Latest Cybersecurity News and Articles


Two LAPSUS$ Hackers Convicted in London Court for High-Profile Tech Firm Hacks

25 August 2023
Two U.K. teenagers have been convicted by a jury in London for being part of the notorious LAPSUS$ transnational gang and for orchestrating a series of brazen, high-profile hacks against major tech firms and demanding a ransom in exchange for not leaking the stolen information. This includes Arion Kurtaj (aka White, Breachbase, WhiteDoxbin, and TeaPotUberHacker), an 18-year-old from Oxford, and

Nearly 1,000 Organizations, 60 Million Individuals Impacted by MOVEit Hack

25 August 2023
On August 14 and 15, the cybercriminals leaked nearly 1 Tb of information allegedly stolen from 16 of the victims, Resecurity said. These victims include UCLA, Siemens Energy, Cognizant, and cybersecurity firms Norton LifeLock and Netscout.

Sextortion Scams Surge 178% in a Year

25 August 2023
The good news is that the scam is an empty threat that aims to play on the victim’s fear of leaking data. By knowing this, they can then be confidently ignored. ESET traced one scam wherein an actor demanded £1000 ($1260) in BTC from the victim.

IT leaders optimistic about how AI will transform their business

25 August 2023
 A new survey of global IT leaders which found that three in four IT leaders are optimistic about the potential benefits of artificial intelligence. 

US Small Business Administration announces $6M in cybersecurity grants

25 August 2023
Six organizations will receive a total of $6 million funding from the U.S. Small Business Administration Cybersecurity for Small Business Pilot Program.

Learn How Your Business Data Can Amplify Your AI/ML Threat Detection Capabilities

25 August 2023
In today's digital landscape, your business data is more than just numbers—it's a powerhouse. Imagine leveraging this data not only for profit but also for enhanced AI and Machine Learning (ML) threat detection. For companies like Comcast, this isn't a dream. It's reality. Your business comprehends its risks, vulnerabilities, and the unique environment in which it operates. No generic,

Title Lender TMX Now Says Payment Card Data Stolen in Breach

25 August 2023
A revised data breach notification is being sent to victims stating that attackers may have also stolen their credit/debit card number, beyond the raft of personal information.

Navigating Legacy Infrastructure: A CISO's Actionable Strategy for Success

25 August 2023
Every company has some level of tech debt. Unless you’re a brand new start-up, you most likely have a patchwork of solutions that have been implemented throughout the years, often under various leadership teams with different priorities and goals. As those technologies age, they can leave your organization vulnerable to cyber threats. While replacing legacy technologies can be costly, those

China-based 'Flax Typhoon' hackers targeting Taiwan govt: Microsoft

25 August 2023
The activities observed suggest the threat actor intends to perform espionage and maintain access to organizations across a broad range of industries for as long as possible.

China-Linked Flax Typhoon Cyber Espionage Targets Taiwan's Key Sectors

25 August 2023
A nation-state activity group originating from China has been linked to cyber attacks on dozens of organizations in Taiwan as part of a suspected espionage campaign. The Microsoft Threat Intelligence team is tracking the activity under the name Flax Typhoon, which is also known as Ethereal Panda. "Flax Typhoon gains and maintains long-term access to Taiwanese organizations' networks with minimal

Time keeps on slippin’ slippin’ slippin’: The 2023 Active Adversary Report for Tech Leaders

25 August 2023
In H1 2023, compromised credentials accounted for 50% of root causes, whereas exploiting a bug came in at 23%. We can’t conclusively say that attackers are favoring compromised credentials over vulnerabilities, but it can’t be denied either.

Researchers released PoC exploit for Ivanti Sentry flaw CVE-2023-38035

25 August 2023
The vulnerability could be exploited to access sensitive API data and configurations, run system commands, or write files onto the system. The vulnerability CVE-2023-38035 impacts Sentry versions 9.18 and prior.

New Luna Grabber Poses as Roblox Packages, Strikes NPM

25 August 2023
Malicious actors are targeting Roblox developers with a new malware called Luna Grabber, distributed through npm packages that impersonate legitimate software. These fake packages, including noblox.js-vps, noblox.js-ssh, and noblox.js-secure, house malicious multi-stage payloads. This campaign underscores the recurring strategy of threat actors employing typosquatting as a tactic to deceive developers.

Rockwell ThinManager Vulnerabilities Could Expose Industrial HMIs to Attacks

25 August 2023
Exploitation of the vulnerabilities can allow causing a denial-of-service (DoS) condition, deleting arbitrary files with system privileges, and uploading arbitrary files to any folder on the drive where ThinServer.exe is installed.

Urgent FBI Warning: Barracuda Email Gateways Vulnerable Despite Recent Patches

25 August 2023
The U.S. Federal Bureau of Investigation (FBI) is warning that Barracuda Networks Email Security Gateway (ESG) appliances patched against a recently disclosed critical flaw continue to be at risk of potential compromise from suspected Chinese hacking groups. It also deemed the fixes as "ineffective" and that it "continues to observe active intrusions and considers all affected Barracuda ESG

WinRAR Zero-Day Actively Exploited to Distribute Malware

25 August 2023
A recently discovered zero-day vulnerability in WinRAR has been exploited in a malware distribution campaign that has been ongoing since April. The vulnerability, known as CVE-2023-3881, allows attackers to create malicious zip archives with spoofed file extensions, concealing them as harmless files. It is highly recommended that users upgrade to the latest version (6.23) of WinRAR.

IT leaders report concern over generative AI in SaaS applications

24 August 2023
When asked in a survey how they would feel if a SaaS vendor used generative AI without their knowledge, more than half of IT leaders reported concern.

Sensitive Data of 10m at Risk After French Employment Agency Breach

24 August 2023
In a public statement published on August 23, 2023, Pôle emploi confirmed “a breach in the information system of one of its service providers, involving a risk of disclosure of jobseekers' personal data.”

Millions stolen from crypto platforms Exactly Protocol and Harbor Protocol

24 August 2023
Two DeFi platforms, Exactly and Harbor, fell victim to cyberattacks resulting in the theft of millions of dollars' worth of cryptocurrency. Exactly Protocol confirmed suffering a loss of around $7.3 million worth of ETH.

Cyberattack disrupts major Mississippi health system

24 August 2023
Despite the shutdown of certain internal systems following the detection of unusual network activity, SRHS disclosed that workarounds have been implemented to ensure the partial continuation of business operations.