Latest Cybersecurity News and Articles


Kevin Paige named Chief Information Security Officer at Uptycs

07 August 2023
With 30 years of security experience, Uptycs announced the appointment of Kevin Paige as Chief Information Security Officer (CISO) and Vice President of Product Strategy. 

Colorado Department of Higher Education Warns of Massive Data Breach

07 August 2023
The Colorado Department of Higher Education (CDHE) discloses a massive data breach impacting students, past students, and teachers after suffering a ransomware attack in June.

UK Sounds Warning Over Targeted Healthcare Attack

07 August 2023
A targeted cyberattack against Britain's national healthcare system could lead to larger-scale disruption causing the organization several years to recover, the U.K. government warns.

Enhancing Security Operations Using Wazuh: Open Source XDR and SIEM

07 August 2023
In today's interconnected world, evolving security solutions to meet growing demand is more critical than ever. Collaboration across multiple solutions for intelligence gathering and information sharing is indispensable. The idea of multiple-source intelligence gathering stems from the concept that threats are rarely isolated. Hence, their detection and prevention require a comprehensive

Hacktivists Fund Their Operations Using Common Cybercrime Tactics

07 August 2023
KELA notes that although hacktivism appears to be about causing service disruption through DDoS attacks or reputation damage via data leaks, the modus operandi of these threat groups encompasses a broader scope of activities.

New 'Deep Learning Attack' Deciphers Laptop Keystrokes with 95% Accuracy

07 August 2023
A group of academics has devised a "deep learning-based acoustic side-channel attack" that can be used to classify laptop keystrokes that are recorded using a nearby phone with 95% accuracy. "When trained on keystrokes recorded using the video conferencing software Zoom, an accuracy of 93% was achieved, a new best for the medium," researchers Joshua Harrison, Ehsan Toreini, and Maryam Mehrnezhad

New Acoustic Attack Steals Data From Keystrokes With 95% Accuracy

07 August 2023
A team of researchers from British universities has trained a deep learning model that can steal data from keyboard keystrokes recorded using a microphone with an accuracy of 95%.

New SkidMap Redis Malware Variant Targeting Vulnerable Redis Servers

07 August 2023
Vulnerable Redis services have been targeted by a "new, improved, dangerous" variant of a malware called SkidMap that's engineered to target a wide range of Linux distributions. "The malicious nature of this malware is to adapt to the system on which it is executed," Trustwave security researcher Radoslaw Zdonczyk said in an analysis published last week. Some of the Linux distribution SkidMap

Cyberattacks on Governments and Public Services Were Way up This Spring, Research Shows

07 August 2023
Cyberattacks on governments and public entities worldwide surged by 40% from March to May compared to the previous quarter, according to researchers at the cybersecurity firm BlackBerry.

Broad SBOM Adoption Takes Root as Businesses Watch Their Supply Chains

07 August 2023
Three-quarters of enterprises in the U.S. and U.K. have implemented software bills of materials since the Biden administration issued an executive order to bolster cybersecurity in 2021, according to a report Sonatype released Thursday.

Fake VMware vConnector Package on PyPI Targets IT Pros

07 August 2023
A malicious package that mimics the VMware vSphere connector module ‘vConnector’ was uploaded on the Python Package Index (PyPI) under the name ‘VMConnect,’ targeting IT professionals.

Reptile Rootkit: Advanced Linux Malware Targeting South Korean Systems

07 August 2023
"Unlike other rootkit malware that typically only provide concealment capabilities, Reptile goes a step further by offering a reverse shell, allowing threat actors to easily take control of systems," ASEC said in a report published last week.

NYC Couple Pleads Guilty to Money Laundering in $3.6 Billion Bitfinex Hack

07 August 2023
A married couple from New York City has pleaded guilty to money laundering charges in connection with the 2016 hack of cryptocurrency stock exchange Bitfinex, resulting in the theft of about 120,000 bitcoin.

Assess multi-cloud security with the open-source CNAPPgoat project

07 August 2023
Ermetic released CNAPPgoat, an open-source project that allows organizations to test their cloud security skills, processes, tools, and posture in interactive sandbox environments that are easy to deploy and destroy. It is available on GitHub.

Researchers Uncover New High-Severity Vulnerability in PaperCut Software

07 August 2023
Tracked as CVE-2023-39143 (CVSS score: 8.4), the flaw impacts PaperCut NG/MF prior to version 22.1.3. It has been described as a combination of a path traversal and file upload vulnerability.

FBI Alert: Crypto Scammers are Masquerading as NFT Developers

07 August 2023
The U.S. Federal Bureau of Investigation (FBI) is warning about cyber crooks masquerading as legitimate non-fungible token (NFT) developers to steal cryptocurrency and other digital assets from unsuspecting users. In these fraudulent schemes, criminals either obtain direct access to NFT developer social media accounts or create look-alike accounts to promote "exclusive" new NFT releases, often

CISA Cybersecurity Strategic Plan: An Important Step To Secure Critical Infrastructure

05 August 2023
As a founding member of the Network Resilience Coalition, Cisco appreciates CISA’s shared commitment to driving focused attention and investment in efforts to secure and maintain existing critical networked technologies.

Google explains how Android malware slips onto Google Play Store

05 August 2023
To evade detection by Play Store systems, the threat actors responsible for SharkBot have adopted the now common strategy of releasing versions with limited functionality on Google Play, concealing their apps' suspicious nature.

Millions of people's healthcare files accessed by Clop gang

05 August 2023
The new additions to the victims' list bring the headcount to 514 organizations and more than 36 million individuals, according to Emsisoft threat researchers. It may take months if not years for the full impact and costs to become clear.

CISA, Five Eyes cyber advisory lists common vulnerabilities among 2022’s top exploits

05 August 2023
This guidance is the latest released by the Five Eyes organization, which consists of government cybersecurity organizations from the U.S., New Zealand, the U.K., Australia and Canada.