Latest Cybersecurity News and Articles


Update: Australian Law Firm Hack Affected 65 Government Agencies

19 September 2023
An April ransomware attack against one of Australia's largest law firms swept up the data of 65 Australian government agencies, the country's newly appointed national cybersecurity coordinator said Monday.

Earth Lusca's New SprySOCKS Linux Backdoor Targets Government Entities

19 September 2023
The China-linked threat actor known as Earth Lusca has been observed targeting government entities using a never-before-seen Linux backdoor called SprySOCKS. Earth Lusca was first documented by Trend Micro in January 2022, detailing the adversary's attacks against public and private sector entities across Asia, Australia, Europe, North America. Active since 2021, the group has relied on

Fraudsters Steal Over $1 Million in Three Weeks in ‘Pig Butchering’ Scam

19 September 2023
The attackers utilized fake trading pools of cryptocurrency from decentralized finance (DeFi) trading applications to defraud their victims, with one individual losing $22,000 in a single week.

New Hook Android Banking Trojan Expands on ERMAC's Legacy

19 September 2023
"All commands (30 in total) that the malware operator can send to a device infected with ERMAC malware, also exist in Hook. The code implementation for these commands is nearly identical," NCC Group security researchers said.

Live Webinar: Overcoming Generative AI Data Leakage Risks

19 September 2023
As the adoption of generative AI tools, like ChatGPT, continues to surge, so does the risk of data exposure. According to Gartner’s "Emerging Tech: Top 4 Security Risks of GenAI" report, privacy and data security is one of the four major emerging risks within generative AI. A new webinar featuring a multi-time Fortune 100 CISO and the CEO of LayerX, a browser extension solution, delves into this

Update: Clorox Reports Production Issues After August Cyberattack

19 September 2023
In regulatory filings with the SEC, the company said the cyberattack “damaged portions of the Company’s IT infrastructure, which caused widescale disruption of Clorox’s operations.”

Metaverse Poses Serious Privacy Risks for Users, Report Warns

19 September 2023
The immersive internet experience known as the metaverse will erode users’ privacy unless significant steps are taken to improve and regulate how the technology captures and stores personal data, a new report from New York University argues.

Thousands of Juniper Devices Vulnerable to Unauthenticated RCE Flaw

19 September 2023
Today, VulnCheck vulnerability researcher Jacob Baines released another PoC exploit that only utilizes CVE-2023-36845, bypassing the need to upload files while still achieving remote code execution.

Over 12,000 Juniper Firewalls Found Vulnerable to Recently Disclosed RCE Vulnerability

19 September 2023
New research has found that close to 12,000 internet-exposed Juniper firewall devices are vulnerable to a recently disclosed remote code execution flaw. VulnCheck, which discovered a new exploit for CVE-2023-36845, said it could be exploited by an "unauthenticated and remote attacker to execute arbitrary code on Juniper firewalls without creating a file on the system." CVE-2023-36845 refers to a

An Assessment of Russian Threat Group Turla (aka Pensive Ursa)

19 September 2023
The top 10 most recently active types of malware used by Pensive Ursa include Capibar, Kazuar, Snake, QUIETCANARY, Kopiluwak, Crutch, ComRAT, Carbon, HyperStack, and TinyTurla, with each having distinct functionalities and attack techniques.

Bumblebee Loader Resurfaces in New Campaign

19 September 2023
Bumblebee, a loader used by ransomware threat actors, has recently resurfaced with new distribution techniques and updates to make it more resilient and harder to disrupt.

Transparent Tribe’s CapraRAT Mimics YouTube to Hijack Android Phones

19 September 2023
The CapraRAT mobile RAT hidden within these YouTube-themed apps gives the attacker control over various data on infected Android devices, including recording audio and video, collecting messages and call logs, and modifying files.

Transparent Tribe Uses Fake YouTube Android Apps to Spread CapraRAT Malware

19 September 2023
The suspected Pakistan-linked threat actor known as Transparent Tribe is using malicious Android apps mimicking YouTube to distribute the CapraRAT mobile remote access trojan (RAT), demonstrating the continued evolution of the activity. "CapraRAT is a highly invasive tool that gives the attacker control over much of the data on the Android devices that it infects," SentinelOne security

Microsoft AI Researchers Accidentally Expose 38 Terabytes of Confidential Data

19 September 2023
Microsoft on Monday said it took steps to correct a glaring security gaffe that led to the exposure of 38 terabytes of private data. The leak was discovered on the company's AI GitHub repository and is said to have been inadvertently made public when publishing a bucket of open-source training data, Wiz said. It also included a disk backup of two former employees' workstations containing secrets

Who’s Behind the 8Base Ransomware Website?

18 September 2023
The victim shaming website operated by the cybercriminals behind 8Base -- currently one of the more active ransomware groups -- was until earlier today leaking quite a bit of information that the crime group probably did not intend to be made public. The leaked data suggests that at least some of website's code was written by a 36-year-old programmer residing in the capital city of Moldova.

Nuance Communications announces data breach affecting healthcare

18 September 2023
St. Luke's Health Systems in Boise, Idaho informed patients of a data breach involving Nuance Communications and MOVEit Transfer software.

Lazarus APT Stole Almost $240 Million in Crypto Assets Since June

18 September 2023
According to a report by Elliptic, the North Korea-linked APT group Lazarus has stolen most of $240 million in crypto assets from multiple businesses, including Atomic Wallet ($100m), CoinsPaid ($37.3M), Alphapo ($60M), and Stake.com ($41M).

ETH Founder Vitalik Buterin’s X (Twitter) Hacked, $700k Stolen

18 September 2023
Regarding how the hacking was successful, it is reported that the hacker compromised Buterin’s account and shared a post on his behalf, celebrating the arrival of Proto-Danksharding to the Ethereum platform.

Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement

18 September 2023
Earth Lusca, a China-linked threat actor, has developed a Linux variant of the backdoor malware SprySOCKS, which originated from the open-source Windows backdoor Trochilus, indicating their continued active operations and expansion.

CardX Issues Data Leak Notification Impacting Their Customers in Thailand

18 September 2023
Thailand-based digital financial platform, CardX, experienced a data leak exposing personal information of customers, including names, addresses, phone numbers, and emails.