Latest Cybersecurity News and Articles


Interpol Busts Phishing-as-a-Service Platform '16Shop,' Leading to 3 Arrests

10 August 2023
Interpol has announced the takedown of a phishing-as-a-service (PhaaS) platform called 16Shop, in addition to the arrests of three individuals in Indonesia and Japan. 16Shop specialized in the sales of phishing kits that other cybercriminals can purchase to mount phishing attacks on a large scale, ultimately facilitating the theft of credentials and payment details from users of popular services

OpenBullet Campaign: Cybercriminals Target Script Kiddies

10 August 2023
Experienced cybercriminals are taking on script kiddies in a new malware campaign through malicious OpenBullet configuration files. Malicious configurations are shared on platforms like Telegram to deliver a Rust-based dropper and a Python-based RAT named Patent. Adversaries have made a profit in crypto worth $1,703.15 over the past two months.

Building digital trust in an organization

10 August 2023
The importance of digital trust.

Horizon3 AI Raises $40 Million to Expand Automated Pentesting Platform

09 August 2023
The additional funding will help the San Francisco-based company integrate pentesting, SOAR, and detection engineering into its platform and expand its channel and partner presence to fuel global growth.

PSNI apologies to police officers after unprecedented data breach – video

09 August 2023
PSNI apologies to police officers after unprecedented data breach – video The UK Information Commissioner’s Office has launched an investigation into an unprecedented data breach that disclosed details of more than 10,000 police officers and staff in Northern Ireland. The agency, which regulates data privacy laws, is working with the Police Service of Northern Ireland to establish the level of risk amid warnings that the leak may compel officers to leave the force or move their home address. The PSNI blamed human error for releasing an Excel spreadsheet that was published on an FoI website and removed two hours later once police discovered the mistake. Chris Todd, a PSNI assistant chief constable, apologised and said the error was unacceptableICO to investigate risk to police officers after Northern Ireland data breach Continue reading...

Hacked UK voter data could be used to target disinformation, warn experts

09 August 2023
Hacked UK voter data could be used to target disinformation, warn experts Data from Electoral Commission breach could allow rogue actors to create AI-generated messages in effort to manipulate electionsData accessed in the Electoral Commission hack could help state-backed actors target voters with AI-generated disinformation, experts have warned.The UK elections watchdog revealed on Tuesday that a hostile cyber-attack had been able to access the names and addresses of all voters registered between 2014 and 2022. Continue reading...

Data Exfiltration is Now the Go-to Cyber Extortion Strategy

09 August 2023
The abuse of zero-day and one-day vulnerabilities in the past six months led to a 143% increase in victims when comparing Q1 2022 with Q1 2023, according to a report by Akamai.

Large-user applications vulnerable to dependency confusion attacks

09 August 2023
A OX Security report found applications with more than 1 billion users are using dependencies which are vulnerable to dependency confusion attacks.

Hackers Prepare to Take on a Satellite at DEF CON

09 August 2023
The annual Hack-A-Sat CTF competition held at Aerospace Village at the DEF CON in Las Vegas is the first time an on-orbit satellite will test contestants' mettle while bringing together hackers who don’t typically work on space systems.

Social media for research and threat intelligence

09 August 2023
Learn about threat intelligence on this episode of The Security Podcasts with Igal Lytzki, Incident Response team leader at Perception Point.

The Ransomware Rollercoaster Continues as Criminals Advance Their Business Models

09 August 2023
Ransomware shows no signs of slowing, with ransomware activity ending 13 times higher than at the start of 2023 as a proportion of all malware detections, according to Fortinet.

Collide+Power, Downfall, and Inception: New Side-Channel Attacks Affecting Modern CPUs

09 August 2023
Cybersecurity researchers have disclosed details of a trio of side-channel attacks that could be exploited to leak sensitive data from modern CPUs. Called Collide+Power (CVE-2023-20583), Downfall (CVE-2022-40982), and Inception (CVE-2023-20569), the novel methods follow the disclosure of another newly discovered security vulnerability affecting AMD's Zen 2 architecture-based processors known as 

Microsoft Office Update Breaks Actively Exploited RCE Attack Chain

09 August 2023
Microsoft today released a defense-in-depth update for Microsoft Office that prevents exploitation of a remote code execution (RCE) vulnerability tracked as CVE-2023-36884 that threat actors have already leveraged in attacks.

Rubrik Buys Startup Laminar to Unify Cyber Posture, Recovery

09 August 2023
Rubrik purchased a data security posture management startup backed by Salesforce and SentinelOne to provide visibility into where a company's data lives and who has access.

Big Cyberespionage Attack Against Japan Attributed to China

09 August 2023
Classified military networks run by Japan reportedly suffered a massive breach in 2020 at the hands of a Chinese cyberespionage group that proved tough to eject even after being discovered.

Android 14 Introduces First-Of-Its-Kind Cellular Connectivity Security Features

09 August 2023
Android 14 introduces new security measures to mitigate the risks associated with 2G networks, allowing users and enterprises to disable 2G connectivity and protect against potential attacks.

Lockbit Threatens to Leak Medical Data of Cancer Patients Stolen From Varian Medical Systems

09 August 2023
Lockbit has fixed the deadline for the ransom payment on August 17, 2023. If confirmed the incident could have a dramatic impact on the privacy of cancer patients. The company has yet to disclose the security incident.

China-Linked Hackers Strike Worldwide: 17 Nations Hit in 3-Year Cyber Campaign

09 August 2023
Hackers associated with China's Ministry of State Security (MSS) have been linked to attacks in 17 different countries in Asia, Europe, and North America from 2021 to 2023. Cybersecurity firm Recorded Future attributed the intrusion set to a nation-state group it tracks under the name RedHotel (previously Threat Activity Group-22 or TAG-222), which overlaps with a cluster of activity broadly

For TSA’s Updated Pipeline Security Directive, Consistency and Collaboration are Key

09 August 2023
This most recent update does not vacate previously established requirements in the simple pursuit of change. Instead, the new directive pursues incremental change that builds on but does not abandon previous requirements.

SESARAM Confirms Cyberattack and Suspends Non-Urgent Activity

09 August 2023
SESARAM issued a statement confirming the occurrence of a “deliberate and malicious cyberattack with the sole objective of causing damage and disrupting the normal functioning of the Regional Health Service of the Autonomous Region of Madeira”.