Latest Cybersecurity News and Articles


Companies are rushing into generative AI without a cohesive, secure strategy

26 July 2023
Despite mass adoption of generative AI, most companies don’t have a coordinated strategy for deploying it or know how to assess its security—exposing them to risks and disadvantages if they don’t change their approach, according to Grammarly.

ALPHV Ransomware Adds Data Leak API in New Extortion Strategy

26 July 2023
The ALPHV ransomware gang, also referred to as BlackCat, is trying to put more pressure on their victims to pay a ransom by providing an API for their leak site to increase visibility for their attacks.

Consumers Demand More From Businesses When It Comes to Security

26 July 2023
Incorporating machine learning into fraud prevention strategies is crucial for businesses to effectively identify and prevent fraud, as well as meet growing fraud risks and consumer expectations.

The Alarming Rise of Infostealers: How to Detect this Silent Threat

26 July 2023
A new study conducted by Uptycs has uncovered a stark increase in the distribution of information stealing (a.k.a. infostealer or stealer) malware. Incidents have more than doubled in Q1 2023, indicating an alarming trend that threatens global organizations. According to the new Uptycs' whitepaper, Stealers are Organization Killers, a variety of new info stealers have emerged this year, preying

Fenix Cybercrime Group Poses as Tax Authorities to Target Latin American Users

26 July 2023
Tax-paying individuals in Mexico and Chile have been targeted by a Mexico-based cybercrime group that goes by the name Fenix to breach targeted networks and steal valuable data. A key hallmark of the operation entails cloning official portals of the Servicio de Administración Tributaria (SAT) in Mexico and the Servicio de Impuestos Internos (SII) in Chile and redirecting potential victims to

Former NSA Insider Coker is White House Pick for National Cyber Director

26 July 2023
President Joe Biden on Tuesday announced he intends to nominate Harry Coker, a former executive director of the National Security Agency, to be the country’s national cyber director.

VMware Fixes Bug Exposing Cloud Foundry API Admin Credentials in Audit Logs

26 July 2023
Tracked as CVE-2023-20891, the security flaw addressed today by Vmware would allow remote attackers with low privileges to access Cloud Foundry API admin credentials on unpatched systems in low-complexity attacks that don't require user interaction.

New AI Tool 'FraudGPT' Emerges, Tailored for Sophisticated Attacks

26 July 2023
Following the footsteps of WormGPT, threat actors are advertising yet another cybercrime generative artificial intelligence (AI) tool dubbed FraudGPT on various dark web marketplaces and Telegram channels. "This is an AI bot, exclusively targeted for offensive purposes, such as crafting spear phishing emails, creating cracking tools, carding, etc.," Netenrich security researcher Rakesh Krishnan 

EU Governments Reject Requiring Manufacturers to Report Vulnerabilities to Central Cyber Agency

26 July 2023
European Union governments have pushed back on the central role initially suggested for the bloc’s cybersecurity agency, rejecting a proposal requiring manufacturers to report actively exploited vulnerabilities to the ENISA.

Critical Flaws Found in Microsoft Message Queuing Service

26 July 2023
Three vulnerabilities have been discovered within the Microsoft Message Queuing (MSMQ) service – a proprietary messaging protocol designed to enable secure communication between applications running on separate computers.

Australian Government Exposed Personal Information via Security Report

26 July 2023
The Guardian Australia revealed yesterday that around 50 business owners and employees got more than they bargained for when they took part in the Understanding Small Business and Cyber Security study.

Update: Norway Says Ivanti Zero-Day Was Used to Hack Government IT Systems

26 July 2023
The Norwegian National Security Authority (NSM) has confirmed that attackers used a zero-day vulnerability in Ivanti's Endpoint Manager Mobile (EPMM) solution to breach a software platform used by 12 ministries in the country.

Over 400,000 Corporate Credentials Stolen by Info-Stealing Malware

26 July 2023
The analysis of nearly 20 million information-stealing malware logs sold on the dark web and Telegram channels revealed that they had achieved significant infiltration into business environments.

Cybersecurity Public-Private Partnership: Where Do We Go Next?

26 July 2023
Sharing threat information and cooperating with other threat intelligence groups helps to strengthen customer safeguards and boosts the effectiveness of the cybersecurity sector overall.

Rust-based Realst Infostealer Targeting Apple macOS Users' Cryptocurrency Wallets

26 July 2023
A new malware family called Realst has become the latest to target Apple macOS systems, with a third of the samples already designed to infect macOS 14 Sonoma, the upcoming major release of the operating system. Written in the Rust programming language, the malware is distributed in the form of bogus blockchain games and is capable of "emptying crypto wallets and stealing stored password and

Critical MikroTik RouterOS Vulnerability Exposes Over Half a Million Devices to Hacking

26 July 2023
A severe privilege escalation issue impacting MikroTik RouterOS could be weaponized by remote malicious actors to execute arbitrary code and seize full control of vulnerable devices. Cataloged as CVE-2023-30799 (CVSS score: 9.1), the shortcoming is expected to put approximately 500,000 and 900,000 RouterOS systems at risk of exploitation via their web and/or Winbox interfaces, respectively,

Who and What is Behind the Malware Proxy Service SocksEscort?

25 July 2023
Researchers this month uncovered a two-year-old Linux-based remote access trojan dubbed AVrecon that enslaves Internet routers into botnet that bilks online advertisers and performs password-spraying attacks. Now new findings reveal that AVrecon is the malware engine behind a 12-year-old service called SocksEscort, which rents hacked residential and small business devices to cybercriminals looking to hide their true location online.

Travel and tourism sector ranked third in cyberattack incidents

25 July 2023
With increased digitalization comes greater vulnerability to cyber threats, making cybersecurity a top priority for lodging and aviation companies.

Spyhide Stalkerware is Spying on Tens of Thousands of Phones

25 July 2023
Spyhide is secretly collecting private data from tens of thousands of Android devices worldwide. The app is often installed on a victim's phone by someone who knows their passcode, and it remains hidden on the home screen.

Casbaneiro Banking Malware Goes Under the Radar with UAC Bypass Technique

25 July 2023
"They are still heavily focused on Latin American financial institutions, but the changes in their techniques represent a significant risk to multi-regional financial organizations as well," Sygnia said in a statement shared with The Hacker News.