Latest Cybersecurity News and Articles


35 Million Indonesians' Passport Data for Sale on Dark Web for $10K

10 July 2023
Indonesian security researcher Teguh Aprianto revealed on Twitter last week that a hacker had put up for sale Indonesian passport holders' details including their full names, birth dates, gender, passport numbers, and passport validity dates.

Midyear Health Data Breach Analysis: The Top Culprits

10 July 2023
The HHS HIPAA Breach Reporting Tool shows that 336 major health data breaches affected nearly 41.4 million individuals between January 1st and June 30th this year - nearly double the number affected during the same period last year.

ISACA joins ECSO to strengthen cybersecurity and digital skills in Europe

10 July 2023
ISACA is joining the European Cyber Security Organisation (ECSO). The membership will work to accelerate ECSO and ISACA’s shared commitment to advancing cybersecurity, fostering collaboration and driving digital trust across Europe.

New Phishing Attack Spoofs Microsoft 365 Authentication System

10 July 2023
According to researchers at Vade, the attack email includes a harmful HTML attachment with JavaScript code. This code is designed to gather the recipient’s email address and modify the page using data from a callback function’s variable.

More Than 42,000 Affected by Ransomware Attack on Pro Bono California Law Firm

10 July 2023
The Law Foundation of Silicon Valley notified regulators in California and Maine last week that the February ransomware attack on their offices resulted in the leak of Social Security numbers and other personal information.

New Mozilla Feature Blocks Risky Add-Ons on Specific Websites to Safeguard User Security

10 July 2023
Mozilla has announced that some add-ons may be blocked from running on certain sites as part of a new feature called Quarantined Domains. "We have introduced a new back-end feature to only allow some extensions monitored by Mozilla to run on specific websites for various reasons, including security concerns," the company said in its Release Notes for Firefox 115.0 released last week. The company

Germany Must be Able to Defend Itself, Warns New Cybersecurity Chief

10 July 2023
Germany’s new cybersecurity chief, Claudia Plattner, told journalists on Friday that the country needed to defend itself amidst a surge in attacks on hospitals, local government authorities and private sector businesses in the country.

New TOITOIN Banking Trojan Targeting Latin American Businesses

10 July 2023
Businesses operating in the Latin American (LATAM) region are the target of a new Windows-based banking trojan called TOITOIN since May 2023. "This sophisticated campaign employs a trojan that follows a multi-staged infection chain, utilizing specially crafted modules throughout each stage," Zscaler researchers Niraj Shivtarkar and Preet Kamal said in a report published last week. "These modules

New 'Letscall' Malware Employs Voice Traffic Routing to Target Victims in South Korea

10 July 2023
The "Letscall" group consists of Android developers, designers, frontend and backend developers, as well as call operators specializing in voice social engineering attacks.

Real Estate Firm Faces Three Lawsuits in Addiction Center Breach

10 July 2023
All the lawsuits were filed in the U.S. District Court for the Eastern District of Pennsylvania. They seek relief including monetary damages and an injunctive order compelling Onix to improve its security practices to prevent future incidents.

Global Retailers Must Keep an Eye on Their SaaS Stack

10 July 2023
Brick-and-mortar retailers and e-commerce sellers may be locked in a fierce battle for market share, but one area both can agree on is the need to secure their SaaS stack. From communications tools to order management and fulfillment systems, much of today's critical retail software lives in SaaS apps in the cloud. Securing those applications is crucial to ongoing operations, chain management,

Bangladesh Government Website Leaks Millions of Citizens' Personal Data

10 July 2023
Viktor Markopoulos, a researcher at Bitcrack Cyber Security, said he accidentally discovered the leak on June 27, and shortly after contacted the Bangladeshi e-Government CERT. He said the leak includes data of millions of Bangladeshi citizens.

How Kids Pay the Price for Ransomware Attacks on Education

10 July 2023
Ransomware attacks on educational institutions have increased significantly in recent years, with the Vice Society ransomware gang especially targeting the education sector in the United States and the United Kingdom.

Killnet as a Private Military Hacking Company? For Now, It’s Probably Just a Dream

10 July 2023
The Russian hacking group Killnet aims to transform into a private military hacking company that conducts cybercrime on behalf of the Russian state. The group plans to expand its capabilities and hire skilled hackers for more destructive attacks.

Only 5% of CISOs report to CEOs, survey finds

10 July 2023
CISOs predominantly report to CIOs and are less likely to report to CEOs now than in previous years, according to a Heidrick & Struggles survey. Despite a slight year-over-year decrease, over one-third of CISOs report directly to the CIO.

BreachForums replacement emerges as robust forum for criminal hackers to trade their spoils

10 July 2023
Even before the FBI seized domains related to BreachForums, the notorious online bazaar where cybercriminals bought and sold hacked or stolen data, a replacement marketplace was taking shape.

More Than $125 Million Taken From Crypto Platform Multichain

10 July 2023
“The team is not sure what happened and is currently investigating. It is recommended that all users suspend the use of Multichain services and revoke all contract approvals related to Multichain,” the crypto platform said in a statement.

Man Charged for Breaching the Discovery Bay Water Treatment Facility

10 July 2023
Rambler Gallo (53), a man from Tracy, California, has been charged with intentionally causing damage to a computer after he allegedly breached the network of the Discovery Bay Water Treatment Facility.

TOITOIN Trojan: A New Multi-Stage Attack Targeting LATAM

10 July 2023
The TOITOIN Trojan utilizes advanced techniques such as XOR decryption, system reboots, and process injection to evade detection and gather sensitive information from infected systems.

RomCom RAT Targeting NATO and Ukraine Support Groups

10 July 2023
The threat actors behind the RomCom RAT have been suspected of phishing attacks targeting the upcoming NATO Summit in Vilnius as well as an identified organization supporting Ukraine abroad. The findings come from the BlackBerry Threat Research and Intelligence team, which found two malicious documents submitted from a Hungarian IP address on July 4, 2023. RomCom, also tracked under the names