Latest Cybersecurity News and Articles


Ransomware Attack on Rapattoni Disrupts US Real Estate Property Listings

16 August 2023
Real estate agents' ability to list or update property information has been compromised by an attack on California-based data services company Rapattoni, which hosts multiple listing services.

What's the State of Credential theft in 2023?

16 August 2023
At a little overt halfway through 2023, credential theft is still a major thorn in the side of IT teams. The heart of the problem is the value of data to cybercriminals and the evolution of the techniques they use to get hold of it. The 2023 Verizon Data Breach Investigations Report (DBIR) revealed that 83% of breaches involved external actors, with almost all attacks being financially motivated

Experts Uncover Weaknesses in PowerShell Gallery Enabling Supply Chain Attacks

16 August 2023
Active flaws in the PowerShell Gallery could be weaponized by threat actors to pull off supply chain attacks against the registry's users. "These flaws make typosquatting attacks inevitable in this registry, while also making it extremely difficult for users to identify the true owner of a package," Aqua security researchers Mor Weinberger, Yakir Kadkoda, and Ilay Goldman said in a report shared

Clorox Cleans up Security Breach That Disrupted Operations

16 August 2023
The intrusion continues to disrupt "parts of the company's business operations," and it is "working diligently to respond to and address this issue, and is also coordinating with law enforcement," according to the Form 8-K submission.

Guide: How Google Workspace-based Organizations can leverage Chrome to improve Security

16 August 2023
More and more organizations are choosing Google Workspace as their default employee toolset of choice. But despite the productivity advantages, this organizational action also incurs a new security debt. Security teams now have to find a way to adjust their security architecture to this new cloud workload. Some teams may rely on their existing network security solutions. According to a new guide

Prince George's County Public Schools Responds Suffers Network Outage Owing to Cyberattack

16 August 2023
District leaders initially said they were working to address a “broad network outage” that knocked out email and other services. On Monday night, the district released a statement saying 4,500 of the system’s 180,000 accounts were “impacted.”

Google Introduces First Quantum Resilient FIDO2 Security Key

16 August 2023
Google on Tuesday announced the first quantum resilient FIDO2 security key implementation as part of its OpenSK security keys initiative. "This open-source hardware optimized implementation uses a novel ECC/Dilithium hybrid signature schema that benefits from the security of ECC against standard attacks and Dilithium's resilience against quantum attacks," Elie Bursztein and Fabian Kaczmarczyck 

Critical Security Flaws Affect Ivanti Avalanche, Threatening 30,000 Organizations

16 August 2023
Multiple critical security flaws have been reported in Ivanti Avalanche, an enterprise mobile device management solution that’s used by 30,000 organizations. The vulnerabilities, collectively tracked as CVE-2023-32560 (CVSS score: 9.8), are stack-based buffer overflows in Ivanti Avalanche WLAvanacheServer.exe v6.4.0.0. Cybersecurity company Tenable said the shortcomings are the result of buffer

Ivanti Avalanche Impacted by Critical Pre-Auth Stack Buffer Overflows

16 August 2023
Two stack-based buffer overflows collectively tracked as CVE-2023-32560 impact Ivanti Avalanche, an enterprise mobility management (EMM) solution designed to manage, monitor, and secure a wide range of mobile devices.

LinkedIn Accounts Hacked in Widespread Hijacking Campaign

16 August 2023
As reported today by Cyberint, many LinkedIn users have been complaining about account takeovers or lockouts and an inability to resolve the problems through LinkedIn support.

Knight Ransomware Used in a Spam Campaign Impersonating TripAdvisor

16 August 2023
Knight ransomware, a recycled version of Cyclops ransomware, is being used in an ongoing spam campaign impersonating TripAdvisor.

TIAA Hit With Class-Action Lawsuit Over MOVEit Data Breach

16 August 2023
The breach affected some 2.3 million TIAA clients, according to a lawsuit filed last week in U.S. District Court in New York. The suit alleges TIAA did not use “reasonable security procedures and practices” to protect clients’ sensitive information.

Cybercriminals Abusing Cloudflare R2 for Hosting Phishing Pages, Experts Warn

16 August 2023
The phishing campaigns identified by Netskope not only abuse Cloudflare R2 to distribute static phishing pages, but also leverage its Turnstile offering, a CAPTCHA replacement, to place such pages behind anti-bot barriers to evade detection.

Law Firm Facing Lawsuit in Aftermath of Its Own Big Breach

16 August 2023
The lawsuit complaint stems from a March hacking incident at San Francisco-based Orrick, Herrington & Sutcliffe that compromised the information of nearly 153,000 individuals, including victims of a client's data breach three years ago.

2,000 Citrix NetScaler Instances Backdoored via Recent Vulnerability

16 August 2023
Tracked as CVE-2023-3519, the critical vulnerability was disclosed last month as a zero-day, being exploited since June 2023, including in attacks against critical infrastructure organizations.

Nearly 2,000 Citrix NetScaler Instances Hacked via Critical Vulnerability

16 August 2023
Nearly 2,000 Citrix NetScaler instances have been compromised with a backdoor by weaponizing a recently disclosed critical security vulnerability as part of a large-scale attack. "An adversary appears to have exploited CVE-2023-3519 in an automated fashion, placing web shells on vulnerable NetScalers to gain persistent access," NCC Group said in an advisory released Tuesday. "The adversary can

22% of BlackHat USA attendants believe AI takeover is already here

15 August 2023
BlackHat USA attendants were surveyed by Delinea, finding that of 100 attendees polled, 54% said that "passwordless" is a viable concept.

Cybercriminals Abusing Cloudflare R2 for Hosting Phishing Pages, Experts Warn

15 August 2023
Threat actors' use of Cloudflare R2 to host phishing pages has witnessed a 61-fold increase over the past six months. "The majority of the phishing campaigns target Microsoft login credentials, although there are some pages targeting Adobe, Dropbox, and other cloud apps," Netskope security researcher Jan Michael said. Cloudflare R2, analogous to Amazon Web Service S3, Google Cloud Storage, and

Multiple Flaws Found in ScrutisWeb Software Exposes ATMs to Remote Hacking

15 August 2023
Four security vulnerabilities in the ScrutisWeb ATM fleet monitoring software made by Iagona could be exploited to remotely break into ATMs, upload arbitrary files, and even reboot the terminals. The shortcomings were discovered by the Synack Red Team (SRT) following a client engagement. The issues have been addressed in ScrutisWeb version 2.1.38. "Successful exploitation of these

Georgia Healthcare System Notifies 180,000 People of Breach After Suffering Ransomware Attack

15 August 2023
The apparent Hive ransomware attack on the Tift Regional Health System involved hackers accessing and copying files containing patient information, including medical and banking account information.