Latest Cybersecurity News and Articles


New CVSS Version Unveiled Amid Rising Cyber Threats

14 July 2023
A new version of the Common Vulnerability Scoring System (CVSS 4.0) has been unveiled publicly by the Forum of Incident Response and Security Teams (FIRST) on July 13, 2023.

Services in North Carolina Town Unavailable After Ransomware Attack

14 July 2023
Residents of Cornelius, North Carolina, are dealing with delayed or unavailable services after a ransomware attack earlier this week. Officials said, on July 11, they discovered a cybersecurity incident later determined to be a ransomware attack.

Fake THREADS App Climbed to Number 1 Spot on Apple Store in Europe

14 July 2023
In a recent development, Apple has taken down a fake version of the popular Threads app from its App Store in Europe. The fake app, developed by SocialKit LTD, had been soaring up the charts of the most downloaded apps.

Shutterfly Says Cl0p Ransomware Attack Did Not Impact Customer Data

14 July 2023
This week, the Cl0p ransomware gang published Shutterfly's name on its data leak site, among other companies it has targeted, largely via the MOVEit SQL Injection vulnerability, tracked as CVE-2023-34362.

Cisco Shopping Spree Adds Oort ID Threat Detection Tech

14 July 2023
Cisco’s cybersecurity shopping spree hit another gear Thursday with the planned acquisition of Oort, an early-stage startup selling software in the Identity Threat Detection and Response (ITDR) category.

Malicious Campaigns Target Government, Military and Civilian Entities in Ukraine, Poland

14 July 2023
Ukraine’s Computer Emergency Response Team (CERT-UA) has attributed the July campaign to the threat actor group UNC1151, as a part of the GhostWriter operational activities allegedly linked to the Belarusian government.

Defend Against Insider Threats: Join this Webinar on SaaS Security Posture Management

14 July 2023
As security practices continue to evolve, one primary concern persists in the minds of security professionals—the risk of employees unintentionally or deliberately exposing vital information. Insider threats, whether originating from deliberate actions or accidental incidents, pose a significant challenge to safeguarding sensitive data. To effectively address insider risks, organizations must

AIOS WordPress Plugin Faces Backlash for Storing User Passwords in Plain Text

14 July 2023
All-In-One Security (AIOS), a WordPress plugin installed on over one million sites, has issued a security update after a bug introduced in version 5.1.9 of the software caused users' passwords being added to the database in plaintext format. "A malicious site administrator (i.e. a user already logged into the site as an admin) could then have read them," UpdraftPlus, the maintainers of AIOS, 

Zimbra Urges Customers to Manually Fix Actively Exploited Zero-Day Reported by Google TAG

14 July 2023
“A security vulnerability in Zimbra Collaboration Suite Version 8.8.15 that could potentially impact the confidentiality and integrity of your data has surfaced,” reads the advisory published by the company.

USB Drive Malware Attacks Spiking Again in First Half of 2023

14 July 2023
Mandiant outlined how two USB malware campaigns have been observed this year; one named 'Sogu,' attributed to a Chinese espionage threat group 'TEMP.HEX,' and another named 'Snowydrive,' attributed to UNC4698, which targets Asian oil and gas firms.

TeamTNT's Cloud Credential Stealing Campaign Now Targets Azure and Google Cloud

14 July 2023
A malicious actor has been linked to a cloud credential stealing campaign in June 2023 that's focused on Azure and Google Cloud Platform (GCP) services, marking the adversary's expansion in targeting beyond Amazon Web Services (AWS). The findings come from SentinelOne and Permiso, which said the "campaigns share similarity with tools attributed to the notorious TeamTNT cryptojacking crew,"

Crit.IX: Flaws in Honeywell Experion DCS, Posing Risk to Critical Industries

14 July 2023
Reportedly, Armis detected these flaws in May 2022 and informed Honeywell about 13 code issues found in the Experion C300 controllers and server, which were later rolled into nine new vulnerabilities.

Fewer Than 100 Scammers Responsible For Global Email Extortion

14 July 2023
Barracuda Networks teamed up with Columbia University to analyze over 300,000 extortion emails tracked by the firm over a one-year period. They looked specifically at the Bitcoin addresses used by the scammers in order to discern specific trends.

Citrix Fixes Critical Flaw in Secure Access Client for Ubuntu

14 July 2023
Citrix addressed a critical vulnerability, tracked as CVE-2023-24492 (CVSS score of 9.6), affecting the Secure Access client for Ubuntu that could be exploited to achieve remote code execution.

NATO Allies’ New Cyber Pledges To Remain Classified — But Here’s What We Know

14 July 2023
During this week’s NATO summit in Vilnius, Lithuania, allies agreed to a number of new cybersecurity pledges. The substance of these commitments has not been detailed — the documents themselves are classified — but here’s what we do know.

Lokibot Exploits Word Document Vulnerabilities to Propagate

14 July 2023
FortiGuard Labs claimed to have found several Office maldocs purposed to exploit known vulnerabilities, specifically CVE-2021-40444 and CVE-2022-30190 (Follina). Researchers noted that the version of Lokibot used in the campaign includes MD5 hash. This version of Lokibot info-stealer seems to have appeared first in March.

Fake PoC for Linux Kernel Vulnerability on GitHub Exposes Researchers to Malware

14 July 2023
In a sign that cybersecurity researchers continue to be under the radar of malicious actors, a proof-of-concept (PoC) has been discovered on GitHub, concealing a backdoor with a "crafty" persistence method.

New SOHO Router Botnet AVrecon Spreads to 70,000 Devices Across 20 Countries

14 July 2023
A new malware strain has been found covertly targeting small office/home office (SOHO) routers for more than two years, infiltrating over 70,000 devices and creating a botnet with 40,000 nodes spanning 20 countries. Lumen Black Lotus Labs has dubbed the malware AVrecon, making it the third such strain to focus on SOHO routers after ZuoRAT and HiatusRAT over the past year. "This makes AVrecon one

Zimbra Warns of Critical Zero-Day Flaw in Email Software Amid Active Exploitation

14 July 2023
Zimbra has warned of a critical zero-day security flaw in its email software that has come under active exploitation in the wild. "A security vulnerability in Zimbra Collaboration Suite Version 8.8.15 that could potentially impact the confidentiality and integrity of your data has surfaced," the company said in an advisory. It also said that the issue has been addressed and that it's expected to

Scam Page Volumes Witness a 304% Annual Surge, Finds Group-IB

14 July 2023
Security researchers published its Digital Risk Trends 2023 report and noted a significant rise in phishing websites, with a 62% year-on-year growth, and a surge of 304% in scam pages. Scammers exhibited a particular interest in brands from the APAC and MEA regions. Organizations must implement robust security measures and foster a proactive cybersecurity culture among employees.