Latest Cybersecurity News and Articles
31 August 2023
Ransomware attacks are increasingly using stolen or reused strains of malware, making it difficult to attribute attacks to specific groups. Attackers are creating Frankenstein ransomware by combining different pieces of malware.
31 August 2023
On Wednesday, the gang took credit for an attack on the Commission des services electriques de Montréal (CSEM) — a 100-year-old municipal organization that manages electrical infrastructure in the city of Montreal.
31 August 2023
69% of top-performing CISOs dedicate recurring time on their calendars for personal professional development, according to Gartner. This is compared with just 36% of bottom-performing CISOs who do so.
31 August 2023
New findings show that malicious actors could leverage a sneaky malware detection evasion technique and bypass endpoint security solutions by manipulating the Windows Container Isolation Framework.
31 August 2023
Hundreds of thousands of people have been trafficked and forced to work for online scamming operations in south-east Asia run by criminal gangs, according to a UN report.
31 August 2023
Hackers are targeting Cisco Adaptive Security Appliance (ASA) SSL VPNs in credential stuffing and brute-force attacks that take advantage of lapses in security defenses, such as not enforcing multi-factor authentication (MFA).
31 August 2023
A serious flaw affecting several major Border Gateway Protocol (BGP) implementations can be exploited to cause prolonged internet outages, but some vendors are not patching it, a researcher warned on Tuesday.
31 August 2023
Mozilla released Firefox 117 with patches for 13 vulnerabilities, including seven rated ‘high severity’, four of which are described as memory corruption bugs affecting the browser’s components.
31 August 2023
All-in-One WP Migration, a popular data migration plugin for WordPress sites with 5 million active installations, suffers from unauthenticated access token manipulation that could allow attackers to access sensitive site information.
31 August 2023
The phishing attack involves sending an email with a cryptic message and a PDF attachment that claims to detail the recipient's involvement in illegal internet activity related to child pornography, in an attempt to coerce them into responding.
31 August 2023
A hacking outfit nicknamed Earth Estries has been attributed to a new, ongoing cyber espionage campaign targeting government and technology industries based in the Philippines, Taiwan, Malaysia, South Africa, Germany, and the U.S.
"The threat actors behind Earth Estries are working with high-level resources and functioning with sophisticated skills and experience in cyber espionage and illicit
31 August 2023
SailPoint has agreed to purchase U.K.-based privileged access management vendor Osirium for $8.3 million to better protect privileged and non-privileged identities on a single platform.
31 August 2023
Researchers at SlashNext warned that cybercriminals are using a variety of methods, including stealers and stolen cookies, to gain unauthorized access to Airbnb accounts and carry out fraudulent activities.
31 August 2023
A new Android banking trojan called MMRat has been found targeting mobile users in Southeast Asia since June, allowing threat actors to carry out bank fraud on victim's devices. The malware collects personal data, including contact lists and installed apps. To protect against this malware, Android users are advised to check rating, user reviews before downloading apps.
31 August 2023
A threat actor linked to the FIN8 threat group is exploiting a critical vulnerability in unpatched Citrix NetScaler systems, potentially leading to ransomware attacks. In the series of attacks, the attacker carried out the exploitation by inserting two harmful code payloads in different processes. Over 31,000 Citrix NetScaler instances are still vulnerable to the flaw, despite security updates being available for over a month.
30 August 2023
Malware, dubbed Infamous Chisel, enables unauthorised access to compromised Android devices.
30 August 2023
According to a VIPRE Security Group report, 85% of phishing emails sent in Q2 2023 utilized malicious links in the content of the email.
30 August 2023
Cyberattacks and risk management were analyzed in a report. When asked, 18% of respondents report cyberattacks threatened or disrupted their business.
30 August 2023
New findings show that malicious actors could leverage a sneaky malware detection evasion technique and bypass endpoint security solutions by manipulating the Windows Container Isolation Framework.
The findings were presented by Deep Instinct security researcher Daniel Avinoam at the DEF CON security conference held earlier this month.
Microsoft's container architecture (and by extension,
30 August 2023
Cybersecurity researchers have discovered malicious Android apps for Signal and Telegram distributed via the Google Play Store and Samsung Galaxy Store that are engineered to deliver the BadBazaar spyware on infected devices.