Latest Cybersecurity News and Articles


U.S. Government Agencies' Emails Compromised in China-Backed Cyber Attack

13 July 2023
An unnamed Federal Civilian Executive Branch (FCEB) agency in the U.S. detected anomalous email activity in mid-June 2023, leading to Microsoft's discovery of a new China-linked espionage campaign targeting two dozen organizations. The details come from a joint cybersecurity advisory released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation

New Vulnerabilities Disclosed in SonicWall and Fortinet Network Security Products

13 July 2023
SonicWall on Wednesday urged customers of Global Management System (GMS) firewall management and Analytics network reporting engine software to apply the latest fixes to secure against a set of 15 security flaws that could be exploited by a threat actor to circumvent authentication and access sensitive information. Of the 15 shortcomings (tracked from CVE-2023-34123 through CVE-2023-34137), four

British Prosecutors Say Teen Lapsus$ Member Was Behind Hacks on Uber, Rockstar

12 July 2023
A British Crown Court on Tuesday lifted a reporting restriction, allowing the naming of teenager Arion Kurtaj who is accused of hacking Uber, Revolut, and video game developer Rockstar Games in a short period of time last September.

Staying ahead of the “professionals”: The service-oriented ransomware crime industry

12 July 2023
The total amount of ransom paid since 2020 is estimated to be at least $2 billion, and this has both motivated and enabled the groups who are profiting from this activity to become more professional.

Python-Based PyLoose Fileless Attack Targets Cloud Workloads for Cryptocurrency Mining

12 July 2023
"The attack consists of Python code that loads an XMRig Miner directly into memory using memfd, a known Linux fileless technique," security researchers Avigayil Mechtinger, Oren Ofer, and Itamar Gilad said.

Small and home office router malware discovered by researchers

12 July 2023
A new malware that targets small and home office (SOHO) routers has been discovered by Lumen Technologies. The malware has been named "AVrecon".

Biden’s Cyber Command and NSA Nominee Seen as a Pick for Continuity

12 July 2023
At his first Senate confirmation hearing on Wednesday, Air Force Lt. Gen. Timothy Haugh, Cyber Command’s deputy chief, will explain how he plans to fill the shoes of Paul Nakasone.

Cl0p Crime Group Adds 62 Ernst & Young Clients to Leak Sites

12 July 2023
The growing list of MOVEit cyberattack victims has grown. Sixty-two clients of Big Four accounting firm Ernst & Young now appear on the Clop ransomware group's data leak sites.

Scam Page Volumes Surge 304% Annually

12 July 2023
In Group-IB’s new Digital Risk Trends 2023 report, security researchers have recorded a 62% year-on-year (YoY) increase in phishing websites and a 304% surge in scam pages in 2022.

54% of organizations struggle with shadow IT

12 July 2023
IT and security leaders were surveyed on malware readiness. The report found that security leaders are concerned about malware compromising data.  

Fortinet Patches Critical FortiOS Vulnerability Leading to Remote Code Execution

12 July 2023
The vulnerability impacts FortiOS and FortiProxy versions 7.2.x and 7.0.x and was resolved in FortiOS versions 7.4.0, 7.2.4, and 7.0.11, and FortiProxy versions 7.2.3 and 7.0.10.

DDoS Attacks Soar by 168% on Government Services, Report Warns

12 July 2023
According to StormWall’s Q2 2023 Report, the United States, India, and China remain the most heavily targeted countries, bearing the brunt of the escalating DDoS attacks.

AMA: CISO Edition — Diego Souza

12 July 2023
Diego Souza, Global Chief Information Security Officer (CISO) at Cummins, Inc., shares cybersecurity tactics and career advice in this AMA episode.

Report: Edge computing in healthcare is taking off

12 July 2023
In a new report, focused on the healthcare industry, found the primary use case was tele-emergency medical services.

SAP Patches Critical Vulnerability in ECC and S/4HANA Products

12 July 2023
German enterprise software maker SAP on Tuesday announced the release of 16 new security notes as part of its July 2023 Security Patch Day. In addition, updates were announced for two previously released notes.

Pro-Chinese Twitter Accounts Seek to Expand Beijing’s Influence in Latin America

12 July 2023
Three Twitter accounts that appear to have links to the Chinese government have been spreading propaganda in Latin America and successfully avoided Twitter's efforts to label state media, researchers said in an analysis published Tuesday.

Update: Bangladesh Government Fixes Website That Leaked Personal Data of 50 Million Citizens

12 July 2023
The information and technology minister of Bangladesh, Zunaid Ahmed, told local media that the data was exposed due to security weaknesses of a website, not a cyberattack.

Chinese Hackers Deploy Microsoft-Signed Rootkit to Target Gaming Sector

12 July 2023
Trend Micro has attributed the new activity cluster to the same threat actor that was previously identified as behind the FiveSys rootkit, which came to light in October 2021.

SaaS Application Security Firm Savvy Exits Stealth Mode With $30 Million in Funding

12 July 2023
The funds were raised in two investment rounds: $10 million in seed funding in 2021, and $20 million in a Series A funding round led by Canaan, with participation from previous investors Cyberstarts and Lightspeed.

Ransomware Extortion Skyrockets in 2023, Reaching $449.1 Million and Counting

12 July 2023
Ransomware has emerged as the only cryptocurrency-based crime to grow in 2023, with cybercriminals extorting nearly $175.8 million more than they did a year ago, according to findings from Chainalysis. "Ransomware attackers are on pace for their second-biggest year ever, having extorted at least $449.1 million through June," the blockchain analytics firm said in a midyear crypto crime report