Latest Cybersecurity News and Articles


Active North Korean Campaign Targeting Security Researchers

09 September 2023
A new campaign has been discovered with similarities to a previous campaign, including the use of social media sites to build rapport with targets. The threat actors then engage in encrypted messaging and send a malicious file with a 0-day exploit.

DGA Behavior Shifts Raise Cybersecurity Concerns

09 September 2023
Researchers at Akamai have unearthed a concerning shift in the behavior of dynamically seeded Domain Generation Algorithm (DGA) families within Domain Name System (DNS) traffic data.

Cybercriminals Weaponizing Legitimate Advanced Installer Tool in Crypto-Mining Attacks

09 September 2023
A legitimate Windows tool used for creating software packages called Advanced Installer is being abused by threat actors to drop cryptocurrency-mining malware on infected machines since at least November 2021. "The attacker uses Advanced Installer to package other legitimate software installers, such as Adobe Illustrator, Autodesk 3ds Max, and SketchUp Pro, with malicious scripts and uses

CISA, FBI, and CNMF Release Advisory on Multiple Nation-State Threat Actors Exploiting CVE-2022-47966 and CVE-2022-42475

09 September 2023
CISA, FBI, and CNMF confirmed that nation-state APT actors exploited CVE-2022-47966 to gain unauthorized access to a public-facing application (Zoho ManageEngine ServiceDesk Plus), establish persistence, and move laterally through the network.

Weaponized Windows Installers Target Graphic Designers in Crypto Heist

09 September 2023
Attackers execute malicious scripts through a feature of the installer called Custom Action, dropping several payloads — including the M3_Mini_Rat client stub backdoor, Ethereum mining malware PhoenixMiner, and multi-coin mining threat lolMiner.

60% of organizations faced at least one API related breach

08 September 2023
The API threat landscape, including data breaches, sprawl, DDoS attacks and zero trust, was analyzed in a recent report by Traceable AI. 

U.K. and U.S. Sanction 11 Russia-based Trickbot Cybercrime Gang Members

08 September 2023
The U.K. and U.S. governments on Thursday sanctioned 11 individuals who are alleged to be part of the notorious Russia-based TrickBot cybercrime gang. “Russia has long been a safe haven for cybercriminals, including the TrickBot group,” the U.S. Treasury Department said, adding it has “ties to Russian intelligence services and has targeted the U.S. Government and U.S. companies, including

Apple Rushes to Patch Zero-Day Flaws Exploited for Pegasus Spyware on iPhones

08 September 2023
Apple on Thursday released emergency security updates for iOS, iPadOS, macOS, and watchOS to address two zero-day flaws that have been exploited in the wild to deliver NSO Group's Pegasus mercenary spyware.

Chinese Hacker Steals Microsoft Signing Key, Spies on US Government

08 September 2023
A series of unfortunate events allowed the China-backed adversary, which Microsoft tracks as Storm-0558, to gain ‘lawful’ access to the Exchange Online and Azure Active Directory (now called Microsoft Entra ID) accounts of 25 organizations.

Washington DC-based group targeted in apparent Pegasus hack

08 September 2023
Washington DC-based group targeted in apparent Pegasus hack Citizen Lab discovers alleged attack using ‘zero-click exploit’ on individual employed by DC organizationAn individual employed by a Washington DC-based organization with international offices was targeted with powerful hacking software made by NSO Group, researchers have claimed, raising new concerns about the proliferation of spyware that can infect Apple devices.The alleged attack was discovered by researchers at the Citizen Lab at the Munk School at the University of Toronto while they were checking the individual’s device. Continue reading...

Check Point Buys Startup Atmosec to Secure SaaS Applications

08 September 2023
Check Point Software plans to purchase Atmosec, an early-stage SaaS security startup founded by former Armis leaders to anticipate and block threats from malicious applications.

Hackers Claim to Publish Prominent Israeli Hospital’s Patient Data

08 September 2023
The ransomware attack on Mayanei Hayeshua Medical Center resulted in the shutdown of its administrative computer systems, leading the hospital to redirect new patients and those requiring emergency care to other medical centers.

Hackers Exploit Multiple Bugs in Hotel Booking Platform

08 September 2023
Financially motivated hackers developed custom malware to exploit a likely zero-day flaw in popular property management software used by resorts and hotels, said security researchers.

CISA announces secure by design pledge with K-12 education tech providers

08 September 2023
CISA announces a voluntary pledge for K-12 Education Technology software manufacturers to commit to designing products with greater security built in.

IBM Reports Patient Data Breach at Johnson & Johnson Subsidiary

08 September 2023
IBM has worked with the database provider to address the technical issue, but warned Janssen customers about the potential for their personal information to be misused by malicious actors.

Alleged LockBit Ransomware Attack Shuts Down City Networks in Seville

08 September 2023
The council said it will not pay a ransom of $1.5 million demanded by the hackers, according to local media reports. The incident has affected a broad range of city services, including police, firefighters, and tax collection.

See Tickets Alerts 300,000 Customers After Another Web Skimmer Attack

08 September 2023
In a data breach notification letter sent to the affected individuals, a copy of which was submitted to the Maine Attorney General’s Office, See Tickets says the new attack was identified in May 2023 and completely shut down in July.

Mirai Botnet Variant 'Pandora' Hijacks Android TVs for Cyberattacks

08 September 2023
A Mirai botnet variant called Pandora has been observed infiltrating inexpensive Android-based TV sets and TV boxes and using them as part of a botnet to perform distributed denial-of-service (DDoS) attacks.

Protecting Your Microsoft IIS Servers Against Malware Attacks

08 September 2023
Microsoft Internet Information Services (IIS) is a web server software package designed for Windows Server. Organizations commonly use Microsoft IIS servers to host websites, files, and other content on the web. Threat actors increasingly target these Internet-facing resources as low-hanging fruit for finding and exploiting vulnerabilities that facilitate access to IT environments.  Recently, a

Cisco Issues Urgent Fix for Authentication Bypass Bug Affecting BroadWorks Platform

08 September 2023
Cisco has released security fixes to address multiple security flaws, including a critical bug, that could be exploited by a threat actor to take control of an affected system or cause a denial-of service (DoS) condition. The most severe of the issues is CVE-2023-20238, which has the maximum CVSS severity rating of 10.0. It’s described as an authentication bypass flaw in the Cisco BroadWorks