Latest Cybersecurity News and Articles


Security leaders chime in on new SEC disclosure rules

10 August 2023
Security leaders discuss the recent vote by Securities and Exchange Commission (SEC) to adopt final rules on cybersecurity disclosure.

White House Launches AI Cyber Challenge to Make Software More Secure

10 August 2023
The Biden-Harris Administration has launched a major two-year competition using AI to protect the United States’ most important software, such as code that helps run the internet and critical infrastructure.

Breach Connected to MOVEit Flaw Affects Missouri Medicaid Recipients

10 August 2023
The Missouri Department of Social Services (DSS) has issued an alert urging residents to safeguard their personal information following a cyberattack originating from a data security breach at IBM Consulting in May 2023.

Encryption Flaws in Popular Chinese Language App Put Users' Typed Data at Risk

10 August 2023
A widely used Chinese language input app for Windows and Android has been found vulnerable to serious security flaws that could allow a malicious interloper to decipher the text typed by users. The findings from the University of Toronto's Citizen Lab, which carried out an analysis of the encryption mechanism used in Tencent's Sogou Input Method, an app that has over 455 million monthly active

Emerging Attacker Exploit: Microsoft Cross-Tenant Synchronization

10 August 2023
Attackers continue to target Microsoft identities to gain access to connected Microsoft applications and federated SaaS applications. Additionally, attackers continue to progress their attacks in these environments, not by exploiting vulnerabilities, but by abusing native Microsoft functionality to achieve their objective. The attacker group Nobelium, linked with the SolarWinds attacks, has been

Data of All Serving Police Officers Police Service of Northern Ireland Mistakenly Published Online

10 August 2023
The Police Service of Northern Ireland (PSNI) has mistakenly shared sensitive data of all 10,000 serving police officers in response to a Freedom of Information (FOI) request. The request aimed at determining the number of PSNI officers.

Ukraine Says It Thwarted Attempt to Breach Military Tablets

10 August 2023
Ukraine’s security service, the SBU, attributed the attack to the infamous hacking group known as Sandworm, working on behalf of GRU, the Russian military intelligence agency. The SBU said it was able to stop the operation during the planning phase.

New Zero-Day Vulnerabilities Could Instantly Drain Crypto Wallets

10 August 2023
Multiple zero-day vulnerabilities have been discovered in some of the most used cryptographic multi-party computation (MPC) protocols, putting consumers’ cryptocurrency funds at risk of theft.

Google to fight hackers with weekly Chrome security updates

10 August 2023
Google has changed the Google Chrome security updates schedule from bi-weekly to weekly to address the growing patch gap problem that allows threat actors extra time to exploit published n-day and zero-day flaws.

Newly Discovered Inception Attack Exposes Data from AMD Zen CPUs

10 August 2023
A recent disclosure highlights a fresh wave of vulnerabilities, with a major focus on AMD's 'Inception.' This vulnerability enables data leakage through a novel attack approach. Any system with an affected CPU can potentially be the target of the attack. AMD has released microcode in “Zen 3” and “Zen 4” CPU architectures to fully mitigate the attack.

Balada Injector Still at Large – New Domains Discovered

10 August 2023
The Balada Injector malware continues to evade security software by using new domain names and obfuscation techniques, posing a persistent threat to vulnerable WordPress websites.

Cybercriminals Increasingly Using EvilProxy Phishing Kit to Target Executives

10 August 2023
Threat actors are increasingly using a phishing-as-a-service (PhaaS) toolkit dubbed EvilProxy to pull off account takeover attacks aimed at high-ranking executives at prominent companies. According to Proofpoint, an ongoing hybrid campaign has leveraged the service to target thousands of Microsoft 365 user accounts, sending approximately 120,000 phishing emails to hundreds of organizations

Report: Threat Actors Abuse Valid Accounts Using Manual Tactics

10 August 2023
Threat actors are spurning the rise of automation and using manual tactics to intrude organizations’ networks and rapidly access sensitive data, according to CrowdStrike’s 2023 Threat Hunting Report released Tuesday.

Open Source Tool Used to Target Ukrainian Government Agencies

10 August 2023
Ukrainian government agencies were targeted by hackers in a phishing campaign that utilized the open-source program MerlinAgent. The campaign was conducted by UAC-0154 and involved sending malicious emails to the targets. As attackers adapt their techniques, vigilance becomes paramount.

Israeli Hospital Redirects New Patients Following Ransomware Attack

10 August 2023
An Israeli hospital near the city of Tel Aviv was hacked on Tuesday by a group of unknown cybercriminals, prompting it to stop admitting new patients and redirecting people to nearby hospitals.

Northern Ireland police chief urged to consider position over data breach

10 August 2023
Northern Ireland police chief urged to consider position over data breach DUP MP Sammy Wilson says serious questions must be asked at highest level of PSNI amid fears over safety of officersThe head of policing in Northern Ireland has been urged to consider his position over the mass breach of officers’ data amid warnings that terrorists could use the information to carry out attacks.Sammy Wilson, a Democratic Unionist party MP, suggested Simon Byrne’s future as chief constable might not be sustainable. Continue reading...

High-Severity Access Control Vulnerability Found in Spring WebFlux

10 August 2023
An advisory on the vulnerability published by JFrog shed light on the exact nature of the flaw, its potential victims, and a proof-of-concept (POC) illustrating the scenarios in which this flaw could be triggered for unauthorized access.

AWS Pledges $20M to K-12 Cyber Training, Incident Response

10 August 2023
The company is participating in a larger collaboration between government agencies and private sector partners to help target rich, resource-poor organizations like local schools combat malicious attacks.

Malicious Campaigns Exploit Weak Kubernetes Clusters for Crypto Mining

10 August 2023
In total, Kubernetes clusters belonging to more than 350 organizations, open-source projects, and individuals were discovered, 60% of which were the target of an active crypto-mining campaign.

New Report Exposes Vice Society's Collaboration with Rhysida Ransomware

10 August 2023
Tactical similarities have been unearthed between the double extortion ransomware group known as Rhysida and Vice Society, including in their targeting of education and healthcare sectors.