Latest Cybersecurity News and Articles


Hackers Target Pakistani Government, Bank, and Telecom Provider With China-Made Malware

17 July 2023
Cybersecurity firm Trend Micro identified three entities in Pakistan targeted by Shadowpad last year: an unnamed government agency, a state bank, and a telecommunications provider.

Global Data Breach Could Impact 70,000 Residents, Vendor Employees With Hillsborough County

17 July 2023
Hillsborough County said they've mailed notification letters to 70,636 people who are clients of Healthcare services and vendors of aging services who they know were impacted.

Hackers Exploit WebAPK to Deceive Android Users into Installing Malicious Apps

17 July 2023
Threat actors are taking advantage of Android's WebAPK technology to trick unsuspecting users into installing malicious web apps on Android phones that are designed to capture sensitive personal information. "The attack began with victims receiving SMS messages suggesting the need to update a mobile banking application," researchers from CSIRT KNF said in an analysis released last week. "The

Russia-Linked Gamaredon APT Starts Stealing Data From Victims Between 30 and 50 Minutes After the Initial Compromise

17 July 2023
The Russia-linked APT group employs spear-phishing emails and messages, such as on Telegram and Signal, to trick victims into opening malicious attachments. Gamaredon uses malware and PowerShell scripts for reconnaissance and executing commands.

New AVrecon Malware Infects 70,000 Linux Routers Across 20 Countries

17 July 2023
A stealthy Linux malware, dubbed AVrecon, was found targeting more than 70,000 Linux-based SOHO routers at least since May 2021. It reportedly hijacked these devices to form a botnet that could steal bandwidth and provide a hidden residential proxy service. A total of 15 second-stage control servers were discovered by security researchers. It has marked its presence in more than 20 countries.

New 'WormGPT' AI Tool Allows Cybercriminals to Launch Sophisticated Cyberattacks

17 July 2023
The fact that WormGPT operates without any ethical boundaries underscores the threat posed by generative AI, even permitting novice cybercriminals to launch attacks swiftly and at scale without having the technical wherewithal to do so.

Facebook and Microsoft Remain Prime Targets for Spoofing

17 July 2023
Facebook and Microsoft’s collective dominance as the most spoofed brands continued into H1 2023, with the former accounting for 18% of all phishing URLs and the latter accounting for 15%, according to Vade.

Thousands of Images on Docker Hub Leak Authentication Secrets, Private Keys

17 July 2023
Researchers at the RWTH Aachen University in Germany published a study revealing that tens of thousands of container images hosted on Docker Hub contain confidential secrets, exposing software, online platforms, and users to a massive attack surface.

These 6 Questions Will Help You Choose the Best Attack Surface Management Platform

17 July 2023
The hype around different security categories can make it difficult to discern features and capabilities from bias when researching new platforms. You want to advance your security measures, but what steps actually make sense for your business? For anyone ready to find an attack surface management (ASM) vendor, review these six questions before getting started to understand the key features to

Malicious USB Drives Targetinging Global Targets with SOGU and SNOWYDRIVE Malware

17 July 2023
Cyber attacks using infected USB infection drives as an initial access vector have witnessed a three-fold increase in the first half of 2023,  That's according to new findings from Mandiant, which detailed two such campaigns – SOGU and SNOWYDRIVE – targeting both public and private sector entities across the world. SOGU is the "most prevalent USB-based cyber espionage attack using USB flash

EPA Says Court Decision to Ban New Rule ‘Undercuts’ Cybersecurity Efforts

17 July 2023
The U.S. Environmental Protection Agency is criticizing a decision by a federal appellate court to place a temporary hold on a new rule that would add cybersecurity assessments to audits of public water systems.

Genesis Market Sold to Anonymous Buyer Despite FBI Disruption

17 July 2023
The criminal group behind the cyber fraud platform Genesis Market claimed on Thursday that it had been sold to an unidentified buyer a few months after U.S. authorities sanctioned the platform and seized some of its domains.

Spotify Reportedly Makes Users’ Private Playlists Public

17 July 2023
In what is shaping up to be a widespread privacy controversy, Spotify has come under scrutiny following allegations by users that the music streaming service made their private playlists public without their consent.

Cybercriminals Exploit Microsoft Word Vulnerabilities to Deploy LokiBot Malware

17 July 2023
Microsoft Word documents exploiting known remote code execution flaws are being used as phishing lures to drop malware called LokiBot on compromised systems. "LokiBot, also known as Loki PWS, has been a well-known information-stealing Trojan active since 2015," Fortinet FortiGuard Labs researcher Cara Lin said. "It primarily targets Windows systems and aims to gather sensitive information from

Zluri Raises $20 Million for SaaS Management Platform

17 July 2023
Led by Lightspeed, the new round saw participation from existing investors Endiya Partners, Kalaari Capital, and MassMutual Ventures. Zluri helps organizations manage SaaS apps, mitigate security risks, and optimize costs, from a single dashboard.

Hackers Target Reddit Alternative Lemmy via Zero-Day Vulnerability

17 July 2023
A few days ago, an attacker leveraged a cross-site scripting (XSS) vulnerability to deface pages on some popular instances, including Lemmy.world, the most popular instance, which has over 100,000 users.

UK Financial Regulator Urges Banks to Tackle AI-Based Fraud

17 July 2023
Financial Conduct Authority (FCA) CEO, Nikhil Rathi, said in a speech delivered at the offices of The Economist this week, “We will remain super vigilant on how firms mitigate cyber-risks and fraud given the likelihood that these will rise.”

FCC Chair Proposes $200M Investment to Boost K-12 Cybersecurity

17 July 2023
The move follows urgent calls for the FCC to update its E-rate program to cover advanced firewalls and other network security measures. The pilot program is part of FCC Chairwoman Jessica Rosenworcel’s Learn Without Limits initiative.

White House Publishes Plan to Implement US National Cybersecurity Strategy

17 July 2023
The plan contains 69 initiatives focused on defending critical infrastructure, disrupting threat actors, shaping market forces, investing in resilience, and forging international partnerships.

TeamTNT's Cloud Credential Stealing Campaign Now Targets Azure and Google Cloud

17 July 2023
A malicious actor has been linked to a cloud credential stealing campaign in June 2023 that's focused on Azure and Google Cloud Platform (GCP) services, marking the adversary's expansion in targeting beyond Amazon Web Services (AWS).