Latest Cybersecurity News and Articles


Critical GitHub Vulnerability Exposes 4,000+ Repositories to Repojacking Attack

12 September 2023
A new vulnerability disclosed in GitHub could have exposed thousands of repositories at risk of repojacking attacks, new findings show. The flaw "could allow an attacker to exploit a race condition within GitHub's repository creation and username renaming operations," Checkmarx security researcher Elad Rapoport said in a technical report shared with The Hacker News. "Successful exploitation of

White House mulls rating system to boost cybersecurity for critical infrastructure

12 September 2023
At a recent summit, Anne Neuberger, deputy national security advisor for cyber and emerging technology, raised the possibility of a letter-grade rating that would hold key providers accountable for maintaining a certain level of cyber resilience.

MGM Resorts Confirms ‘Cybersecurity Issue’, Shuts Down Systems

12 September 2023
Hospitality and entertainment giant MGM Resorts on Monday said a “cybersecurity issue” forced the shutdown of certain computer systems, including the websites for some of the biggest Las Vegas and New York properties.

7 Steps to Kickstart Your SaaS Security Program

12 September 2023
SaaS applications are the backbone of modern businesses, constituting a staggering 70% of total software usage. Applications like Box, Google Workplace, and Microsoft 365 are integral to daily operations. This widespread adoption has transformed them into potential breeding grounds for cyber threats. Each SaaS application presents unique security challenges, and the landscape constantly evolves

Google Rolls Out Privacy Sandbox to Use Chrome Browsing History for Ads

12 September 2023
Google has started to roll out its new interest-based advertising platform called the Privacy Sandbox, shifting the tracking of user's interests from third-party cookies to the Chrome browser.

Chinese Redfly Group Compromised a Nation's Critical Grid in 6-Month ShadowPad Campaign

12 September 2023
A threat actor called Redfly has been linked to a compromise of a national grid located in an unnamed Asian country for as long as six months earlier this year using a known malware referred to as ShadowPad. "The attackers managed to steal credentials and compromise multiple computers on the organization's network," the Symantec Threat Hunter Team, part of Broadcom, said in a report shared with

Ransomware Attack Wipes Out Four Months of Sri Lankan Government Data

12 September 2023
The attack likely started on August 26, 2023, when a gov[dot]lk domain user said they had received suspicious links over the past few weeks and that someone may have clicked one.

Sophisticated Phishing Campaign Deploying Agent Tesla, OriginBotnet, and RedLine Clipper

12 September 2023
A sophisticated phishing campaign is using a Microsoft Word document lure to distribute a trifecta of threats, namely Agent Tesla, OriginBotnet, and OriginBotnet, to gather a wide range of information from compromised Windows machines. "A phishing email delivers the Word document as an attachment, presenting a deliberately blurred image and a counterfeit reCAPTCHA to lure the recipient into

Spies, Hackers, Informants: How China Snoops on the West

12 September 2023
China's cyber espionage activities, including hacking into rival nations' digital systems, pose a significant threat to the government and private sector of Western countries.

Google Patches Chrome Zero-Day Reported by Apple, Spyware Hunters

12 September 2023
Google on Monday released an emergency Chrome 116 security update to patch the fourth zero-day vulnerability discovered in the browser in 2023. Tracked as CVE-2023-4863, it is a critical severity heap buffer overflow issue in the WebP component.

Powerful Ethnic Militia in Myanmar Repatriates 1,200 Chinese Suspected of Involvement in Cybercrime

12 September 2023
One of Myanmar’s biggest and most powerful ethnic minority militias has arrested and repatriated more than 1,200 Chinese nationals allegedly involved in criminal online scam operations, an official of the group said Saturday.

New Quantum Random Number Generator Could Revolutionize Encryption

12 September 2023
Digital information exchange can be safer, cheaper and more environmentally friendly with the help of a new type of random number generator for encryption developed at Linköping University.

Email Forwarding Flaws Enable Attackers to Impersonate High-Profile Domains

12 September 2023
Sending an email with a forged address is easier than previously thought, due to flaws in the process that allows email forwarding, according to a research team led by computer scientists at the University of California San Diego.

China Unleashes AI-Powered Image Generation For Influence Operations

12 September 2023
In particular, China-affiliated actors are employing AI-generated media to target politically divisive topics such as gun violence and disparaging US political figures and symbols.

Update: FBI Blames North Korean Hackers for $41 Million Stake.com Heist

12 September 2023
The incident occurred on September 4, when the Australian-Curaçaoan online platform Stake.com announced that hackers had stolen funds from its Ethereum (ETH) and Binance Smart Chain (BSC) hot wallets.

Beware: MetaStealer Malware Targets Apple macOS in Recent Attacks

12 September 2023
A new information stealer malware called MetaStealer has set its sights on Apple macOS, making the latest in a growing list of stealer families focused on the operating system after Stealer, Pureland, Atomic Stealer, and Realst. "Threat actors are proactively targeting macOS businesses by posing as fake clients in order to socially engineer victims into launching malicious payloads," SentinelOne

Google Rushes to Patch Critical Chrome Vulnerability Exploited in the Wild - Update Now

12 September 2023
Google on Monday rolled out out-of-band security patches to address a critical security flaw in its Chrome web browser that it said has been exploited in the wild. Tracked as CVE-2023-4863, the issue has been described as a case of heap buffer overflow that resides in the WebP image format that could result in arbitrary code execution or a crash. Apple Security Engineering and Architecture (SEAR

Rising fraud is damaging consumer trust

12 September 2023
Consumers reveal how rising fraud impacts their trust in organizations.

NCSC CEO and Information Commissioner sign Memorandum of Understanding

11 September 2023
The joint MoU sets out how the organisations will cooperate to improve the UK's digital resilience.

CISA and FBI release joint cybersecurity advisory

11 September 2023
CISA, the Federal Bureau of Investigation and U.S. Cyber Command’s Cyber National Mission Force (CNMF) released a joint Cybersecurity Advisory (CSA).