Latest Cybersecurity News and Articles


Some of the Top Universities Wouldn’t Pass Cybersecurity Exam: Left Websites Vulnerable

11 September 2023
Many universities worldwide, including some of the most prestigious, leave their webpages unpatched, leaking sensitive information, and even open to full takeovers, a Cybernews Research team investigation reveals.

Vulnerabilities Allow Hackers to Hijack, Disrupt Socomec UPS Devices

11 September 2023
Aaron Flecha Menendez, an ICS security consultant at Spain-based cybersecurity firm S21sec, discovered that some Socomec UPS devices, specifically MODULYS GP (MOD3GP-SY-120K), are affected by seven vulnerabilities.

Anjana Harve named EVP, Chief Information Officer at BJ's Wholesale Club

11 September 2023
Anjana Harve has been named Executive VP, Chief Information Officer at BJ's Wholesale Club. Harve has worked as CIO in a variety of organizations.

IT Systems Encrypted After UK School Hit By Ransomware

11 September 2023
A spate of cyberattacks against UK schools has claimed its latest victim after a Maidstone secondary school, Church of England St Augustine Academy, suffered a serious security breach late last week.

Report: 75% of Education Sector Attacks Linked to Compromised Accounts

11 September 2023
According to a report by Netwrix, 69% of organizations in the education sector have experienced a cyberattack in the past year. Phishing and user account compromise were the most common attack methods in this sector.

Vietnamese Hackers Deploy Python-Based Stealer via Facebook Messenger

11 September 2023
A new phishing attack is leveraging Facebook Messenger to propagate messages with malicious attachments from a "swarm of fake and hijacked personal accounts" with the ultimate goal of taking over the targets' accounts. "Originating yet again from a Vietnamese-based group, this campaign uses a tiny compressed file attachment that packs a powerful Python-based stealer dropped in a multi-stage

New HijackLoader Malware Used to Distribute Various Malware Families

11 September 2023
A new malware loader known as HijackLoader has gained popularity among cybercriminals for distributing various payloads, including DanaBot, SystemBC, and RedLine Stealer. HijackLoader uses a modular architecture that facilitates threat actors to perform code injection and execution. Organizations must stay updated about the tactics and techniques used by the malware loader and deploy multi-layered sandbox techniques to detect indicators

Rhysida Ransomware Gang Claims to Have Hacked Three More US Hospitals

11 September 2023
The Singing River Health System, which operates three hospitals and 10 clinics, experienced a cyberattack that disrupted various services, including laboratory and radiology testing.

Generative AI, Contactless Tech Make Hotels Vulnerable to Cyberattacks

11 September 2023
The transition to mobile and contactless services in the hospitality industry is making hotels more vulnerable to cyber threats, according to a report from Trustwave SpiderLabs.

Charming Kiten's New Backdoor 'Sponsor' Targets Brazil, Israel, and U.A.E.

11 September 2023
The Iranian threat actor known as Charming Kiten has been linked to a new wave of attacks targeting different entities in Brazil, Israel, and the U.A.E. using a previously undocumented backdoor named Sponsor. Slovak cybersecurity firm is tracking the cluster under the name Ballistic Bobcat. Victimology patterns suggest that the group primarily singles out education, government, and healthcare

Cybercriminals Using PowerShell to Steal NTLMv2 Hashes from Compromised Windows

11 September 2023
A new cyberattack campaign is leveraging the PowerShell script associated with a legitimate red teaming tool to plunder NTLMv2 hashes from compromised Windows systems primarily located in Australia, Poland, and Belgium.

CISA Director Says Critical Infrastructure Cyber Incident Reporting Rules Almost Ready

11 September 2023
Final work is underway for the Cyber Incident Reporting for Critical Infrastructure Act, which CISA Director Jen Easterly expects to be done by the end of the year or early 2024 at the latest, she said at the Billington Cybersecurity Summit.

AP Stylebook Breach May Have Hit Hundreds of Journalists

11 September 2023
The Associated Press (AP) has warned that users of a popular writing style guide have been hit by phishing attacks after their personal information was compromised in a data breach.

Baseline Standards for BYOD Access Requirements

11 September 2023
According to a survey by Jamf, nearly half of European enterprises lack a formal BYOD policy, leaving them vulnerable to data security risks associated with employees connecting personal devices to corporate resources.

Microsoft Teams Phishing Attack Pushes DarkGate Malware

11 September 2023
The campaign started in late August 2023, when Microsoft Teams phishing messages were seen being sent by two compromised external Office 365 accounts to other organizations.

Russian Infosec Boss Gets Nine Years Sentence for Hack-And-Trade Operation

11 September 2023
Russian owner of security firm M-13, Vladislav Klyushin, has been sentenced to nine years in prison for his role in a cybercrime operation that stole confidential financial information and made $93 million through insider trading.

Microsoft Teams Phishing Campaign Deploys DarkGate Malware

11 September 2023
A recent phishing campaign leverages Microsoft Teams messages to disseminate the powerful DarkGate Loader malware via malicious attachments. The existing security measures in Microsoft Teams, such as Safe Attachments and Safe Links, were unable to identify or prevent this attack. 

How to Prevent API Breaches: A Guide to Robust Security

11 September 2023
With the growing reliance on web applications and digital platforms, the use of application programming interfaces (APIs) has become increasingly popular. If you aren’t familiar with the term, APIs allow applications to communicate with each other and they play a vital role in modern software development. However, the rise of API use has also led to an increase in the number of API breaches.

Dymocks Booksellers Suffers Data Breach Impacting 836,000 Customers

11 September 2023
The company was informed that its customer data was stolen on September 6th, 2023, by Troy Hunt, the creator of the data breach notification service 'Have I Been Pwned' (HIBP), after a threat actor released it on a hacking forum.

Google Chrome Rolls Out Support for 'Privacy Sandbox' to Bid Farewell to Tracking Cookies

11 September 2023
Google has officially begun its rollout of Privacy Sandbox in the Chrome web browser to a majority of its users, nearly four months after it announced the plans. "We believe it is vital to both improve privacy and preserve access to information, whether it's news, a how-to-guide, or a fun video," Anthony Chavez, vice president of Privacy Sandbox initiatives at Google, said. "Without viable