Latest Cybersecurity News and Articles


FTC warns against online tracking technology for healthcare providers

28 July 2023
Hospitals and telehealth providers have been warned by the FTC and the Office for Civil Rights (OCR) regarding online tracking technology.

DOD, OMB expect September release of proposed CMMC rule

28 July 2023
The rule has been delayed several times as the DOD revamp its approach, including changing to the longer proposed rule-making process. Originally, the expectation was that CMMC would come out as an interim final rule to be finalized in 60 days.

IcedID Malware Adapts and Expands Threat with Updated BackConnect Module

28 July 2023
The latest analysis of the attack infrastructure from Team Cymru has revealed that the number of BackConnect C2s have shot up from 11 to 34 since January 23, 2023, with the average uptime of a server significantly reducing from 28 days to eight days.

New report highlights the rise of IPv6 in cybercriminal activities

28 July 2023
A new report reveals some of the top emerging cybersecurity threats and trends worldwide.

New re highlights the rise of IPv6 in cybercriminal activities

28 July 2023
A new report reveals some of the top emerging cybersecurity threats and trends worldwide.

85% of security leaders cite complexity as wide area network challenge

28 July 2023
The increasing rise of hybrid and remote work has risen the demand for secure access service edge (SASE), according to a recent report.

Zimbra Patches Zero-Day Vulnerability Exploited in XSS Attacks

28 July 2023
Now tracked as CVE-2023-38750, the security flaw is a reflected Cross-Site Scripting (XSS) discovered by security researcher Clément Lecigne of Google Threat Analysis Group.

STARK#MULE Targets Koreans with U.S. Military-Themed Document Lures

28 July 2023
An ongoing cyber attack campaign has set its sights on Korean-speaking individuals by employing U.S. Military-themed document lures to trick them into running malware on compromised systems.

WordPress Ninja Forms Plugin Flaw Lets Hackers Steal Submitted Data

28 July 2023
Researchers at Patchstack discovered and disclosed the three vulnerabilities to the plugin's developer, Saturday Drive, on June 22nd, 2023, warning that it affects NinjaForms versions 3.6.25 and older.

IcedID Malware Adapts and Expands Threat with Updated BackConnect Module

28 July 2023
The threat actors linked to the malware loader known as IcedID have made updates to the BackConnect (BC) module that's used for post-compromise activity on hacked systems, new findings from Team Cymru reveal. IcedID, also called BokBot, is a strain of malware similar to Emotet and QakBot that started off as a banking trojan in 2017, before switching to the role of an initial access facilitator

STARK#MULE Targets Koreans with U.S. Military-themed Document Lures

28 July 2023
An ongoing cyber attack campaign has set its sights on Korean-speaking individuals by employing U.S. Military-themed document lures to trick them into running malware on compromised systems. Cybersecurity firm Securonix is tracking the activity under the name STARK#MULE. "Based on the source and likely targets, these types of attacks are on par with past attacks stemming from typical North

Innovative Attack Methodology Leverages the "search-ms" URI Protocol Handler

28 July 2023
A legitimate Windows search feature could be exploited by malicious actors to download arbitrary payloads from remote servers and compromise targeted systems with remote access trojans such as AsyncRAT and Remcos RAT.

Nitrogen Malvertising - Sneaky Malware in Search Ads

28 July 2023
A recently detected malvertising campaign, known as Nitrogen, has been discovered exploiting Google Search and Bing ads to target users searching for IT tools. The Nitrogen campaign predominantly focuses on technology and non-profit organizations in North America. It operates by posing as installers for well-known software such as AnyDesk, Cisco AnyConnect VPN, TreeSize Free, and WinSCP. 

BlueBravo Deploys GraphicalProton Backdoor Against European Diplomatic Entities

28 July 2023
The Russian nation-state actor known as BlueBravo has been observed targeting diplomatic entities throughout Eastern Europe with the goal of delivering a new backdoor called GraphicalProton, exemplifying the continuous evolution of the threat.

A Data Exfiltration Attack Scenario: The Porsche Experience

28 July 2023
As part of Checkmarx's mission to help organizations develop and deploy secure software, the Security Research team started looking at the security posture of major car manufacturers. Porsche has a well-established Vulnerability Reporting Policy (Disclosure Policy)[1], it was considered in scope for our research, so we decided to start there, and see what we could find. What we found is an

CISA to Establish Network of Regional Election Advisers for 2024

28 July 2023
Announced by Director Jen Easterly on Tuesday, the 10 advisers will support election officials working in their respective areas in an effort to “build even stronger connective tissue between state and local election officials and … CISA.”

Hackers Abusing Windows Search Feature to Install Remote Access Trojans

28 July 2023
A legitimate Windows search feature is being exploited by malicious actors to download arbitrary payloads from remote servers and compromise targeted systems with remote access trojans such as AsyncRAT and Remcos RAT. The novel attack technique, per Trellix, takes advantage of the "search-ms:" URI protocol handler, which offers the ability for applications and HTML links to launch custom local

Related CherryBlos and FakeTrade Android Malware Involved in Scam Campaigns

28 July 2023
The CherryBlos malware steals cryptocurrency wallet credentials and replaces withdrawal addresses, while the FakeTrade malware tricks users into downloading apps that promise increased income but prevent fund withdrawals.

Vulnerabilities Exposed Peloton Treadmills to Malware and Dos Attacks

28 July 2023
The Peloton Treadmill operates on the Android 10 operating system, which may be susceptible to over 1100+ potential vulnerabilities from recent years. Additionally, leaving USB debugging enabled could increase the attack surface.

Education Sector has Highest Ransomware Victim Count

28 July 2023
A new report by Sophos revealed that 79% of higher and 80% of “lower” education institutions were compromised by ransomware over the past year – up from 64% and 56% in 2021, respectively.