Latest Cybersecurity News and Articles
23 August 2023
Phishing attacks using open redirect flaws are on the rise again, according to Kroll’s Cyber Threat Intelligence (CTI) team, which means organizations should consider refreshing employees’ awareness and knowledge on how to spot them.
23 August 2023
Meta has once again reaffirmed its plans to roll out support for end-to-end encryption (E2EE) by default for one-to-one friends and family chats on Messenger by the end of the year.
As part of that effort, the social media giant said it's upgrading "millions more people's chats" effective August 22, 2023, exactly seven months after it started gradually expanding the feature to more users in
23 August 2023
This data includes a mixture of public login and real names, and non-public information, including email addresses and internal information related to the DuoLingo service.
23 August 2023
Jeremy Ventura, Director of Security Strategy & Field CISO at ThreatX, discusses challenges associated with the use of generative AI in cybersecurity, and more. in this episode of The Security Podcast.
23 August 2023
A new survey highlights what application security professionals view as the top security risks related to Application Programming Interfaces (APIs).
23 August 2023
A new study reveals 30% of parents haven't had conversations with their children about cybersecurity.
23 August 2023
A Syrian threat actor named EVLF has been outed as the creator of malware families CypherRAT and CraxsRAT.
"These RATs are designed to allow an attacker to remotely perform real-time actions and control the victim device's camera, location, and microphone," Cybersecurity firm Cyfirma said in a report published last week.
CypherRAT and CraxsRAT are said to be offered to other cybercriminals as
23 August 2023
Developers are not the only people who have adopted the agile methodology for their development processes. From 2023-06-15 to 2023-07-11, Permiso Security’s p0 Labs team identified and tracked an attacker developing and deploying eight (8) incremental iterations of their credential harvesting malware while continuing to develop infrastructure for an upcoming (spoiler: now launched) campaign
23 August 2023
Researchers at ReversingLabs have discovered a malicious campaign targeting Roblox developers on the npm public repository. The campaign involves malicious packages that imitate the legitimate package noblox.js, a Node.js Roblox API wrapper.
23 August 2023
Zoom updated its terms and conditions — again — on Friday following persistent criticism related to language that allowed the company to use customer data to train its AI systems.
23 August 2023
The Austin, Texas-based electric car manufacturer began notifying affected individuals Friday, as part of its ongoing probe into a May data breach it blamed on "insider wrongdoing."
23 August 2023
A report from Critical Insight notes an overall decrease of 15% in total breaches during the first half of 2023 compared to the latter half of 2022 – a positive development given the healthcare industry’s previous upward trend in attacks.
23 August 2023
A malicious toolset dubbed Spacecolon is being deployed as part of an ongoing campaign to spread variants of the Scarab ransomware across victim organizations globally.
"It probably finds its way into victim organizations by its operators compromising vulnerable web servers or via brute forcing RDP credentials," ESET security researcher Jakub Souček said in a detailed technical write-up
23 August 2023
Threat actors are exploiting paid Facebook promotions featuring LLMs to spread malware and steal victims' credentials. The malicious code is distributed through fake profiles and ads promising access to AI tools like Google Bard or Meta AI.
23 August 2023
Agniane Stealer is a new information stealer malware that targets credentials, system information, and cryptocurrency wallets, and is available for sale on dark web forums.
23 August 2023
More than a dozen malicious packages have been discovered on the npm package repository since the start of August 2023 with capabilities to deploy an open-source information stealer called Luna Token Grabber on systems belonging to Roblox developers.
The ongoing campaign, first detected on August 1 by ReversingLabs, employs modules that masquerade as the legitimate package noblox.js, an API
22 August 2023
Browser extension security was analyzed in a recent report by Spin.AI, finding extensions with unknown authors attached to personal email accounts.
22 August 2023
In large metropolitan areas, tourists are often easy to spot because they're far more inclined than locals to gaze upward at the surrounding skyscrapers. Security experts say this same tourist dynamic is a dead giveaway in virtually all computer intrusions that lead to devastating attacks like ransomware, and that more organizations should set simple virtual tripwires that sound the alarm when authorized users and devices are spotted exhibiting this behavior.
22 August 2023
Threat actors are reportedly exploiting APK files that employ unknown or unsupported compression methods to bypass malware analysis, warned cybersecurity firm Zimperium. The approach hinders decompilation efforts while still enabling installation on Android devices running OS versions above Android 9 Pie. Zimperium found 3,300 instances of this tactic in the wild, with 71 of them being compatible with the operating system
22 August 2023
Clop was responsible for one-third of all ransomware attacks in July, positioning the financially-motivated threat actor to become the most prolific ransomware threat actor this summer, according to multiple threat intelligence reports.