Latest Cybersecurity News and Articles


Lawsuit Alleges Bytedance’s Capcut App Secretly Reaps Massive Amounts of User Data

02 August 2023
CapCut and sister company TikTok are owned by the Chinese company ByteDance Ltd., which has long been under scrutiny by American officials concerned with how it collects and leverages American users’ personal data, allegedly including biometric data.

Russian Cyber Adversary BlueCharlie Alters Infrastructure in Response to Disclosures

02 August 2023
A Russa-nexus adversary has been linked to 94 new domains, suggesting that the group is actively modifying its infrastructure in response to public disclosures about its activities. Cybersecurity firm Recorded Future linked the new infrastructure to a threat actor it tracks under the name BlueCharlie, a hacking crew that's broadly known by the names Blue Callisto, Callisto (or Calisto),

Report finds governments, public services facing 40% more cyberattacks

02 August 2023
A new report highlights a 40% increase in cyberattacks targeting government agencies and the public services sector.

Cyberattack on Montclair Township Led to $450K Settlement

02 August 2023
The Garden State Joint Insurance Fund made the deal as law enforcement began investigations into possible criminal charges, Joseph Hartnett, interim township manager, said Thursday.

Possible Chinese Malware in US Systems a ‘Ticking Time Bomb’: Report

02 August 2023
The Biden administration believes China has implanted malware in key US power and communications networks in a “ticking time bomb” that could disrupt the military in event of a conflict, The New York Times reported Saturday.

Cloudzy With a Chance of Global Cybercrime

02 August 2023
Halcyon Research uncovers C2P entities enabling ransomware attacks, identifies new affiliates, and links them to the ISP Cloudzy, facilitating anonymous RDP VPS services with cryptocurrencies. Experts confidently concluded that Cloudzy is highly likely to be a front for abrNOC, the actual hosting company operating from Iran.

Retail Chain Hot Topic Discloses Wave of Credential-Stuffing Attacks

02 August 2023
In a data breach notification today, the company explained that hackers used stolen account credentials and accessed the Rewards platform multiple times, potentially stealing customer data, too.

Phishers Exploit Salesforce's Email Services Zero-Day in Targeted Facebook Campaign

02 August 2023
A sophisticated Facebook phishing campaign has been observed exploiting a zero-day flaw in Salesforce's email services, allowing threat actors to craft targeted phishing messages using the company's domain and infrastructure. "Those phishing campaigns cleverly evade conventional detection methods by chaining the Salesforce vulnerability and legacy quirks in Facebook's Web Games platform,"

Industrial Control Systems Vulnerabilities Soar: Over One-Third Unpatched in 2023

02 August 2023
About 34% of security vulnerabilities impacting industrial control systems (ICSs) that were reported in the first half of 2023 have no patch or remediation, registering a significant increase from 13% the previous year. According to data compiled by SynSaber, a total of 670 ICS product flaws were reported via the U.S. Cybersecurity and Infrastructure Security Agency (CISA) in the first half of

Kazakhstan Refuses to Extradite Detained Russian Cyber Expert to Us

02 August 2023
At the same time, a Moscow court also issued an arrest warrant for Kislitsin, charging him with unauthorized access to protected computer information. Russia said it will also seek his extradition from Kazakhstan.

Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack

02 August 2023
The research was conducted by a group of eight researchers representing the Graz University of Technology in Austria and the CISPA Helmholtz Center for Information Security in Germany.

Study Downplays Cyber Insurance as Incentive to Pay Ransom

02 August 2023
Fears that cyber insurance coverage drives companies into paying ransomware demands more easily than otherwise appear unfounded, concludes a British think tank study that suggests insurers should do more to enact corporate discipline.

Top Industries Significantly Impacted by Illicit Telegram Networks

02 August 2023
In recent years the rise of illicit activities conducted within online messaging platforms has become a growing concern for countless industries. One of the most notable platforms that has been host to many malicious actors and nefarious activities has been Telegram. Thanks to its accessibility, popularity, and user anonymity, Telegram has attracted a large number of threat actors driven by

Researchers Uncover AWS SSM Agent Misuse as a Covert Remote Access Trojan

02 August 2023
Cybersecurity researchers have discovered a new post-exploitation technique in Amazon Web Services (AWS) that allows the AWS Systems Manager Agent (SSM Agent) to be run as a remote access trojan on Windows and Linux environments "The SSM agent, a legitimate tool used by admins to manage their instances, can be re-purposed by an attacker who has achieved high privilege access on an endpoint with

Chattanooga Heart Institute Notifies 170,000 of Hacking, Data Breach

02 August 2023
In a report filed to Maine's attorney general on Friday, The Chattanooga Heart Institute said that on April 17 it saw indications of a cyberattack on its IT network. The incident affected 170,450 individuals in total, including five Maine residents.

Cloud Tech Debt Puts Millions of Apps at Risk, Says New Report

02 August 2023
According to new data by Qualys, over 60 million applications reached the end of support and end of life during the research period. Critical categories, such as databases, web servers, and security software, now lack security updates.

UK Military Embraces Security by Design

02 August 2023
The UK’s Ministry of Defence (MoD) has launched its Secure by Design initiative, which is to transform how cybersecurity is built into its systems and capabilities both internally and across its supply chain.

Silk Security Emerges from Stealth With $12.5 Million Seed Funding

02 August 2023
The seed funding round for the New York-based company was led by Insight Partners and Hetz Ventures, with the CrowdStrike Falcon Fund and angel investors including Shlomo Kramer, Mickey Boodaei, and Rakesh Loonkar also participating.

Data Breach Reported in Arizona’s School Voucher Program

02 August 2023
Arizona's Empowerment Scholarship Account program experienced a data breach where personal information of students, including names and disability categories, was viewable on the program's financial vendor's website.

Newly Discovered WikiLoader Malware Used to Install Ursnif Trojan

02 August 2023
Proofpoint discovered a new malware WikiLoader, a sophisticated malware downloader that targets Italian organizations to drop Ursnif trojan. It uses multiple evasion techniques to make detection and analysis difficult. Organizations and network defenders must leverage IOCs related to the malware to understand the current attack patterns and enhance the defense approaches to stay safe.