Latest Cybersecurity News and Articles


Python-Based PyLoose Fileless Attack Targets Cloud Workloads for Cryptocurrency Mining

12 July 2023
A new fileless attack dubbed PyLoose has been observed striking cloud workloads with the goal of delivering a cryptocurrency miner, new findings from Wiz reveal. "The attack consists of Python code that loads an XMRig Miner directly into memory using memfd, a known Linux fileless technique," security researchers Avigayil Mechtinger, Oren Ofer, and Itamar Gilad said. "This is the first publicly

Update: Apple’s Rapid Security Response Patches Causing Website Access Issues

12 July 2023
Apple has pulled its latest Rapid Security Response updates for iOS and macOS after users complained that they were getting errors when accessing some websites through Safari.

Microsoft Releases Patches for 130 Vulnerabilities, Including 6 Under Active Attack

12 July 2023
Microsoft on Tuesday released updates to address a total of 130 new security flaws spanning its software, including six zero-day flaws that it said have been actively exploited in the wild. Of the 130 vulnerabilities, nine are rated Critical and 121 are rated Important in severity. This is in addition to eight flaws the tech giant patched in its Chromium-based Edge browser towards the end of

Apple & Microsoft Patch Tuesday, July 2023 Edition

11 July 2023
Microsoft Corp. today released software updates to quash 130 security bugs in its Windows operating systems and related software, including at least five flaws that are already seeing active exploitation. Meanwhile, Apple customers have their own zero-day woes again this month: On Monday, Apple issued (and then quickly pulled) an emergency update to fix a zero-day vulnerability that is being exploited on MacOS and iOS devices.

New TOITOIN Trojan Targets LATAM

11 July 2023
Businesses in the Latin American region are facing a new threat from a sophisticated malicious campaign distributing the TOITOIN trojan. Moreover, the campaign uses Amazon EC2 instances to evade domain-based detections. It is crucial for organizations to maintain a high level of vigilance against evolving malware campaigns.

Maneet Singh hired as Chief Information Officer at Odyssey

11 July 2023
Maneet Singh has been hired as Chief Information Officer at Odyssey Logistics & Technology Corporation. Singh comes with over 20 years of experience.

Purr-fectly Crafted for Macs: Charming Kitten Introduces NokNok Malware

11 July 2023
Security researchers uncovered a new campaign by Charming Kitten (APT42) targeting Windows and macOS systems using different malware payloads. A new type of malware called NokNok, is specifically used for targeting macOS systems. For Windows, adversaries leverage PowerShell code and an LNK file to drop the GorjolEcho backdoor from a cloud hosting provider. 

Owncast, EaseProbe Security Vulnerabilities Revealed

11 July 2023
Oxeye has uncovered two critical security vulnerabilities and recommends immediate action to mitigate risk. The vulnerabilities were discovered in Owncast (CVE-2023-3188) and EaseProbe (CVE-2023-33967), two open-source platforms written in Go.

Hackers Exploit Windows Policy Loophole to Forge Kernel-Mode Driver Signatures

11 July 2023
A Microsoft Windows policy loophole has been observed being exploited primarily by native Chinese-speaking threat actors to forge signatures on kernel-mode drivers. "Actors are leveraging multiple open-source tools that alter the signing date of kernel mode drivers to load malicious and unverified drivers signed with expired certificates," Cisco Talos said in an exhaustive two-part report shared

HCA Healthcare Reports Breach of 11 Million Patients’ Personal Data

11 July 2023
In a website notice, HCA confirmed that the data includes “information used for email messages, such as reminders that patients may wish to schedule an appointment and education on healthcare programs and services.”

Six Malicious Python Packages in the PyPI Targeting Windows Users

11 July 2023
The attackers imitated the W4SP attack group by using custom entry points and leveraging free file hosting services to remain undetected during the installation or execution process.

Australian Infrastructure Company Ventia Hit With Cyberattack

11 July 2023
The Australian infrastructure services provider Ventia is dealing with a cyberattack that began this weekend. On Saturday, the company said it identified a cyber intrusion and took some “key systems” offline to contain the incident.

SCARLETEEL Campaign Exploiting AWS Fargate in Ongoing Cryptojacking Attacks

11 July 2023
Cloud environments continue to be at the receiving end of an ongoing advanced attack campaign dubbed SCARLETEEL, with the threat actors now setting their sights on Amazon Web Services (AWS) Fargate.

Cybercriminals Evolve Antidetect Tooling for Mobile OS-Based Fraud

11 July 2023
The tools cost between $700-$1000 and are currently designed for Android-based devices. The authors behind both tools recommend using OnePlus devices to deploy mobile anti-detect or may ship ready-to-use devices with pre-configured packages.

Staff and Patients at the UK's Barts Health NHS Trust Hit With Extortion Threat

11 July 2023
Staff at one of the UK's largest hospital groups have spent a nervous week wondering if private data, stolen from their employer's IT systems by a ransomware gang, is going to be splurged online after a deadline to prevent publication passed.

Trinidad and Tobago Facing Servie Outages After Cyberattack

11 July 2023
The island nation of over 1.4 million people announced on Friday that its Ministry of Digital Transformation discovered a cyberattack targeting the country’s Office of the Attorney General and Ministry of Legal Affairs (AGLA) in recent days.

Law firms under cyberattack

11 July 2023
In April 2023, Australian law firm HWL Ebsworth was hit by a cyberattack that possibly resulted in data of hundreds of its clients and dozens of government agencies being compromised. The attack was claimed by the Russian-linked Blackcat ransomware.

Gaming Firm Razer Probing Potential Hack After Data Offered for US$100,000 Worth of Crypto

11 July 2023
According to a Twitter post by threat intelligence platform FalconFeeds.io, a seller had advertised the sale of source codes, encryption keys, database and backend access logins for Razer and its products in a hackers’ forum on Saturday.

New disturbing ransomware trend threatens organizations

11 July 2023
Ransomware attacks increased by over 37% in 2023 compared to the previous year, with the average enterprise ransom payment exceeding $100,000, with a $5.3 million average demand, according to Zscaler.

Hackers Steal Over $20 Million by Exploiting Flaw in Revolut's Payment Systems

11 July 2023
The problem was first detected in late 2021. But before it could be closed, the report said organized criminal groups leveraged the loophole by "encouraging individuals to try to make expensive purchases that would go on to be declined."