Latest Cybersecurity News and Articles


57% of small and medium enterprises experienced a cybersecurity breach

20 September 2023
Small and medium enterprises were analyzed in a recent report by Guardz. According to the report, 57% of SMEs have experienced a cybersecurity breach.

Malicious NPM Packages Caught Exfiltrating Kubernetes Config, SSH Keys

20 September 2023
The malicious software packages impersonate legitimate JavaScript libraries and components, but upon installation, they run obfuscated code to collect and siphon sensitive files.

Finnish Authorities Dismantle Notorious PIILOPUOTI Dark Web Drug Marketplace

20 September 2023
Finnish law enforcement authorities have announced the takedown of PIILOPUOTI, a dark web marketplace that specialized in illegal narcotics trade since May 2022. "The site operated as a hidden service in the encrypted TOR network," the Finnish Customs (aka Tulli) said in a brief announcement on Tuesday. "The site has been used in anonymous criminal activities such as narcotics trade." The agency

Critical Security Flaws Exposed in Nagios XI Network Monitoring Software

20 September 2023
Multiple security flaws have been disclosed in the Nagios XI network monitoring software that could result in privilege escalation and information disclosure. The four security vulnerabilities, tracked from CVE-2023-40931 through CVE-2023-40934, impact Nagios XI versions 5.11.1 and lower. Following responsible disclosure on August 4, 2023, They have been patched as of September 11, 2023, with

Cyberattack on Kansas Town Affects Email, Phone, Payment Systems

20 September 2023
The city’s incident response team “took proactive measures to protect city data and network systems” while also hiring forensic experts to “ fully understand the extent and implications” of the attack.

Hackers Targeted International Criminal Court’s Systems Last Week

20 September 2023
At present, there is no available information regarding the extent of the cyberattack's nature and impact on the ICC's systems or whether the perpetrators managed to access or exfiltrate any data or files from its network.

HiddenLayer Raises Hefty $50M Round for AI Security Tech

20 September 2023
HiddenLayer, which emerged from stealth in July 2022 with $6 million in funding, said the latest financing was led by M12, Microsoft’s Venture Fund, and Moore Strategic Ventures.

SEC Cyber Disclosure Rules: What’s the Role of the CIO?

20 September 2023
The Securities and Exchange Commission introduced new requirements for disclosing material cybersecurity incidents on September 5, placing pressure on organizations to adopt robust reporting mechanisms.

New Silent Skimmer Campaign Hits Payment Firms in APAC and NALA Regions

20 September 2023
BlackBerry has uncovered a financially motivated campaign named Silent Skimmer, which targets vulnerable online payment businesses in the APAC and NALA regions. The attacker gains initial access by exploiting web server vulnerabilities and then deploys payment scraping mechanisms on compromised websites to steal sensitive financial data. Organizations must stay updated on the adversary's attack infrastructures and exploitation tools to defend.

Alcion, Which Provides Backup and Security Services to Enterprises, Raises $21M

20 September 2023
Alcion's platform offers backup-as-a-service, disaster recovery, anti-ransomware, anti-malware, and compliance tools for businesses with cloud-based workloads in Microsoft 365.

Regulatory Activity Forces Compliance Leaders To Spend More on Grc Tools

20 September 2023
Without effective self-discovery, companies risk being subject to criminal prosecution, and officers and directors may be subject to shareholder derivative litigation for failing to fulfill their duty of oversight.

Do You Really Trust Your Web Application Supply Chain?

20 September 2023
Well, you shouldn’t. It may already be hiding vulnerabilities. It's the modular nature of modern web applications that has made them so effective. They can call on dozens of third-party web components, JS frameworks, and open-source tools to deliver all the different functionalities that keep their customers happy, but this chain of dependencies is also what makes them so vulnerable. Many of

Claimants in Celsius Crypto Bankruptcy Targeted in Phishing Attack

20 September 2023
In July 2022, crypto lender Celsius filed for bankruptcy and froze withdrawals from user accounts. Customers have since filed claims against the company, hoping to recover a portion of the funds.

Fresh Wave of Malicious npm Packages Threaten Kubernetes Configs and SSH Keys

20 September 2023
Cybersecurity researchers have discovered a fresh batch of malicious packages in the npm package registry that are designed to exfiltrate Kubernetes configurations and SSH keys from compromised machines to a remote server. Sonatype said it has discovered 14 different npm packages so far: @am-fe/hooks, @am-fe/provider, @am-fe/request, @am-fe/utils, @am-fe/watermark, @am-fe/watermark-core,

Sophisticated Phishing Campaign Targeting Chinese Users with ValleyRAT and Gh0st RAT

20 September 2023
Chinese-language speakers have been increasingly targeted as part of multiple email phishing campaigns that aim to distribute various malware families such as Sainbox RAT, Purple Fox, and a new trojan called ValleyRAT. "Campaigns include Chinese-language lures and malware typically associated with Chinese cybercrime activity," enterprise security firm Proofpoint said in a report shared with The

Araújo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

20 September 2023
The threat actors have boldly announced their intention to publish the compromised data on September 25, 2023. The Twitter handle @8BASEHOME, known as Birdy, took responsibility for the data breach.

Signal Messenger Introduces PQXDH Quantum-Resistant Encryption

20 September 2023
Encrypted messaging app Signal has announced an update to the Signal Protocol to add support for quantum resistance by upgrading the Extended Triple Diffie-Hellman (X3DH) specification to Post-Quantum Extended Diffie-Hellman (PQXDH). "With this upgrade, we are adding a layer of protection against the threat of a quantum computer being built in the future that is powerful enough to break current

Critical Business App Outages Cost $500,000 per Hour of Downtime

20 September 2023
Observability’s adoption is on the rise and full-stack observability leads to better service-level metrics, such as fewer, shorter outages and lower outage costs, according to New Relic.

Trend Micro Releases Urgent Fix for Actively Exploited Critical Security Vulnerability

20 September 2023
Cybersecurity company Trend Micro has released patches and hotfixes to address a critical security flaw in Apex One and Worry-Free Business Security solutions for Windows that has been actively exploited in real-world attacks.

Azure Storage Compromised in Latest BlackCat Ransomware Attack

20 September 2023
The BlackCat ransomware group has been found using stolen Microsoft accounts and the Sphynx encryptor to encrypt Azure cloud storage. They gained access to a victim's Sophos Central account and encrypted their systems and Azure storage. Closely monitor and patch vulnerabilities in third-party extensions, and continually update cybersecurity protocols to adapt to evolving ransomware TTPs.