Latest Cybersecurity News and Articles


Protecting the Cloud

14 July 2023
One of the technologies that has been instrumental in facilitating smart buildings has been the emergence of “the cloud.”

HWL Ebsworth hack: sensitive Victorian government documents released by criminals

13 July 2023
HWL Ebsworth hack: sensitive Victorian government documents released by criminals State’s chief information security officer says information from Victorian departments and agencies was accessedFollow our Australia news live blog for the latest updatesGet our morning and afternoon news emails, free app or daily news podcastHighly sensitive legal documents from the Victorian government’s departments and agencies have been published on the dark web by cybercriminals.The breach is connected to data that was stolen from the law firm HWL Ebsworth in April by a Russian-linked ransomware gang and posted online.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...

SEO Expert Hired and Fired By Ashley Madison Turned on Company, Promising Revenge

13 July 2023
[This is Part II of a story published here last week on reporting that went into a new Hulu documentary series on the 2015 Ashley Madison hack.] It was around 9 p.m. on Sunday, July 19, when I received a message through the contact form on KrebsOnSecurity.com that the marital infidelity website AshleyMadison.com had been hacked. The message contained links to confidential Ashley Madison documents, and included a manifesto that said a hacker group calling itself the Impact Team was prepared to leak data on all 37 million users unless Ashley Madison and a sister property voluntarily closed down within 30 days.

Critical RCE found in popular Ghostscript open-source PDF library

13 July 2023
The flaw is tracked as CVE-2023-36664, having a CVSS v3 rating of 9.8, and impacts all versions of Ghostscript before 10.01.2, which is the latest available version released three weeks ago.

Juniper Networks Patches High-Severity Vulnerabilities in Junos OS

13 July 2023
The company published 17 advisories detailing roughly a dozen Junos OS-specific security defects, and nearly three times as many issues in third-party components used in its products.

Tampa Bay Zoo Targeted in Cyberattack by Apparent Offshoot of Royal Ransomware

13 July 2023
One of the U.S.’s most popular zoos has been hit with a cyberattack involving the theft of employee and vendor information, and a likely offshoot of the Royal ransomware gang is taking credit.

Criminals Target Businesses With Malicious Extension for Meta’s Ads Manager and Accidentally Leak Stolen Accounts

13 July 2023
The Vietnamese threat actors are using malicious Chrome extensions to steal Facebook account credentials, with over 800 victims worldwide and $180K in compromised ad budget.

Ransomware Crypto Payments Poised to Set New Record in 2023

13 July 2023
While overall crypto proceeds, including from crimes such as scams, fell dramatically over the past year, ransomware funds are expected to hit $899 million in 2023, according to Chainalysis.

APT Exploit Targeting Rockwell Automation Flaws Threatens Critical Infrastructure

13 July 2023
The 1756 EN2 and 1756 EN3 products are impacted by CVE-2023-3595, a critical flaw that can allow attackers to achieve remote code execution with persistence on targeted systems by using specially crafted Common Industrial Protocol (CIP) messages.

12% of organizations experienced a breach while using new solutions

13 July 2023
According to a survey of RSA and InfoSec attendants, 63% of the 219 respondents now use cloud-native security tools to monitor and protect data.

PicassoLoader Malware Used in Ongoing Attacks on Ukraine and Poland

13 July 2023
Government entities, military organizations, and civilian users in Ukraine and Poland have been targeted as part of a series of campaigns designed to steal sensitive data and gain persistent remote access to the infected systems. The intrusion set, which stretches from April 2022 to July 2023, leverages phishing lures and decoy documents to deploy a downloader malware called PicassoLoader, which

TeamTNT's Silentbob Botnet Infecting 196 Hosts in Cloud Attack Campaign

13 July 2023
As many as 196 hosts have been infected as part of an aggressive cloud campaign mounted by the TeamTNT group called Silentbob. "The botnet run by TeamTNT has set its sights on Docker and Kubernetes environments, Redis servers, Postgres databases, Hadoop clusters, Tomcat and Nginx servers, Weave Scope, SSH, and Jupyter applications," Aqua security researchers Ofek Itach and Assaf Morag said in a

Software supply chain compromise was fourth most frequent attack

13 July 2023
A recent security threats and trends survey measured responses of senior cybersecurity leaders, CISOs, CIOs, VPs, directors and IT managers.

Unpatched Office Zero-Day CVE-2023-36884 Actively Exploited in Targeted Attacks

13 July 2023
“An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim," reads the advisory published by Microsoft.

Only 45% of Cloud Data is Currently Encrypted

13 July 2023
About 39% of businesses experienced a data breach in their cloud environment last year, an increase from the 35% reported in 2022, according to Thales. Human error was reported as the leading cause of cloud data breaches by 55% of those surveyed.

New Attack Drops LokiBot Malware via Malicious Macros in Word Documents

13 July 2023
FortiGuard Labs recently uncovered a concerning discovery in their investigation, revealing a series of malicious Microsoft Office documents designed to take advantage of well-known vulnerabilities.

White House announces cybersecurity implementation plan

13 July 2023
The White House has released a cybersecurity plan that outlines over 60 federal initiatives including cybercrime and building a cyber workforce. 

Silk Road Drug Market’s ‘Mentor’ Sentenced to 20 Years in Prison

13 July 2023
During its operation from 2011 until 2013, Silk Road was used by thousands of drug dealers to distribute narcotics and other illicit goods and services to more than 100,000 buyers and to launder hundreds of millions from those unlawful transactions.

Diplomats in Ukraine Hit by Staggering BMW Phishing Campaign From APT29

13 July 2023
A notorious Russian state-affiliated cyber gang has leveraged a legitimate sale of a BMW car to target diplomats in Kyiv, Ukraine, a new analysis by Palo Alto Network’s Unit 42 researchers has observed.

Infrastructure upgrades alone won’t guarantee strong security

13 July 2023
While 75% of organizations have made significant strides to upgrade their infrastructure in the past year, and 78% have increased their security budgets, only 2% of industry experts are confident in their security strategies, according to OPSWAT.