Latest Cybersecurity News and Articles


Perimeter81 Vulnerability Disclosed After Botched Disclosure Process

24 July 2023
Cybersecurity researcher Erhad Husovic published a blog post in late June to disclose the details of a local privilege escalation vulnerability discovered in Perimeter81’s macOS application.

How to Protect Patients and Their Privacy in Your SaaS Apps

24 July 2023
The healthcare industry is under a constant barrage of cyberattacks. It has traditionally been one of the most frequently targeted industries, and things haven’t changed in 2023. The U.S. Government’s Office for Civil Rights reported 145 data breaches in the United States during the first quarter of this year. That follows 707 incidents a year ago, during which over 50 million records were

CISOs are making cybersecurity a business problem

24 July 2023
U.S. enterprises are responding to growing cybersecurity threats by working to make the best use of tools and services to ensure business resilience, according to an ISG report.

First Known Targeted OSS Supply Chain Attacks Against the Banking Sector

24 July 2023
The attackers employed deceptive tactics such as creating fake LinkedIn profiles to appear credible and using customized command and control (C2) centers for each target, exploiting legitimate services for illicit activities.

Attackers intensify DDoS attacks with new tactics

24 July 2023
As we entered 2023, the cybersecurity landscape witnessed an increase in sophisticated, high-volume attacks, according to Gcore. The maximum attack power rose from 600 to 800 Gbps.

CERT-In Cautions Internet Users Against Akira Ransomware Attack

24 July 2023
In its latest advisory, India's federal cybersecurity agency warned of a ransomware called 'Akira' that steals vital personal information and encrypts data leading to extortion of money from people.

Update: Virustotal Apologizes for Accidental Leak That Exposed Customer Data

24 July 2023
Google’s malware scanning platform VirusTotal published an apology on Friday after hundreds of individuals working for defense and intelligence agencies globally had their names and email addresses accidentally exposed by an employee.

Ransom Monetization Rates Fall to Record Low Despite Jump In Average Ransom Payments

24 July 2023
According to a Coveware report, in the second quarter of 2023, the percentage of ransomware attacks resulting in payment decreased to a record low of 34%. This is attributed to companies investing in security measures and incident response training.

New OpenSSH Vulnerability Exposes Linux Systems to Remote Command Injection

24 July 2023
Details have emerged about a now-patched flaw in OpenSSH that could be potentially exploited to run arbitrary commands remotely on compromised hosts under specific conditions. "This vulnerability allows a remote attacker to potentially execute arbitrary commands on vulnerable OpenSSH's forwarded ssh-agent," Saeed Abbasi, manager of vulnerability research at Qualys, said in an analysis last week.

White House Secures Safety Commitments From Seven AI Companies

24 July 2023
Seven leading AI companies, including Amazon, Anthropic, Google, Meta, Microsoft, OpenAI, and Inflection, have committed to building secure systems and increasing transparency regarding model behavior, The White House announced Friday.

Phishers Exploiting Google Docs to Harvest Crypto Credentials

24 July 2023
Researchers at Check Point Software have discovered a new phishing scam campaign that exploits Google Docs to distribute illegitimate URLs and steal cryptocurrency credentials.

Update: Microsoft Attackers May Have Data Access Beyond Outlook, Researchers Warn

24 July 2023
The China-linked threat actors behind the theft of U.S. State Department and other Microsoft customer emails may have gained access to applications beyond Exchange Online and Outlook.com, according to a report released Friday by Wiz.

Clop Now Leaks Data Stolen in Moveit Attacks on Clearweb Sites

24 July 2023
The Clop ransomware gang is copying an ALPHV ransomware gang extortion tactic by creating Internet-accessible websites dedicated to specific victims, making it easier to leak stolen data and further pressuring victims into paying a ransom.

Banking Sector Targeted in Open-Source Software Supply Chain Attacks

24 July 2023
Cybersecurity researchers said they have discovered what they say is the first open-source software supply chain attacks specifically targeting the banking sector. "These attacks showcased advanced techniques, including targeting specific components in web assets of the victim bank by attaching malicious functionalities to it," Checkmarx said in a report published last week. "The attackers

Cl0p Gang to Earn Over $75 Million From MOVEit Extortion Attacks

22 July 2023
In a new report released today, Coveware explains that the number of victims paying ransoms has fallen to a record low of 34%, causing ransomware gangs to switch strategies to make their attacks more profitable.

Global CDN Service ‘jsdelivr’ Exposed Users to Phishing Attacks

22 July 2023
The malicious NPM package, which masqueraded as a legitimate alternative to a popular package, downloaded a phishing HTML code from the jsdelivr CDN service to steal users' credentials.

DHL Investigating MOVEit Breach as Number of Victims Surpasses 20 Million

22 July 2023
The United Kingdom arm of shipping giant DHL said it is investigating a data breach sourced back to its use of the MOVEit software, which has been exploited by a Russia-based ransomware group for nearly two months.

Coastal Mississippi County Recovering From Ransomware Attack

22 July 2023
The local government in George County, Mississippi, was thrown into chaos this weekend when ransomware actors used a discrete phishing email to gain deep access to the county’s systems.

Apple Threatens to Pull iMessage and FaceTime from U.K. Amid Surveillance Demands

22 July 2023
Apple has warned that it would rather stop offering iMessage and FaceTime services in the U.K. than bowing down to government pressure in response to new proposals that seek to expand digital surveillance powers available to state intelligence agencies. The development, first reported by BBC News, makes the iPhone maker the latest to join the chorus of voices protesting against forthcoming

Few Fortune 100 Firms List Security Pros in Their Executive Ranks

21 July 2023
Many things have changed since 2018, such as the names of the companies in the Fortune 100 list. But one aspect of that vaunted list that hasn't shifted much since is that very few of these companies list any security professionals within their top executive ranks. The next time you receive a breach notification letter that invariably says a company you trusted places a top priority on customer security and privacy, consider this: Only four of the Fortune 100 companies currently list a security professional in the executive leadership pages of their websites. This is actually down from five of the Fortune 100 in 2018, the last time KrebsOnSecurity performed this analysis.