Latest Cybersecurity News and Articles


SpyNote Android Spyware Strikes Financial Institutions Through Smishing Campaigns

01 August 2023
The infection chain typically begins with a deceptive SMS message urging users to install a “new certified banking app,” followed by a redirect to a seemingly authentic TeamViewer app, which is used for technical remote support.

Mattress Giant Tempur Sealy Hit with Cyberattack Forcing System Shutdown

01 August 2023
The company’s chief financial officer Bhaskar Rao reported to the U.S. Securities and Exchange Commission on Monday morning that Tempur Sealy’s operations had been hindered by a cyberattack that began on July 23.

Spike in Ransomware Delivery via URLs, Reports Unit 42

01 August 2023
Ransomware delivered through URLs has become the leading method for distributing ransomware, accounting for over 77% of cases in 2022 - found Unit 42. This is followed by emails at 12%. Researchers observed attackers using different URLs/hostnames to host or deliver different malware, including ransomware strains. Vigilance, user education, advanced security solutions, regular backups, and efficient incident response are crucial to mitigating this emerging threat.

European Bank Customers Targeted in SpyNote Android Trojan Campaign

01 August 2023
Various European customers of different banks are being targeted by an Android banking trojan called SpyNote as part of an aggressive campaign detected in June and July 2023. "The spyware is distributed through email phishing or smishing campaigns and the fraudulent activities are executed with a combination of remote access trojan (RAT) capabilities and vishing attack," Italian cybersecurity

What is Data Security Posture Management (DSPM)?

01 August 2023
Data Security Posture Management is an approach to securing cloud data by ensuring that sensitive data always has the correct security posture - regardless of where it's been duplicated or moved to. So, what is DSPM? Here's a quick example: Let's say you've built an excellent security posture for your cloud data. For the sake of this example, your data is in production, it's protected behind a

Meta Subsidiaries Must Pay $14M Over Misleading Data Collection Disclosure

01 August 2023
Facebook's subsidiaries, including Onavo, have been ordered to pay $14 million in an Australian court case for undisclosed data collection through a now-discontinued VPN, highlighting the company's privacy issues.

Researchers Expose Space Pirates' Cyber Campaign Across Russia and Serbia

01 August 2023
The threat actor known as Space Pirates has been linked to attacks against at least 16 organizations in Russia and Serbia over the past year by employing novel tactics and adding new cyber weapons to its arsenal. "The cybercriminals' main goals are still espionage and theft of confidential information, but the group has expanded its interests and the geography of its attacks," Positive

The Race Against Time in Ransomware Attacks

01 August 2023
Despite both the rise in threats and the high percentage of respondents whose organizations suffered recent attacks, there hasn’t been a corresponding uptick in strategic measures to shore up cyber resilience, according to BigID.

China's APT31 Suspected in Attacks on Air-Gapped Systems in Eastern Europe

01 August 2023
A nation-state actor with links to China is suspected of being behind a series of attacks against industrial organizations in Eastern Europe that took place last year to siphon data stored on air-gapped systems. Cybersecurity company Kaspersky attributed the intrusions with medium to high confidence to a hacking crew called APT31, which is also tracked under the monikers Bronze Vinewood,

Web Browsing is the Primary Entry Vector for Ransomware Infections

01 August 2023
The attackers have been spotted rotating different URLs/hostnames to host the same ransomware or using the same URL to deliver different ransomware. Some attackers do both of these things.

Be Aware of Exposure of Sensitive Data on Wi-Fi Settings for Canon Inkjet Printers

01 August 2023
Canon warns that sensitive information on the Wi-Fi connection settings stored in the memories of home and office/large format inkjet printers may not be deleted by the usual initialization process.

Enterprises Should Layer-up Security to Avoid Legal Repercussions

01 August 2023
Implementing a nimble incident response process and establishing repeatable procedures for investigations are crucial for reducing the impact of data breaches and minimizing legal repercussions.

White House Unveils ‘Whole of Society’ Push To Expand Cybersecurity Workforce

01 August 2023
A sweeping partnership comprising nine government agencies and over 200 nonprofits, corporations, colleges, and universities will together build an organized “whole of society” approach to expanding the cybersecurity workforce, the ONCD announced.

New WikiLoader Malware Employs Sophisticated Evasion

01 August 2023
WikiLoader is a sophisticated downloader malware that evades detection and is likely available for sale to multiple cybercriminal groups. It has been observed in multiple campaigns targeting Italian organizations.

Cybercriminals Renting WikiLoader to Target Italian Organizations with Banking Trojan

01 August 2023
Organizations in Italy are the target of a new phishing campaign that leverages a new strain of malware called WikiLoader with an ultimate aim to install a banking trojan, stealer, and spyware called Ursnif (aka Gozi). "It is a sophisticated downloader with the objective of installing a second malware payload," Proofpoint said in a technical report. "The malware uses multiple mechanisms to evade

Hackers Exploit Bleedingpipe RCE Flaw to Target Minecraft Servers, Players

31 July 2023
BleedingPipe is a vulnerability found in many Minecraft mods caused by the incorrect use of deserialization in the 'ObjectInputStream' class in Java to exchange network packets between servers and clients.

White House Unveils National Cyber Workforce Strategy

31 July 2023
"Cyber education and workforce development have not kept pace with demand and the rapid pace of technological change," says the strategy document. "Moreover, skills in demand in the cyber workforce are evolving."

Fredrick Lee named Reddit’s Chief Information Security Officer

31 July 2023
Fredrick “Flee” Lee has been named Reddit’s new Chief Information Security Officer (CISO).

Between 80- and 95% of cyberattacks begin with phishing

31 July 2023
A recent Comcast Business report pulls data from 23.5 billion cybersecurity attacks and found that attacks come from internal and external sources.

Blocking Access to ChatGPT is a Short Term Solution to Mitigate Risk

31 July 2023
For every 10,000 enterprise users, an enterprise organization is experiencing approximately 183 incidents of sensitive data being posted to ChatGPT per month, according to Netskope.