Latest Cybersecurity News and Articles


GitLab Releases Urgent Security Patches for Critical Vulnerability

20 September 2023
The issue, tracked as CVE-2023-5009 (CVSS score: 9.6), impacts all versions of GitLab Enterprise Edition (EE) starting from 13.12 and prior to 16.2.7 as well as from 16.3 and before 16.3.4.

FBI Director Urges Private Sector to Work With the Agency on Cyber Threats

20 September 2023
At the annual mWISE 2023 conference on Monday, FBI Director Christopher Wray urged private sector organizations to help the agency by coming forward with information regarding malicious cyber activity.

Kubernetes Vulnerability Allows RCE on Windows Endpoints (CVE-2023-3676)

20 September 2023
Three high-severity Kubernetes vulnerabilities (CVE-2023-3676, CVE-2023-3893, CVE-2023-3955) could allow attackers to execute code remotely and gain control over all Windows nodes in the Kubernetes cluster.

GitLab Releases Urgent Security Patches for Critical Vulnerability

20 September 2023
GitLab has shipped security patches to resolve a critical flaw that allows an attacker to run pipelines as another user. The issue, tracked as CVE-2023-5009 (CVSS score: 9.6), impacts all versions of GitLab Enterprise Edition (EE) starting from 13.12 and prior to 16.2.7 as well as from 16.3 and before 16.3.4. "It was possible for an attacker to run pipelines as an arbitrary user via scheduled

Pizza Hut Australia hack: data breach exposes customer information and order details

20 September 2023
Pizza Hut Australia hack: data breach exposes customer information and order details Company says it believes about 193,000 customers are affected by the breach, which it spotted in early SeptemberFollow our Australia news live blog for latest updatesGet our morning and afternoon news emails, free app or daily news podcastPizza Hut’s Australian operations have been hit by a cyber-attack, the company says, with customer data including delivery addresses and order details stolen in the hack.In an email to customers on Wednesday, Pizza Hut Australia’s chief executive, Phil Reed, said the company became aware in early September that there had been “unauthorised third party” access to some of the company’s data.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...

Chinese APT Earth Lusca Adds SprySOCKs Backdoor to its Arsenal

20 September 2023
While monitoring a campaign by Earth Lusca, researchers stumbled across a Linux malware variant derived from the open-source Windows backdoor Trochilus. Named SprySOCKS, the malware is gaining traction for its agility and SOCKS implementation. The group is infamous for targeting government departments and using N-day vulnerabilities.

Trend Micro Releases Urgent Fix for Actively Exploited Critical Security Vulnerability

20 September 2023
Cybersecurity company Trend Micro has released patches and hotfixes to address a critical security flaw in Apex One and Worry-Free Business Security solutions for Windows that has been actively exploited in real-world attacks. Tracked as CVE-2023-41179 (CVSS score: 9.1), it relates to a third-party antivirus uninstaller module that's bundled along with the software. The complete list of impacted

New AMBERSQUID Cryptojacking Operation Targets Uncommon AWS Services

19 September 2023
A novel cloud-native cryptojacking operation has set its eyes on uncommon Amazon Web Services (AWS) offerings such as AWS Amplify, AWS Fargate, and Amazon SageMaker to illicitly mine cryptocurrency.

'ShroudedSnooper' Backdoors Use Ultra-Stealth in Mideast Telecom Attacks

19 September 2023
ShroudedSnooper has targeted Middle East-based telecom firms using two stealthy backdoors, HTTPSnoop and PipeSnoop, which employ advanced anti-detection techniques and can give cyberattackers persistent access to networks.

Inside the Code of a New XWorm Variant

19 September 2023
The configuration of the latest XWorm variant reveals key details such as the host, port, AES key, and Telegram information, providing insights into the malware's operations.

Operation Rusty Flag: Azerbaijan Targeted in New Rust-Based Malware Campaign

19 September 2023
The attack chain involves the use of LNK files and Dropbox to retrieve a second-stage payload, an MSI installer, that drops a Rust backdoor implant and other files on compromised systems.

Energy sector faces 39% of critical infrastructure attacks

19 September 2023
According to a critical infrastructure cyberattack report, almost 60% of attacks are led by state-affiliated actors and 39% targeted energy.

51% of healthcare committed to investing more in cybersecurity

19 September 2023
A recent healthcare security report shows that 86% of healthcare organizations have experienced data theft compared to 80% across all industries.

Gaming and financial service applications most likely to be attacked

19 September 2023
According to a report, 57% of monitored applications are under attack with no correlation between app popularity and likelihood of being attacked.

Payment Card-Skimming Campaign Now Targeting Websites in North America

19 September 2023
A Chinese-speaking threat actor known for skimming credit card numbers off e-commerce sites and point-of-sale service providers in the Asia/Pacific region for more than a year has begun aiming at similar targets in North and Latin America as well.

ShroudedSnooper's HTTPSnoop Backdoor Targets Middle East Telecom Companies

19 September 2023
Telecommunication service providers in the Middle East are the target of a new intrusion set dubbed ShroudedSnooper that employs a stealthy backdoor called HTTPSnoop. "HTTPSnoop is a simple, yet effective, backdoor that consists of novel techniques to interface with Windows HTTP kernel drivers and devices to listen to incoming requests for specific HTTP(S) URLs and execute that content on the

German Spy Chief Warns of Cyberattacks Targeting Liquefied Natural Gas Terminals

19 September 2023
Bruno Kahl, the head of Germany’s foreign intelligence service, warned that liquefied natural gas (LNG) terminals in the country could be targeted by state-sponsored hackers.

Operation Rusty Flag: Azerbaijan Targeted in New Rust-Based Malware Campaign

19 September 2023
Targets located in Azerbaijan have been singled out as part of a new campaign that's designed to deploy Rust-based malware on compromised systems. Cybersecurity firm Deep Instinct is tracking the operation under the name Operation Rusty Flag. It has not been associated with any known threat actor or group. "The operation has at least two different initial access vectors," security researchers

Microsoft AI Research Division Leak 38TB of Private Data

19 September 2023
Cloud security firm Wiz discovered the privacy snafu when it found the GitHub repository “robust-models-transfer,” which belonged to Microsoft’s AI research division, leaking sensitive internal information.

Inside the Code of a New XWorm Variant

19 September 2023
XWorm is a relatively new representative of the remote access trojan cohort that has already earned its spot among the most persistent threats across the globe.  Since 2022, when it was first observed by researchers, it has undergone a number of major updates that have significantly enhanced its functionality and solidified its staying power.  The analyst team at ANY.RUN came across the newest