Latest Cybersecurity News and Articles


Over 640 Citrix Servers Backdoored With Web Shells in Ongoing Attacks

03 August 2023
Hundreds of Citrix Netscaler ADC and Gateway servers have already been breached and backdoored in a series of attacks targeting a critical remote code execution (RCE) vulnerability tracked as CVE-2023-3519.

Software Supply Chain Startup Endor Labs Scores Massive $70M Series A Round

03 August 2023
Just ten months after securing an abnormally large seed-stage funding round, software supply chain startup Endor Labs has attracted renewed interest from venture capital investors.

Microsoft Flags Growing Cybersecurity Concerns for Major Sporting Events

03 August 2023
Microsoft is warning of the threat malicious cyber actors pose to stadium operations, warning that the cyber risk surface of live sporting events is "rapidly expanding." "Information on athletic performance, competitive advantage, and personal information is a lucrative target," the company said in a Cyber Signals report shared with The Hacker News. "Sports teams, major league and global

Researchers Discover Bypass for Recently Patched Critical Ivanti EPMM Vulnerability

03 August 2023
Tracked as CVE-2023-35082 (CVSS score: 10.0) and discovered by Rapid7, the issue "allows unauthenticated attackers to access the API in older unsupported versions of MobileIron Core (11.2 and below)."

"Mysterious Team Bangladesh" Targeting India with DDoS Attacks and Data Breaches

03 August 2023
A hacktivist group known as Mysterious Team Bangladesh has been linked to over 750 distributed denial-of-service (DDoS) attacks and 78 website defacements since June 2022. "The group most frequently attacks logistics, government, and financial sector organizations in India and Israel," Singapore-headquartered cybersecurity firm Group-IB said in a report shared with The Hacker News. "The group is

AI-Powered CryptoRom Scam Targets Mobile Users

03 August 2023
CryptoRom, a notorious scam that combines fake cryptocurrency trading and romance scams, has taken a new twist by utilizing generative artificial intelligence (AI) chat tools to lure and interact with victims.

Russia-Linked Cybercriminals Target UK School for Children With Learning Difficulties

03 August 2023
The LockBit ransomware group, potentially the world’s most prolific cybercrime organization, is attempting to extort a school for children with special educational needs.

New Variants of NodeStealer Found Infecting Facebook Business Accounts

03 August 2023
Unit 42 researchers discovered a previously unreported phishing campaign targeting Facebook business accounts. The campaign distributed new variants of NodeStealer malware that could fully take over these accounts, steal cryptocurrency, and download further payloads. This type of attack can cause both financial and reputational damage to individuals and organizations.

Microsoft Exposes Russian Hackers' Sneaky Phishing Tactics via Microsoft Teams Chats

03 August 2023
Microsoft on Wednesday disclosed that it identified a set of highly targeted social engineering attacks mounted by a Russian nation-state threat actor using credential theft phishing lures sent as Microsoft Teams chats. The tech giant attributed the attacks to a group it tracks as Midnight Blizzard (previously Nobelium). It's also called APT29, BlueBravo, Cozy Bear, Iron Hemlock, and The Dukes.

Researchers Discover Bypass for Recently Patched Critical Ivanti EPMM Vulnerability

03 August 2023
Cybersecurity researchers have discovered a bypass for a recently fixed actively exploited vulnerability in some versions of Ivanti Endpoint Manager Mobile (EPMM), prompting Ivanti to urge users to update to the latest version of the software. Tracked as CVE-2023-35082 (CVSS score: 10.0) and discovered by Rapid7, the issue "allows unauthenticated attackers to access the API in older unsupported

NCSC and allies reveal most common cyber vulnerabilities exploited in 2022

02 August 2023
New advisory highlights how threat actors exploited a larger number of older software vulnerabilities rather than more recently disclosed flaws last year.

Cyberattack response times are accelerating

02 August 2023
According to a recent Immersive Labs report, organizations saw an accelerated cyberattack response time, from 29 days to 19 days from 2021 to 2022.

Cyber attack response times are accelerating

02 August 2023
According to a recent Immersive Labs report, organizations saw an accelerated cyberattack response time, from 29 days to 19 days from 2021 to 2022.

Researchers Uncover AWS SSM Agent Misuse as a Covert Remote Access Trojan

02 August 2023
Cybersecurity researchers have discovered a new post-exploitation technique in Amazon Web Services (AWS) that allows the AWS Systems Manager Agent (SSM Agent) to be run as a remote access trojan on Windows and Linux environments.

OT/IoT Malware Surges Tenfold in First Half of the Year

02 August 2023
Malware-related cyber-threats in operational technology (OT) and Internet of Things (IoT) environments jumped tenfold year-on-year in the first six months of 2023, according to Nozomi Networks.

Millions Stolen From Crypto Platforms Through Exploited ‘Vyper’ Vulnerability

02 August 2023
Millions of dollars worth of cryptocurrency were stolen from several platforms over the weekend after hackers exploited a vulnerability in a programming language used widely in the cryptocurrency world.

The Gap in Users’ Identity Security Knowledge Gives Cybercriminals an Opening

02 August 2023
With exponential growth in the number of human and machine actors on the network and more sophisticated technology in more places, identity in this new era is rapidly becoming a super-human problem, according to RSA.

Nile, Which Offers Enterprise Networks as a Service, Raises $175M

02 August 2023
Nile, a networking-as-a-service (NaaS) provider founded by former Cisco executive Pankaj Patel, has raised $175 million in a Series C funding round. The funding will be used for go-to-market growth and expanding the company's workforce.

Business email compromise attacks outpace malware

02 August 2023
A recent Abnormal report analyzed the increase in third-party application usage and increase in email attacks in the first half of 2023.

Firefox Fixes a Flurry of Flaws in the First of Two Releases This Month

02 August 2023
Mozilla has released a new version of Firefox, marking the first of two upgrades for the month. The patched flaws are tracked as CVE-2023-4045, CVE-2023-4047, CVE-2023-4048, CVE-2023-4050, CVE-2023-4051, CVE-2023-4057, and CVE-2023-4058.