Latest Cybersecurity News and Articles
01 September 2023
Topgolf Callaway (Callaway) suffered a data breach at the start of August, which exposed the sensitive personal and account data of more than a million customers. Callaway is an American golf equipment maker and seller.
01 September 2023
More than 100,000 Pima County residents could be affected by a nationwide data breach that affected the company that handled COVID-19 case investigations and contact tracing here, officials say.
01 September 2023
Some customers of the network security company LogicMonitor have been hacked due to the use of default passwords, TechCrunch has learned. A LogicMonitor spokesperson confirmed “a security incident” affecting some of the company’s customers.
01 September 2023
Also known as keygroup777, Key Group is a Russian-speaking cybercrime actor known for selling personally identifiable information (PII) and access to compromised devices, as well as extorting victims for money.
01 September 2023
According to the platform, the admin access token used in the attack was leaked in a July 14 commit that passed internal code analysis tools. The token “had broad privileges to view and modify account information on Sourcegraph.com”.
01 September 2023
The intrusion singled out an unnamed activist, who was contacted in late August 2023 and received a malicious LNK file from an address impersonating a member of the organization, non-profit entity Interlabs said in a new report.
01 September 2023
Threat actors are exploiting poorly secured Microsoft SQL (MS SQL) servers to deliver Cobalt Strike and a ransomware strain called FreeWorld.
Cybersecurity firm Securonix, which has dubbed the campaign DB#JAMMER, said it stands out for the way the toolset and infrastructure is employed.
“Some of these tools include enumeration software, RAT payloads, exploitation and credential stealing software
01 September 2023
Domain names ending in “.US” — the top-level domain for the United States — are among the most prevalent in phishing scams, new research shows. This is noteworthy because .US is overseen by the U.S. government, which is frequently the target of phishing domains ending in .US. Also, .US domains are only supposed to be available to U.S. citizens and to those who can demonstrate that they have a physical presence in the United States.
01 September 2023
According to a cybersecurity trends report, malware was the top online consumer threat from May to July 2023, accounting for 58% of all detections.
01 September 2023
Among the methods employed by cybercriminals to carry out the scheme is to trick users into buying falsely-advertised goods or services via social engineering schemes and directing potential victims to the automatically generated phishing sites.
01 September 2023
CISA recently published a joint report on a malware campaign conducted by Russian cyber actors against the Ukrainian military.
01 September 2023
Western intelligence and cybersecurity agencies published a report on Thursday highlighting a collection of hacking tools being used by Russia’s military intelligence service against Android devices operated by the Ukrainian Armed Forces.
01 September 2023
Healthcare organizations are facing many cybersecurity challenges that require them to increasingly prioritize cybersecurity and compliance, according to a report by Claroty.
01 September 2023
Multiple actors are using SapphireStealer, modifying and improving the original code to create several variants. The malware is often delivered through multi-stage infection processes, with attackers using open-source loaders like FUD-Loader.
01 September 2023
Cybersecurity and intelligence agencies from Australia, Canada, New Zealand, the U.K., and the U.S. on Thursday disclosed details of a mobile malware strain targeting Android devices used by the Ukrainian military.
The malicious software, dubbed Infamous Chisel and attributed to a Russian state-sponsored actor called Sandworm, has capabilities to “enable unauthorized access to compromised
01 September 2023
The campaign, conducted by a group called "Smishing Triad," impersonates various postal services and government agencies to deceive victims into providing personal and financial information.
01 September 2023
A new phishing attack likely targeting civil society groups in South Korea has led to the discovery of a novel remote access trojan called SuperBear.
The intrusion singled out an unnamed activist, who was contacted in late August 2023 and received a malicious LNK file from an address impersonating a member of the organization, non-profit entity Interlabs said in a new report.
The LNK file, upon
01 September 2023
As cyber threats continue to evolve, adversaries are deploying a range of tools to breach security defenses and compromise sensitive data. Surprisingly, one of the most potent weapons in their arsenal is not malicious code but simply stolen or weak usernames and passwords. This article explores the seriousness of compromised credentials, the challenges they present to security solutions, and the
01 September 2023
Forsyth County officials had acknowledged an attack in June, but offered few details about what happened. On Tuesday, AlphV took credit for the attack and added the county to its leak site, threatening to expose 350GB of allegedly stolen data.
01 September 2023
On July 11, 2023, Prime became aware that an unauthorized actor obtained access to an employee's mobile email account containing documents that included members' PHI, including name, address, date of birth, member ID number, and medication(s).