Latest Cybersecurity News and Articles


New AMI BMC Flaws Allowing Takeover and Physical Damage Could Impact Millions of Devices

21 July 2023
The new vulnerabilities disclosed by Eclypsium on Thursday are CVE-2023-34329, a critical authentication bypass issue that can be exploited by spoofing HTTP headers, and CVE-2023-34330, a code injection flaw.

Critical API Security Gaps Found in Financial Services

21 July 2023
According to the new data presented in Salt Security's 2023 State of API Security for Financial Services and Insurance report, nearly 70% of financial services and insurance companies have encountered rollout delays due to API security issues.

Report: 67% of Daily Security Alerts Overwhelm SOC Analysts

21 July 2023
On average, SOC teams receive 4,484 alerts daily and spend nearly three hours a day manually triaging alerts, according to a study by Vectra AI. Security analysts are unable to deal with 67% of the daily alerts received.

P2PInfect Worm: A Stealthy Cross-Platform Threat Targeting Redis Servers

21 July 2023
Cybersecurity researchers discovered a new P2P worm named P2PInfect that targets vulnerable Redis instances for exploitation. The worm is notable for its use of the critical Lua sandbox escape flaw, identified as CVE-2022-0543, to infect systems. Written in Rust, its attacks are more scalable than other worms. Organizations must use IOCs around the worm's modus operandi and implement robust security measures.

Adobe Releases New Patches for Exploited ColdFusion Vulnerabilities

21 July 2023
On July 19, Adobe issued another ColdFusion update to fix three new CVEs. One of them, CVE-2023-38205, is the bypass for CVE-2023-29298. The software giant warned in its advisory that CVE-2023-38205 has been exploited in the wild in limited attacks.

DDoS Botnets Hijacking Zyxel Devices to Launch Devastating Attacks

21 July 2023
Several distributed denial-of-service (DDoS) botnets have been observed exploiting a critical flaw in Zyxel devices that came to light in April 2023 to gain remote control of vulnerable systems. "Through the capture of exploit traffic, the attacker's IP address was identified, and it was determined that the attacks were occurring in multiple regions, including Central America, North America,

UK: Most CNI Firms Think Climate Tech is Increasing Cyber Risk

21 July 2023
Over eight in 10 (83%) of the UK’s critical national infrastructure (CNI) firms believe new technologies designed to enhance sustainability will become a significant vector for cyberattacks, according to Bridewell.

Update: Cyberattack on Github Customers Linked to North Korean Hackers, Microsoft Says

21 July 2023
GitHub attributed the attacks to a group known at Microsoft (which owns GitHub) by the name “Jade Sleet” and called TraderTraitor by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

Report: DDoS Attacks, Growing More Sophisticated, Surged in Q2

21 July 2023
Among the most serious attacks during Q2 2023, researchers noted an ACK flood DDoS attack that originated from a Mirai-variant botnet comprising about 11,000 IP addresses. The attack targeted an ISP in the U.S. and peaked at 1.4 terabits per second.

Report: Microsoft the Most Phished Brand in Q2 2023

21 July 2023
Microsoft, Google, and Apple were the most frequently impersonated brands in phishing attacks during Q2 2023, highlighting the need for cybersecurity measures to protect against brand phishing.

Update: Attacker Infrastructure Links JumpCloud Intrusion to North Korean APT Activity

21 July 2023
Analysis of the infrastructure linked to the JumpCloud intrusion reveals patterns consistent with previous DPRK-linked campaigns, highlighting their unique tactics and techniques.

FakeSG: A SocGholish Competitor Delivers NetSupport RAT

21 July 2023
A new malicious campaign FakeSG has emerged, mirroring the tactics of the well-known SocGholish in delivering the NetSupport RAT through compromised WordPress websites. FakeSG imitates browser update templates based on the victim's browser and uses different layers of obfuscation and delivery techniques. It is recommended to patch any vulnerabilities in your WordPress site/s.

Citrix NetScaler ADC and Gateway Devices Under Attack: CISA Urges Immediate Action

21 July 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory on Thursday warning that the newly disclosed critical security flaw in Citrix NetScaler Application Delivery Controller (ADC) and Gateway devices is being abused to drop web shells on vulnerable systems. "In June 2023, threat actors exploited this vulnerability as a zero-day to drop a web shell on a critical

Update: Old Roblox Data Leak Resurfaces, 4000 Users' Personal Information Exposed

20 July 2023
The leak, which initially occurred in 2021 but gained more attention after being re-published on a public hacking forum, has led to high-profile users receiving malicious calls, texts, and emails.

Mallox Ransomware Exploits Weak MS-SQL Servers to Breach Networks

20 July 2023
Mallox ransomware activities in 2023 have witnessed a 174% increase when compared to the previous year, new findings from Palo Alto Networks Unit 42 reveal. "Mallox ransomware, like many other ransomware threat actors, follows the double extortion trend: stealing data before encrypting an organization's files, and then threatening to publish the stolen data on a leak site as leverage to convince

Critical Flaws in AMI MegaRAC BMC Software Expose Servers to Remote Attacks

20 July 2023
Two more security flaws have been disclosed in AMI MegaRAC Baseboard Management Controller (BMC) software that, if successfully exploited, could allow threat actors to remotely commandeer vulnerable servers and deploy malware. "These new vulnerabilities range in severity from High to Critical, including unauthenticated remote code execution and unauthorized device access with superuser

Q2 observed more ransomware events than Q1

20 July 2023
Ransomware attacks in Q2 was analyzed in a recent report by GuidePoint Security and shows a 38% increase in public ransomware victims compared to Q1.

Renewable technologies add risk to the US electric grid, experts warn

20 July 2023
Technologies that underpin solar and wind energy storage systems, which are central to transferring renewable power to the grid, are potential hacking risks, experts noted at a congressional hearing Tuesday.

Phishing via Google Ads

20 July 2023
Hackers are using URL redirects within Google ads to lead users to malicious sites, leveraging the trust and legitimacy of Google Ads. This technique, known as BEC 3.0, involves referencing legitimate sites instead of spoofed ones.

Zyxel Vulnerability Exploited by DDoS Botnets on Linux Systems

20 July 2023
Distributed Denial of Service (DDoS) botnets have been used to actively exploit a critical vulnerability found in Zyxel firewall models. The flaw, identified by Fortinet security researchers as CVE-2023-28771, explicitly affects Linux platforms.