron Patches PLC, Engineering Software Flaws Discovered During ICS Malware Analysis

21 September 2023
Japanese electronics giant Omron recently patched programmable logic controller (PLC) and engineering software vulnerabilities that were discovered by industrial cybersecurity firm Dragos during the analysis of a sophisticated piece of malware.

Companies Still Don’t Know How to Handle Generative AI Risks

21 September 2023
Energized by the hype around generative AI, enterprises are aggressively pursuing practical applications of this new technology while remaining cautious about the risks, according to ISG.

Researchers Witness 600X Increase in P2Pinfect Botnet Traffic

21 September 2023
The developers of P2Pinfect are actively iterating on the malware's capabilities and expanding the botnet, as seen through frequent updates and a substantial increase in activity.

DHS Council Seeks to Simplify Cyber Incident Reporting Rules

21 September 2023
The Department of Homeland Security delivered a 100-page report on Tuesday with recommendations on how to revamp the thicket of cyber incident reporting requirements faced by U.S. critical infrastructure operators.

'Gold Melody' Group Sells Access to Compromised Networks to Ransomware Attackers

21 September 2023
GOLD MELODY uses a variety of tools and techniques, including web shells, RATs, and tunneling tools, to facilitate their malicious activities within compromised environments.

Solarium Commission Wants Action on Stalled Cybersecurity Recommendations

21 September 2023
Three years since its release, nearly 70% of the congressionally mandated Solarium Commission’s 80 initial recommendations have been implemented or are close to it, a testament to the report’s influence.

Researchers Raise Red Flag on P2PInfect Malware with 600x Activity Surge

21 September 2023
The peer-to-peer (P2) worm known as P2PInfect has witnessed a surge in activity since late August 2023, witnessing a 600x jump between September 12 and 19, 2023. "This increase in P2PInfect traffic has coincided with a growing number of variants seen in the wild, suggesting that the malware's developers are operating at an extremely high development cadence," Cado Security researcher Matt Muir

Critical Infrastructure Organizations Warned of Snatch Ransomware Attacks

21 September 2023
Prior to ransomware deployment, the Snatch threat actors spend up to three months on victims’ networks, searching for valuable data to exfiltrate and identifying systems they can encrypt. They also attempt to disable security software.

The Rise of the Malicious App

21 September 2023
Security teams are familiar with threats emanating from third-party applications that employees add to improve their productivity. These apps are inherently designed to deliver functionality to users by connecting to a “hub” app, such as Salesforce, Google Workspace, or Microsoft 365. Security concerns center on the permission scopes that are granted to the third party apps, and the potential

UK Passes the Online Safety Bill — And No, It Doesn’t Ban End-to-End Encryption

21 September 2023
The UK's Online Safety Bill does not ban end-to-end encryption but includes provisions for messaging platforms to use accredited technology to identify specific types of content.

LLM Guard: Open-Source Toolkit for Securing Large Language Models

21 September 2023
The open-source toolkit provides evaluators for inputs and outputs of LLMs, offering features such as sanitization, detection of harmful language, data leakage prevention, and protection against prompt injection and jailbreak attacks.