Latest Cybersecurity News and Articles
20 September 2023
Small and medium enterprises were analyzed in a recent report by Guardz. According to the report, 57% of SMEs have experienced a cybersecurity breach.
20 September 2023
The malicious software packages impersonate legitimate JavaScript libraries and components, but upon installation, they run obfuscated code to collect and siphon sensitive files.
20 September 2023
Finnish law enforcement authorities have announced the takedown of PIILOPUOTI, a dark web marketplace that specialized in illegal narcotics trade since May 2022.
"The site operated as a hidden service in the encrypted TOR network," the Finnish Customs (aka Tulli) said in a brief announcement on Tuesday. "The site has been used in anonymous criminal activities such as narcotics trade."
The agency
20 September 2023
Multiple security flaws have been disclosed in the Nagios XI network monitoring software that could result in privilege escalation and information disclosure.
The four security vulnerabilities, tracked from CVE-2023-40931 through CVE-2023-40934, impact Nagios XI versions 5.11.1 and lower. Following responsible disclosure on August 4, 2023, They have been patched as of September 11, 2023, with
20 September 2023
The city’s incident response team “took proactive measures to protect city data and network systems” while also hiring forensic experts to “ fully understand the extent and implications” of the attack.
20 September 2023
At present, there is no available information regarding the extent of the cyberattack's nature and impact on the ICC's systems or whether the perpetrators managed to access or exfiltrate any data or files from its network.
20 September 2023
HiddenLayer, which emerged from stealth in July 2022 with $6 million in funding, said the latest financing was led by M12, Microsoft’s Venture Fund, and Moore Strategic Ventures.
20 September 2023
The Securities and Exchange Commission introduced new requirements for disclosing material cybersecurity incidents on September 5, placing pressure on organizations to adopt robust reporting mechanisms.
20 September 2023
BlackBerry has uncovered a financially motivated campaign named Silent Skimmer, which targets vulnerable online payment businesses in the APAC and NALA regions. The attacker gains initial access by exploiting web server vulnerabilities and then deploys payment scraping mechanisms on compromised websites to steal sensitive financial data. Organizations must stay updated on the adversary's attack infrastructures and exploitation tools to defend.
20 September 2023
Alcion's platform offers backup-as-a-service, disaster recovery, anti-ransomware, anti-malware, and compliance tools for businesses with cloud-based workloads in Microsoft 365.
20 September 2023
Without effective self-discovery, companies risk being subject to criminal prosecution, and officers and directors may be subject to shareholder derivative litigation for failing to fulfill their duty of oversight.
20 September 2023
Well, you shouldn’t. It may already be hiding vulnerabilities.
It's the modular nature of modern web applications that has made them so effective. They can call on dozens of third-party web components, JS frameworks, and open-source tools to deliver all the different functionalities that keep their customers happy, but this chain of dependencies is also what makes them so vulnerable.
Many of
20 September 2023
In July 2022, crypto lender Celsius filed for bankruptcy and froze withdrawals from user accounts. Customers have since filed claims against the company, hoping to recover a portion of the funds.
20 September 2023
Cybersecurity researchers have discovered a fresh batch of malicious packages in the npm package registry that are designed to exfiltrate Kubernetes configurations and SSH keys from compromised machines to a remote server.
Sonatype said it has discovered 14 different npm packages so far: @am-fe/hooks, @am-fe/provider, @am-fe/request, @am-fe/utils, @am-fe/watermark, @am-fe/watermark-core,
20 September 2023
Chinese-language speakers have been increasingly targeted as part of multiple email phishing campaigns that aim to distribute various malware families such as Sainbox RAT, Purple Fox, and a new trojan called ValleyRAT.
"Campaigns include Chinese-language lures and malware typically associated with Chinese cybercrime activity," enterprise security firm Proofpoint said in a report shared with The
20 September 2023
The threat actors have boldly announced their intention to publish the compromised data on September 25, 2023. The Twitter handle @8BASEHOME, known as Birdy, took responsibility for the data breach.
20 September 2023
Encrypted messaging app Signal has announced an update to the Signal Protocol to add support for quantum resistance by upgrading the Extended Triple Diffie-Hellman (X3DH) specification to Post-Quantum Extended Diffie-Hellman (PQXDH).
"With this upgrade, we are adding a layer of protection against the threat of a quantum computer being built in the future that is powerful enough to break current
20 September 2023
Observability’s adoption is on the rise and full-stack observability leads to better service-level metrics, such as fewer, shorter outages and lower outage costs, according to New Relic.
20 September 2023
Cybersecurity company Trend Micro has released patches and hotfixes to address a critical security flaw in Apex One and Worry-Free Business Security solutions for Windows that has been actively exploited in real-world attacks.
20 September 2023
The BlackCat ransomware group has been found using stolen Microsoft accounts and the Sphynx encryptor to encrypt Azure cloud storage. They gained access to a victim's Sophos Central account and encrypted their systems and Azure storage. Closely monitor and patch vulnerabilities in third-party extensions, and continually update cybersecurity protocols to adapt to evolving ransomware TTPs.