Latest Cybersecurity News and Articles


NATO Investigates Alleged Data Theft by SiegedSec Hackers

27 July 2023
Cybersecurity company CloudSEK analyzed the leaked data and found that it comprises 845MB of files, 8,000 rows of user-related sensitive information, unclassified documents, and user account access details.

GameOver(lay): Two Severe Linux Vulnerabilities Impact 40% of Ubuntu Users

27 July 2023
Cybersecurity researchers have disclosed two high-severity security flaws in the Ubuntu kernel that could pave the way for local privilege escalation attacks. Cloud security firm Wiz, in a report shared with The Hacker News, said the easy-to-exploit shortcomings have the potential to impact 40% of Ubuntu users. "The impacted Ubuntu versions are prevalent in the cloud as they serve as the default

DOJ Reorganizes Units to Better Fight Ransomware

27 July 2023
The U.S. Justice Department is merging its National Cryptocurrency Enforcement Team with its Crime and Intellectual Property Section to strengthen its capabilities in investigating cryptocurrency-related criminal cases and cybercrime.

New Malvertising Campaign Distributing Trojanized IT Tools via Google and Bing Search Ads

27 July 2023
A new malvertising campaign has been observed leveraging ads on Google Search and Bing to target users seeking IT tools like AnyDesk, Cisco AnyConnect VPN, and WinSCP, and trick them into downloading trojanized installers with an aim to breach enterprise networks and likely carry out future ransomware attacks. Dubbed Nitrogen, the "opportunistic" activity is designed to deploy second-stage

New Nitrogen Malware Pushed via Google Ads for Ransomware Attacks

27 July 2023
Sophos X-Ops researchers have discovered a new malware campaign called Nitrogen. The campaign uses malicious advertising and impersonates legitimate software to compromise business networks.

Repeatable VEC Attacks Target Critical Infrastructure

27 July 2023
According to a new report published by cybersecurity firm Abnormal Security earlier today, VEC attacks – a variant of business email compromise (BEC) – pose a significant risk to organizations worldwide.

Akira Ransomware Compromised at Least 63 Victims Since March

27 July 2023
Akira commonly infiltrates targeted Windows and Linux systems through VPN services, especially where users haven't enabled multi-factor authentication. To gain access, attackers use compromised credentials, which are likely acquired on the dark web.

Zero Trust Rated as Highly Effective by Businesses Worldwide

27 July 2023
Zero trust is here to stay, with 82% of experts currently working on implementing zero trust, and 16% planning to begin within 18 months, according to a study by Beyond Identity.

Lazarus Hackers Linked to $60 Million Alphapo Cryptocurrency Theft

27 July 2023
Blockchain analysts blame the North Korean Lazarus hacking group for a recent attack on payment processing platform Alphapo where the attackers stole almost $60 million in crypto.

The 4 Keys to Building Cloud Security Programs That Can Actually Shift Left

27 July 2023
As cloud applications are built, tested and updated, they wind their way through an ever-complex series of different tools and teams. Across hundreds or even thousands of technologies that make up the patchwork quilt of development and cloud environments, security processes are all too often applied in only the final phases of software development.  Placing security at the very end of the

Why are computer security guidelines so confusing?

27 July 2023
Computer security guidelines often become overwhelming and confusing due to the inclusion of excessive information, leading to the most important points being lost in the shuffle.

Hackers Target Apache Tomcat Servers for Mirai Botnet and Crypto Mining

27 July 2023
Misconfigured and poorly secured Apache Tomcat servers are being targeted as part of a new campaign designed to deliver the Mirai botnet malware and cryptocurrency miners. The findings come courtesy of Aqua, which detected more than 800 attacks against its Tomcat server honeypots over a two-year time period, with 96% of the attacks linked to the Mirai botnet. Of these attack attempts, 20% (or

macOS Under Attack: Examining the Growing Threat and User Perspectives

27 July 2023
Mac users are facing increasing threats to their security, with hackers specifically targeting Apple devices using malware such as Geacon, MacStealer, CloudMensis, and JockerSpy, compromising user data and privacy.

Group-IB Co-Founder Sentenced to 14 Years in Russian Prison for Alleged High Treason

27 July 2023
A city court in Moscow on Wednesday convicted Group-IB co-founder and CEO Ilya Sachkov of "high treason" and jailed him for 14 years in a "strict regime colony" over accusations of passing information to foreign spies. "The court found Sachkov guilty under Article 275 of the Russian Criminal Code (high treason) sentencing him to 14 years of incarceration in a maximum-security jail, restriction

Who and What is Behind the Malware Proxy Service SocksEscort? – Krebs on Security

27 July 2023
Proxy services like SocksEscort are exploited by cybercriminals to hide their true location online and engage in malicious activities, making it difficult to trace their actions back to the original source.

Cryptojacking soars as cyberattacks increase, diversify

27 July 2023
Despite the decline in global ransomware attempts (-41%), a variety of other attacks have trended up globally, including cryptojacking (+399%), IoT malware (+37%), and encrypted threats (+22%), according to SonicWall.

Wiz Says 62% of AWS Environments Exposed to Zenbleed Exploitation

27 July 2023
In a research note posted Wednesday, Wiz calculated that more than 60 percent of AWS environments are running EC2 instances with Zen 2 CPUs and may therefore be affected by the use-after-free memory corruption bug.

SEC Wants Cyber-Incident Disclosure Within Four Days

27 July 2023
The US Securities and Exchange Commission (SEC) has adopted new rules requiring publicly listed firms to disclose serious incidents within four days. The regulator voted 3-2 to adopt the rules.

Almost 40% of Ubuntu Users Vulnerable to New Privilege Elevation Flaws

27 July 2023
Two recent flaws tracked as CVE-2023-32629 and CVE-2023-2640 discovered by Wiz's researchers S. Tzadik and S. Tamari were recently introduced into the operating system, impacting roughly 40% of Ubuntu's userbase.

New SEC Rules Require U.S. Companies to Reveal Cyber Attacks Within 4 Days

27 July 2023
The U.S. Securities and Exchange Commission (SEC) on Wednesday approved new rules that require publicly traded companies to publicize details of a cyber attack within four days of identifying that it has a "material" impact on their finances, marking a major shift in how computer breaches are disclosed. "Whether a company loses a factory in a fire — or millions of files in a cybersecurity