Latest Cybersecurity News and Articles


Multiple Flaws Found in the Avada WordPress Theme and Plugin

12 August 2023
These security flaws in the widely used Avada theme and the Avada Builder plugin, uncovered by Patchstack’s security researcher Rafie Muhammad, expose a significant number of WordPress websites to potential breaches.

MacOS Systems Turned Into Proxy Exit Nodes by Adload

12 August 2023
AdLoad malware is still infecting Mac systems and has been observed turning infected systems into a giant proxy botnet. AT&T Alien Labs has identified over 10,000 IPs behaving as proxy exit nodes, indicating a potentially widespread infection.

Honor Among Cybercriminals? Why a Canadian Firm Paid Ransom

12 August 2023
A nonprofit firm that administers government dental programs in Canada is notifying nearly 1.5 million individuals that their data, including banking information for some, was compromised in a ransomware incident last month.

Lolek Bulletproof Hosting Servers Seized, 5 Key Operators Arrested

12 August 2023
European and U.S. law enforcement agencies have announced the dismantling of a bulletproof hosting service provider called Lolek Hosted, which cybercriminals have used to launch cyber-attacks across the globe. "Five of its administrators were arrested, and all of its servers seized, rendering LolekHosted.net no longer available," Europol said in a statement. "The service facilitated the

JanelaRAT: Repurposed BX Rat Variant Targeting LATAM FinTech

12 August 2023
Zscaler ThreatLabz has discovered a threat actor targeting FinTech users in the LATAM region with a malware called JanelaRAT. This malware uses tactics such as DLL side-loading and dynamic C2 infrastructure.

New SystemBC Malware Variant Targets Southern African Power Company

12 August 2023
An unknown threat actor has been linked to a cyber attack on a power generation company in South Africa with a new variant of the SystemBC malware called DroxiDat as a precursor to a suspected ransomware attack.

New Python URL Parsing Flaw Enables Command Injection Attacks

12 August 2023
A high-severity security flaw has been disclosed in the Python URL parsing function that could be exploited to bypass domain or protocol filtering methods implemented with a blocklist, ultimately resulting in arbitrary file reads and command execution. "urlparse has a parsing problem when the entire URL starts with blank characters," the CERT Coordination Center (CERT/CC) said in a Friday

UK: Cumbria Police Admit Huge Breach of Data of Officers and Staff

12 August 2023
Cumbria police have admitted accidentally publishing the names and salaries of every one of its more than 2,000 employees and have apologized. The data breach happened in March and has not previously been publicized.

Magento Shopping Cart Attack Targets Critical Vulnerability

11 August 2023
Security researchers at Akamai say they have identified a server-side template injection campaign aimed at Magneto 2 shops that have yet to address CVE-2022-24086, an input validation flaw with a CVSS score of 9.8.

Data leaks have given Irish republican groups ‘upper hand’ against police, analysts warn

11 August 2023
Data leaks have given Irish republican groups ‘upper hand’ against police, analysts warn Breaches hurt police morale and may help republican paramilitaries intimidate officers and their familiesPolice data breaches in Northern Ireland have given republican paramilitaries a powerful tool to intimidate, demoralise and target officers and their families for years to come, according to security experts.The New IRA and other groups have gained the “upper hand” and will be able to use the unprecedented leaks of officers’ personal information to carry out psychological and possibly physical attacks, the analysts warned. Continue reading...

16 New CODESYS SDK Flaws Expose OT Environments to Remote Attacks

11 August 2023
The remote code execution bugs, in particular, could be abused to backdoor OT devices and interfere with the functioning of programmable logic controllers (PLCs) in a manner that could pave the way for information theft.

Gafgyt Malware Exploits Five-Years-Old Flaw in EoL Zyxel Router

11 August 2023
Fortinet has issued an alert warning that the Gafgyt botnet malware is actively trying to exploit a vulnerability in the end-of-life Zyxel P660HN-T1A router in thousands of daily attacks.

Charming Kitten Hackers Target Iranian Dissidents in Germany

11 August 2023
The Federal Office for the Protection of the Constitution (BfV) reported it had found concrete attempts by the group known as Charming Kitten to target the Iranian opposition and exiles based in Germany.

Ukrainian Official Touts Country’s Wartime Cyber Intelligence Efforts

11 August 2023
Intelligence gathered in cyberspace is helping Ukraine understand Russia's plans and stop the enemy from carrying them out, according to the country’s top cyber and information security official.

Researchers Uncover Decade-Long Cyber Espionage on Foreign Embassies in Belarus

11 August 2023
A hitherto undocumented threat actor operating for nearly a decade and codenamed MoustachedBouncer has been attributed to cyber espionage attacks aimed at foreign embassies in Belarus. "Since 2020, MoustachedBouncer has most likely been able to perform adversary-in-the-middle (AitM) attacks at the ISP level, within Belarus, in order to compromise its targets," ESET security researcher Matthieu

Dell Compellent Hardcoded Key Exposes Vmware vCenter Admin Credentials

11 August 2023
The flaw, tracked as CVE-2023-39250, is caused by a static AES encryption key, shared across all installs, that is used to encrypt the vCenter credentials stored in the program's configuration file.

US National Security Agency Announces Codebreaker Challenge Theme

11 August 2023
The NSA Codebreaker Challenge is a competition for high school and university students across the US that started in 2013 to explain what the missions of NSA agents are using fictitious scenarios.

New Whirlpool Backdoor Used in Barracuda ESG Campaign

11 August 2023
The US Cybersecurity and Infrastructure Security Agency (CISA) has released a new advisory detailing the malware, dubbed “Whirlpool.” It claimed the backdoor established a TLS reverse shell to a command-and-control (C2) server.

Cumbria police admits huge breach of data of officers and staff

11 August 2023
Cumbria police admits huge breach of data of officers and staff Exclusive: Accidental publishing of names and salaries happened in March and follows scandal over PSNI leakAnother British police force has experienced a huge breach of the data of all its officers and staff, the Guardian has learned.Cumbria police has admitted accidentally publishing the names and salaries of every one of its more than 2,000 employees and has apologised. Continue reading...

India Passes Data Protection Legislation in Parliament. Critics Fear Privacy Violation

11 August 2023
Indian lawmakers Wednesday approved a data protection legislation that “seeks to better regulate big tech firms and penalize companies for data breaches” as several groups expressed concern over citizens’ privacy rights.