Latest Cybersecurity News and Articles


US CISA Urges Security by Design for AI

22 August 2023
The U.S federal government is advocating for artificial intelligence developers to embrace security as a core requirement, warning that machine learning code is particularly difficult and expensive to fix after deployment.

French Town of Sartrouville Recovering From Cyberattack Claimed by Ransomware Gang

22 August 2023
Officials noted that the town’s IT department has set up a “robust” backup system that allowed them to preserve critical data and “minimize disruption to the operation of municipal services.

Rust Developers Push Back as Serde Project Ships Precompiled Binaries

22 August 2023
Serde is a commonly used serialization and deserialization framework for Rust data structures that, according to its website, is designed to conduct these operations "efficiently and generically."

Critical Adobe ColdFusion Flaw Added to CISA's Exploited Vulnerability Catalog

22 August 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw in Adobe ColdFusion to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

Police Insider Tipped Off Criminal Friend About EncroChat Bust

22 August 2023
An intelligence analyst working for police in the North West of England shared information about a major countrywide operation with a criminal contact, in what has been described as a “disgraceful” betrayal of her colleagues.

Ivanti Warns of New Actively Exploited Sentry Zero-Day Bug

22 August 2023
Discovered and reported by researchers at mnemonic, the critical vulnerability enables unauthenticated attackers to gain access to sensitive admin portal configuration APIs exposed over port 8443, used by MobileIron Configuration Service (MICS).

Australian Lender Latitude Financial Reports $50 Million in Cyberattack Costs

22 August 2023
In a financial report covering the first half of 2023, the consumer lender reported AU$76 million (roughly US$50 million) of pre-tax costs and provisions relating to the cyber incident.

New Variant of XLoader macOS Malware Disguised as 'OfficeNote' Productivity App

22 August 2023
A new variant of an Apple macOS malware called XLoader has surfaced in the wild, masquerading its malicious features under the guise of an office productivity app called "OfficeNote." "The new version of XLoader is bundled inside a standard Apple disk image with the name OfficeNote.dmg," SentinelOne security researchers Dinesh Devadoss and Phil Stokes said in a Monday analysis. "The application

Ivanti Warns of Critical Zero-Day Flaw Being Actively Exploited in Sentry Software

22 August 2023
Software services provider Ivanti is warning of a new critical zero-day flaw impacting Ivanti Sentry (formerly MobileIron Sentry) that it said is being actively exploited in the wild, marking an escalation of its security woes. Tracked as CVE-2023-38035 (CVSS score: 9.8), the issue has been described as a case of authentication bypass impacting versions 9.18 and prior due to what it called an

Critical Adobe ColdFusion Flaw Added to CISA's Exploited Vulnerability Catalog

21 August 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw in Adobe ColdFusion to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability, cataloged as CVE-2023-26359 (CVSS score: 9.8), relates to a deserialization flaw present in Adobe ColdFusion 2018 (Update 15 and earlier) and ColdFusion 2021 (

Customer data used for unwanted romantic contact, UK poll shows

21 August 2023
Customer data used for unwanted romantic contact, UK poll shows Almost one in three people aged 18-34 have been messaged by staff after giving personal details to a businessAlmost one in three people aged 18-34 have received unwanted romantic contact after giving their personal information to a business, a UK poll has shown.The Information Commissioner’s Office (ICO) has called for recipients of such texts to come forward to help the regulator gather evidence of the impact of this phenomenon.The ICO has an online form for people who want to report an experience of unwanted contact. Continue reading...

Detecting malware cited as a challenge for organizations

21 August 2023
According to a report, threat actors leverage malware as an initial foothold to infiltrate targeted infrastructures to gain long-term access.

Sneaky Amazon Google Ad Leads to Microsoft Support Scam

21 August 2023
A fake Amazon ad in Google search results is redirecting users to a tech support scam that poses as a Microsoft Defender alert. The tech support scam locks up the browser in full-screen mode.

Researchers Spoof an Apple Device and Trick Users Into Sharing Sensitive Data

21 August 2023
The spoofed Apple device prompts users to connect their Apple ID or share a password with a nearby Apple TV, allowing threat actors to collect data such as phone numbers and Apple ID emails.

Japanese Watchmaker Seiko Breached by BlackCat Ransomware Gang

21 August 2023
Seiko apologized to the potentially impacted customers and business partners and urged them to be vigilant against email or other communication attempts potentially impersonating Seiko.

HiatusRAT Returns after a Hiatus in a Fresh Wave of Attacks

21 August 2023
The HiatusRAT malware group reemerged to target Taiwan-based organizations and a U.S. military procurement system allegedly to snoop on military contracts. The audacity of threat actors is evident in their disregard for previous disclosures and their minimal efforts to change their payload servers. The IOCs from this campaign are available for organizations to proactively take action in thwarting such threats.

Researchers Uncover Real Identity of CypherRAT and CraxsRAT Malware Developer

21 August 2023
The CraxsRAT builder, Cyfirma says, generates highly obfuscated packages, allowing threat actors to customize the contents based on the type of attack they are preparing, including with WebView page injections.

41% of organizations said they can enforce consistent access policies

21 August 2023
According to a recent Strata Identity report, 60% of organizations do not have the resources or time to rewrite old, outdated applications.

Tesla Discloses Data Breach Impacting 75,000 People's Personal Information

21 August 2023
A notification letter sent to impacted people reveals that the data breach is related to a couple of former employees sending confidential information to German media outlet Handelsblatt.

Federally Insured Credit Unions Required to Report Cyber Incidents Within 72 Hours

21 August 2023
The new policy, National Credit Union Administration (NCUA) announced, comes into effect on September 1, and will cover all incidents that impact information systems or the integrity, confidentiality, or availability of data on those systems.