Latest Cybersecurity News and Articles


Thousands of Popular Websites Found Leaking Secrets, Source Code

07 September 2023
An analysis of the exposed credentials by Truffle Security has revealed that AWS and GitHub keys were the most prevalent type of leaked secrets, accounting for 45% of all credentials.

Tenable to Acquire Cloud Security Firm Ermetic for $240 Million

07 September 2023
Exposure management solutions provider Tenable announced on Thursday that it has entered into a definitive agreement to acquire Israeli cloud security startup Ermetic for roughly $240 million in cash and $25 million in restricted stock and RSUs.

Australian Official Slams Firms for Data Breach Reporting Delays

07 September 2023
In the first half of 2023, OAIC received reports of breaches within 30 days after they occurred from 74% of organizations, and just 5% of organizations took longer than four months to report breaches.

Battery Ventures Buys GrammaTech's Application Security Unit

07 September 2023
GrammaTech has separated its security software products and cyber research services divisions, and venture capital firm Battery Ventures has acquired the former and renamed it CodeSecure.

Avoidable Digital Certificate Issues Fuel Data Breaches

07 September 2023
Among organizations that have suffered data breaches 58% were caused by issues related to digital certificates, according to a report by AppViewX and Forrester Consulting.

New report analyses ransomware activity for past 6 months

07 September 2023
A new report reveals the most headline-grabbing cyber extortion event in the first half of 2023 was the Clop ransomware group.

UK Boards Are Growing Less Concerned About Cyber-Risk

07 September 2023
Far fewer board members of UK companies are worried about cyber risk than their global peers, according to the second annual Cybersecurity: The 2023 Board Perspective Report from Proofpoint.

The State of the Virtual CISO Report: MSP/MSSP Security Strategies for 2024

07 September 2023
By the end of 2024, the number of MSPs and MSSPs offering vCISO services is expected to grow by almost 5 fold, as can be seen in figure 1. This incredible surge reflects the growing business demand for specialized cybersecurity expertise and the lucrative opportunities for MSPs and MSSPs in vCISO services. Figure 1: Timeline for offering vCISO services The State of the Virtual CISO Survey Report

Russia Undertakes Disinformation Campaign Across Africa

07 September 2023
Russia has launched sympathetic media outlets, courted anti-French public support, and created fake civil society organizations in turbulent African states, according to an investigation by Microsoft.

Alert: Apache SuperSet Vulnerabilities Expose Servers to Remote Code Execution Attacks

07 September 2023
Patches have been released to address two new security vulnerabilities in Apache SuperSet that could be exploited by an attacker to gain remote code execution on affected systems. The update (version 2.1.1) plugs CVE-2023-39265 and CVE-2023-37941, which make it possible to conduct nefarious actions once a bad actor is able to gain control of Superset’s metadata database. Outside of these

Coffee Meets Bagel Says Recent Outage Caused by Destructive Cyberattack

07 September 2023
At this time, Coffee Meets Bagel has not confirmed if the attack was ransomware that encrypted data, effectively making it unusable, or if the threat actors purposely deleted data to bring down the service.

UK National Cyber Security Centre Gets a New CTO

07 September 2023
The UK’s National Cyber Security Centre (NCSC) has announced its new chief technology officer (CTO) will be Ollie Whitehouse. Whitehouse joins the NCSC from UK-headquartered information assurance firm NCC Group, where he worked for many years.

Feds Publicly Name 130 Healthcare Firms Using Web Trackers

07 September 2023
While the FTC and HHC OCR also publicly disclosed on July 20 that they had sent letters to 130 entities, the regulators at the time did not disclose the identities of the organizations,

CISA Seeks Vendor Commitments to Boost Cybersecurity in K-12 Schools

07 September 2023
CISA Director Jen Easterly said in a statement that the goal of the pledge is to address K-12 cybersecurity issues and help ensure schools and administrators “have access to technology and software that is safe and secure right out of the box.”

Mirai Botnet Variant 'Pandora' Hijacks Android TVs for Cyberattacks

07 September 2023
A Mirai botnet variant called Pandora has been observed infiltrating inexpensive Android-based TV sets and TV boxes and using them as part of a botnet to perform distributed denial-of-service (DDoS) attacks. Doctor Web said the compromises are likely to occur either during malicious firmware updates or when applications for viewing pirated video content are installed. "It is likely that this

Ukraine's CERT Thwarts APT28's Cyberattack on Critical Energy Infrastructure

07 September 2023
The Computer Emergency Response Team of Ukraine (CERT-UA) on Tuesday said it thwarted a cyber attack against an unnamed critical energy infrastructure facility in the country.

Peiter 'Mudge' Zatko Lands Role as CISA Senior Technical Adviser

07 September 2023
The U.S. government’s cybersecurity agency CISA on Monday confirmed the addition of Peiter ‘Mudge’ Zatko to its roster of prominent voices preaching the gospel of security-by-design and secure-by-default development principles.

Experts Uncover Underground Phishing “Empire” W3LL Targeting 56,000 Microsoft 365 Accounts

07 September 2023
Security researchers have uncovered a new covert phishing operation selling sophisticated tools used to target an estimated 56,000 Microsoft 365 accounts in just a 10-month period.

MITRE and CISA Release Open Source Tool for OT Attack Emulation

07 September 2023
The new Caldera for OT extension is the result of a collaboration between the Homeland Security Systems Engineering and Development Institute (HSSEDI) and CISA, to help improve the resilience of critical infrastructure.

Hawai’i State Department of Health Resolves Website Defacement

07 September 2023
The incident affected healthybydefault.hawaii.gov — a website created by the Hawai?i State Department of Health (DOH) in compliance with a 2020 state law that mandates healthy beverages be the default option in children’s meals.