Latest Cybersecurity News and Articles


BreachForums Database and Private Chats for Sale in Hacker Data Breach

28 July 2023
While consumers are usually the ones worried about their information being exposed in data breaches, it's now the hacker's turn, as the notorious Breached cybercrime forum's database is up for sale and member data shared with Have I Been Pwned.

A step-by-step guide for patching software vulnerabilities

28 July 2023
Coalition’s recent Cyber Threat Index 2023 predicts the average Common Vulnerabilities and Exposures (CVEs) rate will rise by 13% over 2022 to more than 1,900 per month in 2023.

Update: Hawaiʻi Community College Pays Ransom After Attackers Steal Personal Info of 28,000 People

28 July 2023
The attack was claimed by the NoEscape ransomware group, a new gang that emerged in May. Despite paying the ransom, the community college is still in the process of restoring its IT infrastructure.

CISA and Partners Release Joint Cybersecurity Advisory on Preventing Web Application Access Control Abuse

28 July 2023
These vulnerabilities are frequently exploited by malicious actors in data breach incidents and have resulted in the compromise of personal, financial, and health information of millions of users and consumers.

BlueBravo Deploys GraphicalProton Backdoor Against European Diplomatic Entities

28 July 2023
The Russian nation-state actor known as BlueBravo has been observed targeting diplomatic entities throughout Eastern Europe with the goal of delivering a new backdoor called GraphicalProton, exemplifying the continuous evolution of the threat. The phishing campaign is characterized by the use of legitimate internet services (LIS) for command-and-control (C2) obfuscation, Recorded Future said in

TSA Revises Security Directives for Oil and Gas Pipelines to Test Resilience

28 July 2023
The Transportation Security Administration revised its security directive on cybersecurity for oil and natural gas pipelines Wednesday. The directive was issued and later renewed following the ransomware attack on Colonial Pipeline.

Major Security Flaw Discovered in Metabase BI Software – Urgent Update Required

28 July 2023
"An unauthenticated attacker can run arbitrary commands with the same privileges as the Metabase server on the server you are running Metabase on," Metabase said in an advisory released last week.

Major Security Flaw Discovered in Metabase BI Software – Urgent Update Required

28 July 2023
Users of Metabase, a popular business intelligence and data visualization software package, are being advised to update to the latest version following the discovery of an "extremely severe" flaw that could result in pre-authenticated remote code execution on affected installations. Tracked as CVE-2023-38646, the issue impacts open-source editions prior to 0.46.6.1 and Metabase Enterprise

Cybersecurity Agencies Warn Against IDOR Bugs Exploited for Data Breaches

28 July 2023
Cybersecurity agencies in Australia and the U.S. have published a joint cybersecurity advisory warning against security flaws in web applications that could be exploited by malicious actors to orchestrate data breach incidents and steal confidential data. This includes a specific class of bugs called Insecure Direct Object Reference (IDOR), a type of access control flaw that occurs when an

Legal industry expresses AI concerns

27 July 2023
The legal industry's response to artificial intelligence (AI) was analyzed in a recent report by Litify, finding that there were privacy concerns. 

Elizabeth Davies joins Verkada as Chief Privacy Officer

27 July 2023
Elizabeth Davies has been hired as Chief Privacy Officer at Verkada. Davies will oversee Verkada's privacy and government affairs programs.

CISA Analysis Shows Most Cyberattacks on Governments, Critical Infrastructure Involve Valid Credentials

27 July 2023
More than half of all cyberattacks on government agencies, critical infrastructure organizations, and state-level government bodies involved the use of valid accounts, according to a new report from the CISA.

CardioComm Takes Systems Offline Following Cyberattack

27 July 2023
The attack, the company says, impacted its production server environments and has an impact on its business operations. Visitors to the company’s website are informed that CardioComm services are currently offline.

Up to 11 Million People Hit by MOVEit Hack at Government Services Firm Maximus

27 July 2023
According to Maximus, the attackers stole files containing personal information and protected health information, including Social Security numbers, “of at least 8 to 11 million individuals”.

Report reveals new information about Akira Group connection to Conti

27 July 2023
New research dives into the Akira ransomware group, including the group’s recent victim focuses, tactics and affiliation with Conti.

China Allegedly Turns to Transnational Criminals to Spread Disinformation in Australia

27 July 2023
Australian researchers have found evidence that China is using fake social media accounts linked to transnational criminal groups to spread online propaganda and disinformation.

Hackers Target Apache Tomcat Servers for Mirai Botnet and Crypto Mining

27 July 2023
Misconfigured and poorly secured Apache Tomcat servers are being targeted as part of a new campaign designed to deliver the Mirai botnet malware and cryptocurrency miners.

Introducing FraudGPT: The Latest AI Cybercrime Tool in the Dark Web

27 July 2023
In the wake of WormGPT's success, threat actors have now introduced another AI-powered cybercrime tool called FraudGPT. This AI bot is being promoted on numerous dark web marketplaces and Telegram channels, and is capable of designing spear-phishing emails, generating cracking tools, and facilitating carding activities.

Industry Coalition Calls For Enhanced Network Resilience

27 July 2023
The alliance argued that, while these vendors and their peers work hard to make their products as secure as possible, end-customer patching and vulnerability management is often sub-par.

Decoy Dog Malware Evolves to Expand its Reach

27 July 2023
An unidentified nation-state appears to be preparing for a new hacking campaign, according to researchers at Infoblox. The campaign uses the relatively new Decoy Dog malware toolkit. Decoy Dog has undergone a major upgrade from Pupy, an open-source remote access tool, to disguise its activities and ensure long-term access to compromised devices.