Latest Cybersecurity News and Articles


Go Beyond the Headlines for Deeper Dives into the Cybercriminal Underground

18 July 2023
Discover stories about threat actors’ latest tactics, techniques, and procedures from Cybersixgill’s threat experts each month. Each story brings you details on emerging underground threats, the threat actors involved, and how you can take action to mitigate risks. Learn about the top vulnerabilities and review the latest ransomware and malware trends from the deep and dark web. Stolen ChatGPT

Data Compromises on Track to Set a New Record

18 July 2023
The number of data compromises reported in the U.S. in the H1 of 2023 is higher than the total compromises reported every year between 2005 and 2020, except for 2017, according to Identity Theft Resource Center.

Meet NoEscape: Avaddon Ransomware Gang’s Likely Successor

18 July 2023
NoEscape launched in June 2023 when it began targeting the enterprise in double-extortion attacks. As part of these attacks, the threat actors steal data and encrypt files on Windows, Linux, and VMware ESXi servers.

FIN8 Group Using Modified Sardonic Backdoor for BlackCat Ransomware Attacks

18 July 2023
The financially motivated threat actor known as FIN8 has been observed using a "revamped" version of a backdoor called Sardonic to deliver the BlackCat ransomware. According to the Symantec Threat Hunter Team, part of Broadcom, the development is an attempt on the part of the e-crime group to diversify its focus and maximize profits from infected entities. The intrusion attempt took place in

CISA Provides Factsheet with Free Tools for Cloud Environments

18 July 2023
CISA has published a factsheet called "Free Tools for Cloud Environments" to assist businesses in identifying and utilizing open-source tools and techniques for protecting critical assets and data security in cloud environments.

BreachForums administrator facing 30-year sentence after pleading guilty to three charges

18 July 2023
Conor Brian Fitzpatrick was arrested at his home in Peekskill, New York in March by the FBI for his role in running BreachForums – one of the most visited cybercrime forums available to those looking to sell or purchase stolen data.

Cybercriminals Exploiting WooCommerce Payments Plugin Flaw to Hijack Websites

18 July 2023
"Large-scale attacks against the vulnerability, assigned CVE-2023-28121, began on Thursday, July 14, 2023, and continued over the weekend, peaking at 1.3 million attacks against 157,000 sites on Saturday, July 16, 2023," Wordfence researchers said.

Owner of BreachForums Pleads Guilty to Cybercrime and Child Pornography Charges

18 July 2023
Conor Brian Fitzpatrick, the owner of the now-defunct BreachForums website, has pleaded guilty to charges related to his operation of the cybercrime forum as well as having child pornography images. The development, first reported by DataBreaches.net last week, comes nearly four months after Fitzpatrick (aka pompompurin) was formally charged in the U.S. with conspiracy to commit access device

TeamTNT Steals to Azure and Google Cloud Credentials

18 July 2023
Researchers have uncovered a new cloud credential stealing campaign that specifically targets Azure and Google Cloud Platform (GCP) services. They discovered up to eight new versions of the credential harvesting script, indicating an actively evolving campaign. Notably, this campaign exhibits resemblances to the tactics used by the TeamTNT cryptojacking group.

Cybercriminals Exploiting WooCommerce Payments Plugin Flaw to Hijack Websites

18 July 2023
Threat actors are actively exploiting a recently disclosed critical security flaw in the WooCommerce Payments WordPress plugin as part of a massive targeted campaign. The flaw, tracked as CVE-2023-28121 (CVSS score: 9.8), is a case of authentication bypass that enables unauthenticated attackers to impersonate arbitrary users and perform some actions as the impersonated user, including an

JumpCloud Blames 'Sophisticated Nation-State' Actor for Security Breach

17 July 2023
A little over a week after JumpCloud reset API keys of customers impacted by a security incident, the company said the intrusion was the work of a sophisticated nation-state actor. The adversary "gained unauthorized access to our systems to target a small and specific set of our customers," Bob Phan, chief information security officer (CISO) at JumpCloud, said in a post-mortem report. "The

Digital maturity is a growing factor in cybersecurity practices

17 July 2023
A report finds that the U.S. security landscape changed significantly in 2022, with breaches declining in number but increasing in size.

Hackers Exploit WebAPK to Deceive Android Users into Installing Malicious Apps

17 July 2023
Threat actors are taking advantage of Android's WebAPK technology to trick unsuspecting users into installing malicious web apps on Android phones that are designed to capture sensitive personal information.

Update: JumpCloud Discloses Breach by State-Backed APT Hacking Group

17 July 2023
US-based enterprise software firm JumpCloud says a state-backed hacking group breached its systems almost one month ago as part of a highly targeted attack focused on a limited set of customers.

Accreditation Commission for Education in Nursing reveals data breach

17 July 2023
The Accreditation Commission for Education in Nursing announced they were contacted by an unknown user claiming to have accessed the computer network.

Meta’s Threads App Used as a Lure

17 July 2023
Researchers with Veriti are warning about “over 700 domains related to Threads being registered daily” in recent weeks, offering an Android version of the app for download outside of Google’s official app store.

Exploitation of ColdFusion Vulnerability Reported as Adobe Patches Another Critical Flaw

17 July 2023
Tracked as CVE-2023-38203 (CVSS score of 9.8), the flaw is described as “deserialization of untrusted data” in ColdFusion versions 2023, 2021, and?2018. This allows an attacker to use specially crafted data to trigger the execution of arbitrary code.

Healthcare organizations hesitant to adopt new software patches

17 July 2023
Healthcare cybersecurity risks were analyzed in a report by Trustwave following the healthcare industry facing a number of recent cyberattacks.

Applications open for SIA 2023 Women in Security Forum scholarship

17 July 2023
The Security Industry Association is accepting applications for the 2023 SIA Women in Security Forum Scholarship, an initiative led by the SIA Women in Security Forum.

Update: Google Removes Swing VPN Android App Exposed as DDoS Botnet

17 July 2023
The incident serves as a reminder that even seemingly legitimate apps can harbor dangerous intentions, highlighting the importance of staying informed and vigilant against cyber threats.