Latest Cybersecurity News and Articles


How to Apply MITRE ATT&CK to Your Organization

11 July 2023
Discover all the ways MITRE ATT&CK can help you defend your organization. Build your security strategy and policies by making the most of this important framework. What is the MITRE ATT&CK Framework? MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a widely adopted framework and knowledge base that outlines and categorizes the tactics, techniques, and procedures (TTPs)

Triada Malware Infects Android Devices via Fake Telegram App

11 July 2023
Check Point Software Technologies’ recent research highlights a concerning trend: a circulating fake Telegram messenger app that infects Android devices with Triada malware upon installation.

New Big Head Ransomware Propagates via Malvertising

11 July 2023
A newly discovered ransomware strain dubbed Big Head is spreading through malvertising, which involves the promotion of fake Windows updates and Microsoft Word installers, warned Trend Micro. Designed as a .NET binary, the ransomware deploys three AES-encrypted files on the targeted system: one for spreading the malware, another for facilitating communication with a Telegram bot, and the third for encrypting files.

Archive of Our Own Website Suffering Massive DDoS Attacks

11 July 2023
The popular fanfiction platform Archive of Our Own (AO3) is currently grappling with a wave of DDoS attacks. Since early Monday morning, the AO3 website has been experiencing intermittent periods of outage, leaving users frustrated.

SCARLETEEL Cryptojacking Campaign Exploiting AWS Fargate in Ongoing Campaign

11 July 2023
Cloud environments continue to be at the receiving end of an ongoing advanced attack campaign dubbed SCARLETEEL, with the threat actors now setting their sights on Amazon Web Services (AWS) Fargate. "Cloud environments are still their primary target, but the tools and techniques used have adapted to bypass new security measures, along with a more resilient and stealthy command and control

TPG to Buy Forcepoint’s Public Sector Cybersecurity Business for $2.45 Billion

11 July 2023
The sale, which is under a definitive agreement, is expected to close before the end of 2023. Forcepoint is separating out its Global Governments and Critical Infrastructure business, known as G2CI, in the sale to TPG, creating an independent entity.

Number of email-based phishing attacks surges 464%

11 July 2023
The evolving cyberattack landscape reveals the increasing utilization of generative AI systems, like ChatGPT, by cybercriminals for crafting malicious content and executing sophisticated attacks, according to Acronis.

Apple Issues Urgent Patch for Zero-Day Flaw Targeting iOS, iPadOS, macOS, and Safari

11 July 2023
The WebKit bug, cataloged as CVE-2023-37450, could allow threat actors to achieve arbitrary code execution when processing specially crafted web content. The iPhone maker said it addressed the issue with improved checks.

Beware of Big Head Ransomware: Spreading Through Fake Windows Updates

11 July 2023
A developing piece of ransomware called Big Head is being distributed as part of a malvertising campaign that takes the form of bogus Microsoft Windows updates and Word installers. Big Head was first documented by Fortinet FortiGuard Labs last month, when it discovered multiple variants of the ransomware that are designed to encrypt files on victims' machines in exchange for a cryptocurrency

EU Adopts More Robust Data Privacy Agreement With US

11 July 2023
Three years after a European court invalidated a transatlantic data transfer agreement, the EU now adopted a new agreement with the U.S. meant to better ensure privacy protections for data moving between American tech companies and users overseas.

VMware Warns of Exploit Available for Critical vRealize RCE Bug

11 July 2023
VMware warned customers today that exploit code is now available for a critical vulnerability in the VMware Aria Operations for Logs analysis tool, which helps admins manage terabytes worth of app and infrastructure logs in large-scale environments.

‘LetsCall’ Multi-Stage Vishing Attack Found Targeting Korean Android Users

11 July 2023
A cautionary alert has been issued by researchers regarding an advanced voice phishing (vishing) campaign referred to as "Letscall," presently targeting Android users in South Korea. The attackers pose as banking employees and use social engineering tactics to extract sensitive information from unsuspecting users.

Apple Issues Urgent Patch for Zero-Day Flaw Targeting iOS, iPadOS, macOS, and Safari

11 July 2023
Apple has released Rapid Security Response updates for iOS, iPadOS, macOS, and Safari web browser to address a zero-day flaw that it said has been actively exploited in the wild. The WebKit bug, cataloged as CVE-2023-37450, could allow threat actors to achieve arbitrary code execution when processing specially crafted web content. The iPhone maker said it addressed the issue with improved checks

Cyber Extortion Cases Surge 39% Annually

10 July 2023
Incidents of online extortion reported to the police increased by nearly two-fifths in 2022 compared to a year previously, according to law firm RPC. The findings, which cover the full year to December 2022, were sourced from the UK's Action Fraud.

RomCom RAT Targeting NATO and Ukraine Support Groups

10 July 2023
The threat actors behind the RomCom RAT have been suspected of phishing attacks targeting the upcoming NATO Summit in Vilnius as well as an identified organization supporting Ukraine abroad.

Central Bankers Develop Framework For Securing Digital Currencies

10 July 2023
An international financial institution owned by the world’s central banks has published a new framework designed to help members mitigate cyber risks associated with their digital currencies.

Genesis Market gang tries to sell platform after FBI disruption

10 July 2023
Unlike its competitors, Genesis Market did not just sell stolen data and credentials but also provided a platform to criminals that allowed them to weaponize that data using a custom browser extension to impersonate victims.

Cybersecurity researchers identify new ShadowVault malware

10 July 2023
A new malware has been identified by Guardz. The malware known as 'ShadowVault' is capable of stealing sensitive data from macOS-based devices.

PoC Exploit Published for Recent Ubiquiti EdgeRouter Vulnerability

10 July 2023
A recently patched vulnerability in Ubiquiti EdgeRouter and AirCube devices could be exploited to execute arbitrary code, vulnerability reporting firm SSD Secure Disclosure warns.

Honeywell Boosting OT Cybersecurity Offering With Acquisition of SCADAfence

10 July 2023
Honeywell has agreed to acquire SCADAfence for an undisclosed amount and plans on integrating its solutions into the company’s Forge Cybersecurity+ suite. The deal is expected to close in the second half of the year.