Latest Cybersecurity News and Articles
18 July 2023
The ransomware attack, which impacted multiple UKG customers such as Tesla, PepsiCo, Whole Foods, and New York City’s Metropolitan Transportation Authority, hindered some customers’ ability to process payroll.
18 July 2023
Using the online moniker ‘La_Citrix’, the threat actor has been active on Russian-speaking cybercrime forums since 2020, offering access to hacked companies and info-stealer logs from active infections.
18 July 2023
The Biden administration has considered an Energy Star type of consumer labeling program a key part of an effort to strengthen the nation’s cyber infrastructure following the SolarWinds and Colonial Pipeline attacks.
18 July 2023
Operating as part of a Man-in-the-Browser (MITB) attack, the web injects allow cybercriminals to manipulate the content of legitimate web pages in real time, bypassing the TLS protocol.
18 July 2023
Cybersecurity, risk management and insider risks within the life sciences industry were analyzed in a recent report by Code42 Software.
18 July 2023
The forensic investigation confirmed that there had been unauthorized access to files containing the protected health information of patients, some of which may have been obtained by the hackers.
18 July 2023
[This is Part III in a series on research conducted for a recent Hulu documentary on the 2015 hack of marital infidelity website AshleyMadison.com.]
In 2019, a Canadian company called Defiant Tech Inc. pleaded guilty to running LeakedSource[.]com, a service that sold access to billions of passwords and other data exposed in countless data breaches. KrebsOnSecurity has learned that the owner of Defiant Tech, a 32-year-old Ontario man named Jordan Evan Bloom, was hired in late 2014 as a developer for the marital infidelity site AshleyMadison.com. Bloom resigned from AshleyMadison citing health reasons in June 2015 -- less than one month before unidentified hackers stole data on 37 million users -- and launched LeakedSource three months later.
18 July 2023
For the past decade, millions of emails destined for .mil US military addresses were actually directed at .ml addresses, that being the top-level domain for the African nation of Mali, it's claimed.
18 July 2023
A report highlights how financial services organizations have embraced the cloud in response to the pandemic-fueled movement toward remote work.
18 July 2023
The average number of scam resources per brand across all regions and industries more than doubled year-on-year in 2022, up 162%, according to Group-IB. Additionally, the total number of scam pages detected in 2022 was more than thrice in 2021.
18 July 2023
Cybersecurity researcher Jeremiah Fowler discovered a non-password-protected database containing approximately 2.3 million records associated with multiple dating applications.
18 July 2023
GoTo recently announced the appointment of Attila Török as Chief Information Security Officer (CISO).
18 July 2023
The fraudster was apprehended at Barcelona airport after managing to evade capture for over a decade, according to Spanish police. They were apparently supported by the FBI and Interpol, which had issued a red notice for the individual’s capture.
18 July 2023
Data associated with a subset of registered customers of VirusTotal, including their names and email addresses, were exposed after an employee inadvertently uploaded the information to the malware scanning platform.
18 July 2023
An unidentified threat actor compromised an application used by multiple entities in Pakistan to deliver ShadowPad, a successor to the PlugX backdoor that's commonly associated with Chinese hacking crews.
Targets included a Pakistan government entity, a public sector bank, and a telecommunications provider, according to Trend Micro. The infections took place between mid-February 2022 and
18 July 2023
A series of phishing emails is directing recipients to packed executable files containing the BlotchyQuasar malware variant, allegedly developed by a threat group known as Hive0129. Several features of it were found to overlap with a malware called ProyectoRAT. IOCs associated with the attack campaign will help organizations in eliminating or blocking the threat.
18 July 2023
The British company known for its anti-phishing and cybercrime disruption tools said the $100 million financing was led by Spectrum Equity, a growth equity firm focused on internet-enabled software and data services companies.
18 July 2023
The Syssphinx cybercrime group, known for financially motivated attacks, has diversified its tactics by deploying ransomware in addition to its traditional point-of-sale attacks.
18 July 2023
Chinese President Xi Jinping has directed officials to build a Beijing-controlled "security barrier" around the country's internet, emphasizing the Party's leadership and the need to govern cyberspace according to the law.
18 July 2023
Data associated with a subset of registered customers of VirusTotal, including their names and email addresses, have leaked on the internet.
The security incident, which comprises a database of 5,600 names in a 313KB file, was first disclosed by Der Spiegel and Der Standard yesterday.
Launched in 2004, VirusTotal is a popular service that analyzes suspicious files and URLs to detect types of