Latest Cybersecurity News and Articles


Nine Vulnerabilities Patched in SEL Power System Management Products

06 September 2023
Nine vulnerabilities, including potentially serious flaws, were patched recently in a couple of electric power management products made by Schweitzer Engineering Laboratories (SEL).

Nascent Malware Campaign Targets npm, PyPI, and RubyGems Developers

06 September 2023
A malware campaign targeting software developers in multiple ecosystems (PyPI, npm, and RubyGems) has been discovered, with packages collecting and exfiltrating data from macOS machines.

Evil MinIO Exploits: A New Attack Vector to Breach Corporate Networks

06 September 2023
An unidentified threat actor weaponized critical security holes in the MinIO high-performance object storage system, gaining unauthorized code execution on targeted servers. Upon launching the application, attackers exploit the flaws to add a backdoor that allows them to conduct remote code execution attacks on victims’ systems. It is recommended to apply the available security update to protect their assets from Evil MinIO exploit attacks.

Yes, There's an npm Package Called @(-.-)/env and Some Others Like it

06 September 2023
These packages have unconventional names and some of them do not follow naming guidelines. While not all of them pose a security risk, they could potentially cause confusion or break software development tooling.

W3LL Store: How a Secret Phishing Syndicate Targets 8,000+ Microsoft 365 Accounts

06 September 2023
A previously undocumented "phishing empire" has been linked to cyber attacks aimed at compromising Microsoft 365 business email accounts over the past six years. "The threat actor created a hidden underground market, named W3LL Store, that served a closed community of at least 500 threat actors who could purchase a custom phishing kit called W3LL Panel, designed to bypass MFA, as well as 16

New BLISTER Malware Update Fuelling Stealthy Network Infiltration

06 September 2023
"New BLISTER update includes keying feature that allows for precise targeting of victim networks and lowers exposure within VM/sandbox environments," Elastic Security Labs researchers said in a technical report published late last month.

Ukraine's CERT Thwarts APT28's Cyberattack on Critical Energy Infrastructure

06 September 2023
The Computer Emergency Response Team of Ukraine (CERT-UA) on Tuesday said it thwarted a cyber attack against an unnamed critical energy infrastructure facility in the country. The intrusion, per the agency, started with a phishing email containing a link to a malicious ZIP archive that activates the infection chain. “Visiting the link will download a ZIP archive containing three JPG images (

Ransomware Attacks Soar by 87% in U.K, Reveals JUMPSEC

06 September 2023
A report from JUMPSEC noted an 87% increase in attacker-reported ransomware in the U.K and a 37% globally in H1 2023. The mass exploitation of vulnerabilities is the primary contributor to this growth.  One key reason for the surge in attack figures is due to the growing number of ransomware variants.Organizations must continually enhance their strategies for responding to cyber extortion.

Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach

05 September 2023
In November 2022, the password manager service LastPass disclosed a breach in which hackers stole password vaults containing both encrypted and plaintext data for more than 25 million users. Since then, a steady trickle of six-figure cryptocurrency heists targeting security-conscious people throughout the tech industry has led some security experts to conclude that crooks likely have succeeded at cracking open some of the stolen LastPass vaults.

71% of organizations are impacted by cybersecurity skills shortage

05 September 2023
According to a recent report on security leaders, a career in cybersecurity is becoming more difficult in an increasingly challenging environment.

65% of organizations prioritize vulnerabilities based on risk

05 September 2023
A recent report by Syxsense shows that 78% of respondents report experiencing an increase in vulnerability volume over the past 12 months.

Suspected ALPHV Ransomware Attack on Melbourne Pathology Clinic Possibly Exposed Patient Data

05 September 2023
The Australian government is aware of the data breach as well as potential incidents affecting real estate firm Barry Plant and owners corporation management company Strata Plan, national cybersecurity coordinator Darren Goldie said in a statement.

More UK Schools Hit by Cyberattacks Before Term Begins

05 September 2023
Highgate Wood School in Crouch End will now begin accepting pupils on September 11 rather than September 5 as originally intended. The secondary school, which serves local students aged 11–16, appears to have escaped the worst of the attack.

New Chaes Malware Variant Targeting Financial and Logistics Customers

05 September 2023
This new variant, primarily targeting logistics and financial sectors, has undergone significant changes, including being rewritten in Python, enhanced communication protocols, and new modules.

Amerita and PharMerica announce data breach

05 September 2023
Amerity and parent company announced a data breach that exposed personal information after learning of suspicious activity on their computer network.

Researchers Warn of Cyber Weapons Used by Lazarus Group's Andariel Cluster

05 September 2023
Some of the malware families employed by Andariel in its attacks include Gh0st RAT, DTrack, YamaBot, NukeSped, Rifdoor, Phandoor, Andarat, Andaratm, TigerRAT (and its successor MagicRAT), and EarlyRAT.

Swedish Insurer Trygg-Hansa Fined $3M for Exposing Data of 650,000 Clients for Two Years

05 September 2023
About 650,000 customers have been impacted. The information exposed included personal data, health information, condition details, financial information, contact details, Social Security numbers, and insurance details.

New BLISTER Malware Update Fuelling Stealthy Network Infiltration

05 September 2023
An updated version of a malware loader known as BLISTER is being used as part of SocGholish infection chains to distribute an open-source command-and-control (C2) framework called Mythic. “New BLISTER update includes keying feature that allows for precise targeting of victim networks and lowers exposure within VM/sandbox environments,” Elastic Security Labs researchers Salim Bitam and Daniel

Cybercriminals Use Research Contests to Create New Attack Methods

05 September 2023
The contests mirror legitimate security conference ‘Call For Papers’ and provide the winners considerable financial rewards, recognition from peers, and also, potential jobs.

Exploring the Traits of Effective Chief Audit Executives

05 September 2023
Chief audit executives (CAEs) have identified risk orientation, stakeholder management, and team leadership as the top three characteristics of the most effective individuals, according to Gartner.