Latest Cybersecurity News and Articles


Cyberinsurance Firm Resilience Raises $100 Million to Expand Its Cyber Risk Platform

08 August 2023
The Series D round was led by Intact Ventures, an affiliate of Resilience’s primary capacity provider, Intact Insurance’s underwriting companies, with participation by Lightspeed Venture Partners, as well as General Catalyst and Founders Fund.

Latest Batloader Campaigns Use Pyarmor Pro for Evasion

08 August 2023
The Batloader initial access malware, used by the group Water Minyades, has upgraded its evasion techniques by utilizing Pyarmor Pro to obfuscate its malicious Python scripts.

LOLBAS in the Wild: 11 Living-Off-The-Land Binaries Used for Malicious Purposes

08 August 2023
Cybersecurity researchers have discovered a set of 11 living-off-the-land binaries-and-scripts (LOLBAS) that could be maliciously abused by threat actors to conduct post-exploitation activities.  "LOLBAS is an attack method that uses binaries and scripts that are already part of the system for malicious purposes," Pentera security researcher Nir Chako said. "This makes it hard for security teams

Extended warranty robocallers fined $300 million after 5 billion scam calls

08 August 2023
The Federal Communications Commission (FCC) has announced a record-breaking $299,997,000 fine imposed on an international network of companies for placing five billion robocalls to more than 500 million phone numbers over three months in 2021.

New Microsoft Azure AD CTS Feature can be Abused for Lateral Movement

08 August 2023
Microsoft's new Azure Active Directory Cross-Tenant Synchronization (CTS) feature, introduced in June 2023, has created a new potential attack surface that might allow threat actors to more easily spread laterally to other Azure tenants.

Rise of AI leads to free training sources

07 August 2023
The rise of technology such as artificial intelligence (AI) has led to security leaders looking for ways to educate themselves on its uses and risks. 

Cl0p Ransomware Gang Revises its Extortion Strategy

07 August 2023
MOVEit-hijacker Cl0p ransomware gang has changed its extortion tactics and is now using torrents to distribute data stolen in the MOVEit Transfer breaches. Previously, the group utilized Tor data leak sites, but this method was slow and easier to shut down. Through torrents, criminals are expecting faster transfer speeds making the leak more impactful. As torrents are decentralized, it becomes challenging for law enforcement to shut them down.

New Malware Campaign Targets Inexperienced Cyber Criminals with OpenBullet Configs

07 August 2023
A new malware campaign has been observed making use of malicious OpenBullet configuration files to target inexperienced cyber criminals with the goal of delivering a remote access trojan (RAT) capable of stealing sensitive information. Bot mitigation company Kasada said the activity is designed to "exploit trusted criminal networks," describing it as an instance of advanced threat actors "

White House announces K-12 cybersecurity plans

07 August 2023
 The White House has announced steps for providing various resources for K-12 schools to update their cybersecurity practices and report incidents.

Spyware Maker Letmespy Shuts Down After Hacker Deletes Server Data

07 August 2023
In a notice on its website in both English and Polish, LetMeSpy confirmed the “permanent shutdown” of the spyware service and that it would cease operations by the end of August.

C-Suite, Rank-And-File at Odds Over Security’s Role

07 August 2023
A disconnect is brewing between how C-suite executives and cybersecurity workers perceive security’s role, according to a Cloud Security Alliance report released last week. The study by Expel surveyed 1,000 IT and security professionals in May.

North Korean Hackers Targets Russian Missile Engineering Firm

07 August 2023
Two different North Korean nation-state actors have been linked to a cyber intrusion against the major Russian missile engineering company NPO Mashinostroyeniya. Cybersecurity firm SentinelOne said it identified "two instances of North Korea related compromise of sensitive internal IT infrastructure," including a case of an email server compromise and the deployment of a Windows backdoor dubbed

Clop Ransomware Now Uses Torrents to Leak Data and Evade Takedowns

07 August 2023
According to security researcher Dominic Alvieri, who first spotted this new tactic, torrents have been created for twenty victims, including Aon, K & L Gates, Putnam, Delaware Life, Zurich Brazil, and Heidelberg.

US ‘Lagging Behind’ on Border Gateway Protocol Security Practices, CISA and FCC Chiefs Say

07 August 2023
The U.S. government is lagging behind other countries in instituting more stringent cybersecurity measures governing the Border Gateway Protocol (BGP) – a set of technical rules responsible for routing data efficiently.

New SkidMap Redis Malware Variant Targets Vulnerable Redis Servers

07 August 2023
Vulnerable Redis services have been targeted by a "new, improved, dangerous" variant of a malware called SkidMap that's engineered to target a wide range of Linux distributions.

VPNs remain a risky gamble for remote access

07 August 2023
A new Zscaler report stresses the need for organizations to reevaluate their security posture and migrate to a zero-trust architecture due to the increasing threat of cybercriminals exploiting VPN vulnerabilities.

Reptile Rootkit Targets Linux Systems in South Korea

07 August 2023
Reptile, an open-source kernel module rootkit, designed to target Linux systems was found on GitHub. Unlike typical rootkit malware, Reptile not only conceals its presence but also offers a reverse shell, granting threat actors control over compromised systems. It is crucial to regularly inspect systems for vulnerable configurations and ensure all relevant software is up to date.

Russian Hackers Overwhelm Spanish Sites With DDoS Attacks

07 August 2023
Banks, telecoms providers, media, and tourism companies are thought to have been affected by the attacks, which followed a trip by Prime Minister Pedro Sanchez to Kyiv in which he expressed his government’s support for Ukraine.

Multi-Modal Data Protection With AI’s Help

07 August 2023
Multi-modal monitoring through AI enables the identification of both data and conversation types, enhancing the ability to detect and prevent data leakage or any unauthorized activities.

Report: US suffers 49.8M leaked accounts in Q2

07 August 2023
A recent report shows the United States was the most breached country in Q2 of this yea