Latest Cybersecurity News and Articles


Apache OpenMeetings Web Conferencing Tool Exposed to Critical Vulnerabilities

20 July 2023
Multiple security flaws have been disclosed in Apache OpenMeetings, a web conferencing solution, that could be potentially exploited by malicious actors to seize control of admin accounts and run malicious code on susceptible servers. "Attackers can bring the application into an unexpected state, which allows them to take over any user account, including the admin account," Sonar vulnerability

Tampa General Hospital Says Hackers Exfiltrated the Data of 1.2 Million Patients

20 July 2023
A security breach was detected on May 31, 2023, when suspicious activity was identified within its network. The affected systems were immediately taken offline to prevent further unauthorized access.

97% of organizations report plans to use generative AI by 2025

20 July 2023
A recent study from Grammarly and Forrester found that generative AI is being adopted across more organizations despite growing security concerns.

Turla's New DeliveryCheck Backdoor Breaches Ukrainian Defense Sector

20 July 2023
DeliveryCheck is distributed via email with malicious macros and can breach Microsoft Exchange servers to install a server-side component, turning a legitimate server into a malware C2 server.

CISA and Microsoft partner to expand access to logging capabilities

20 July 2023
 A collaboration between CISA and Microsoft, will now expanded cloud logging capabilities at no additional charge to customers, enhancing cyber defense and incident response.

CISA and NSA Issue New Guidance to Strengthen 5G Network Slicing Against Threats

20 July 2023
U.S. cybersecurity and intelligence agencies have released a set of recommendations to address security concerns with 5G standalone network slicing and harden them against possible threats.

North Korean State-Sponsored Hackers Suspected in JumpCloud Supply Chain Attack

20 July 2023
An analysis of the indicators of compromise (IoCs) associated with the JumpCloud hack has uncovered evidence pointing to the involvement of North Korean state-sponsored groups, in a style that's reminiscent of the supply chain attack targeting 3CX. The findings come from SentinelOne, which mapped out the infrastructure pertaining to the intrusion to uncover underlying patterns. It's worth noting

Russian Medical Lab Suspends Some Services After Ransomware Attack

20 July 2023
Customers of the Russian medical laboratory Helix have been unable to receive their test results for several days due to a “serious” cyberattack that crippled the company's systems over the weekend.

Estée Lauder Takes Down Some Systems Following Cyberattack

20 July 2023
The ALPHV group claims Estée Lauder has not responded and listed the company on its leak site Tuesday, according to activity observed by Emsisoft Threat Analyst Brett Callow.

Microsoft Set to Expand Access to Detailed Logs in the Wake of Chinese Hacking Operation

20 July 2023
Microsoft said in a blog post on Wednesday that it will include “access to wider cloud security logs for our worldwide customers at no additional cost” starting in September and that it would increase default log retention from 90 to 180 days.

New P2PInfect Worm Targeting Redis Servers on Linux and Windows Systems

20 July 2023
"P2PInfect exploits Redis servers running on both Linux and Windows Operating Systems making it more scalable and potent than other worms," Palo Alto Networks Unit 42 researchers William Gamazo and Nathaniel Quist said.

Industry Experts Urge CISA to Update Secure by Design Guidance

20 July 2023
A joint letter by a group of industry experts urges CISA to go further in integrating and advocating threat modeling in the document, which aims to help manufacturers prioritize cybersecurity practices while designing technology products.

Nation States Using Cybercrime Groups as Proxies, Warns NCA Chief

20 July 2023
In his first public speech, Graeme Biggar, the new chief of the UK's National Crime Agency (NCA), highlighted the emerging links between serious crime groups and nation-state operations in cyberspace.

A Few More Reasons Why RDP is Insecure (Surprise!)

20 July 2023
If it seems like Remote Desktop Protocol (RDP) has been around forever, it's because it has (at least compared to the many technologies that rise and fall within just a few years.) The initial version, known as "Remote Desktop Protocol 4.0," was released in 1996 as part of the Windows NT 4.0 Terminal Server edition and allowed users to remotely access and control Windows-based computers over a

OpenAI Credentials Stolen by the Thousands for Sale on the Dark Web

20 July 2023
Over 200,000 OpenAI credentials are available for sale on the dark web, indicating that cybercriminals see potential in using AI tools like ChatGPT for malicious activities.

Recently Patched GE Cimplicity Vulnerabilities Reminiscent of Russian ICS Attacks

20 July 2023
Over a dozen vulnerabilities patched recently by GE in its Cimplicity product are reminiscent of industrial control system (ICS) attacks conducted by a notorious Russian hacker group.

Healthcare Organizations in the Crosshairs of Cyberattackers

20 July 2023
In an era where cyber threats continue to evolve, healthcare organizations are increasingly targeted by malicious actors employing multiple attack vectors, according to Trustwave.

Oracle Releases 508 New Security Patches With July 2023 CPU

20 July 2023
Successful exploitation of some of these vulnerabilities may lead to complete application or system compromise, Oracle says. Many of the updates also include additional third-party patches.

Turla's New DeliveryCheck Backdoor Breaches Ukrainian Defense Sector

20 July 2023
The defense sector in Ukraine and Eastern Europe has been targeted by a novel .NET-based backdoor called DeliveryCheck (aka CAPIBAR or GAMEDAY) that's capable of delivering next-stage payloads. The Microsoft threat intelligence team, in collaboration with the Computer Emergency Response Team of Ukraine (CERT-UA), attributed the attacks to a Russian nation-state actor known as Turla, which is

FIN8 APT Delivers BlackCat Ransomware Using Sardonic Backdoor Variant

20 July 2023
Symantec's Threat Hunter Team found a new variant of the FIN8’s Sardonic backdoor used to deliver the Noberus ransomware. In this new version, the group behind Sardonic has reworked most of its code, most likely to avoid detection. Organizations are recommended to monitor the networks and the latest versions of PowerShell logged into systems.