Latest Cybersecurity News and Articles


Hackers Steal $20 Million by Exploiting Flaw in Revolut's Payment Systems

10 July 2023
Malicious actors exploited an unknown flaw in Revolut's payment systems to steal more than $20 million of the company's funds in early 2022. The development was reported by the Financial Times, citing multiple unnamed sources with knowledge of the incident. The breach has not been disclosed publicly. The fault stemmed from discrepancies between Revolut's U.S. and European systems, causing funds

New Campaigns Use Malicious npm Packages to Support Phishing Kits

08 July 2023
These packages imitated legitimate modules, such as jquery, which has millions of weekly downloads. Although the malicious packages were downloaded roughly 1000 times, they were swiftly removed from npm after detection.

Tailing Big Head Ransomware’s Variants, Tactics, and Impact

08 July 2023
The Big Head ransomware displays a fake Windows update to deceive victims, communicates with the threat actor via a Telegram bot, and drops ransom notes with contact information.

CISA warns govt agencies to patch actively exploited Android driver

08 July 2023
CISA ordered federal agencies today to patch a high-severity Arm Mali GPU kernel driver privilege escalation flaw added to its list of actively exploited vulnerabilities and addressed with this month's Android security updates.

Two Spyware Apps on Google Play with 1.5 Million Users Sending Data to China

08 July 2023
Two file management apps on the Google Play Store have been discovered to be spyware, putting the privacy and security of up to 1.5 million Android users at risk. These apps engage in deceptive behaviour and secretly send sensitive user data to malicious servers in China. Pradeo, a leading mobile security company, has uncovered this alarming infiltration. The report shows that both spyware apps,

WISE REMOTE Stealer Unleashed : Unveiling Its Multifaceted Malicious Arsenal

08 July 2023
The WISE REMOTE Stealer is an advanced information stealer and Remote Access Trojan (RAT) that is coded in the Go programming language and utilizes code manipulation techniques to evade antivirus detection, making it difficult to detect and mitigate.

Global Translation Service Exposed Highly Sensitive Records Online

08 July 2023
Website Planet‘s security researcher Jeremiah Fowler discovered a non-password-protected database that contained over 25,000 records, all publicly exposed, including ‘highly sensitive’ documents.

Vulnerabilities in PiiGAB Product Could Expose Industrial Organizations to Attacks

08 July 2023
The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday published an advisory describing the vulnerabilities discovered by researchers at Radboud University in PiiGAB M-Bus 900s gateway/converter.

Top Suspect in 2015 Ashley Madison Hack Committed Suicide in 2014

07 July 2023
When the marital infidelity website AshleyMadison.com learned in July 2015 that hackers were threatening to publish data stolen from 37 million users, the company’s then-CEO Noel Biderman was quick to point the finger at an unnamed former contractor. But as a new documentary series on Hulu reveals [SPOILER ALERT!], there was just one problem with that theory: Their top suspect had killed himself more than a year before the hackers began publishing stolen user data.

Cybersecurity is top concern for education technology leaders

07 July 2023
A recent report by the Consortium for School Networking (CoSN) analyzed the cybersecurity priorities of education technology (EdTech) leaders. 

Vishing Goes High-Tech: New 'Letscall' Malware Employs Voice Traffic Routing

07 July 2023
Researchers have issued a warning about an emerging and advanced form of voice phishing (vishing) known as "Letscall." This technique is currently targeting individuals in South Korea. The criminals behind "Letscall" employ a multi-step attack to deceive victims into downloading malicious apps from a counterfeit Google Play Store website. Once the malicious software is installed, it redirects

TMF announces five new digital services and cybersecurity investments

07 July 2023
The Labor Department will use the $15.2 million in the most recent batch of funding for zero-trust architecture. The EPA will put its $2.5 million toward the cybersecurity of its analytical radiation data system.

Mastodon Social Network Patches Critical Flaws Allowing Server Takeover

07 July 2023
The most critical vulnerability, CVE-2023-36460, allows hackers to exploit a flaw in the media attachments feature, creating and overwriting files in any location the software could access on an instance.

MOVEit Transfer customers warned to patch new critical flaw

07 July 2023
“An attacker could submit a crafted payload to a MOVEit Transfer application endpoint which could result in modification and disclosure of MOVEit database content,” an advisory by MOVEit said.

Lee Buttke hired as Managing Director and CISO at AgileBlue

07 July 2023
Lee Buttke has been hired as Managing Director and Chief Information Security Officer (CISO) at AgileBlue. Buttke brings threat mitigation experience.

BlackByte 2.0 Ransomware: Infiltrate, Encrypt, and Extort in Just 5 Days

07 July 2023
Recently, Microsoft's Incident Response team investigated several BlackByte 2.0 ransomware attacks and exposed these cyber strikes' terrifying velocity and damaging nature.

Iranian Hackers' Sophisticated Malware Targets Windows and macOS Users

07 July 2023
"TA453 eventually used a variety of cloud hosting providers to deliver a novel infection chain that deploys the newly identified PowerShell backdoor GorjolEcho," Proofpoint said in a new report.

Another Critical Unauthenticated SQLi Flaw Discovered in MOVEit Transfer Software

07 July 2023
Progress Software has announced the discovery and patching of a critical SQL injection vulnerability in MOVEit Transfer, popular software used for secure file transfer. In addition, Progress Software has patched two other high-severity vulnerabilities. The identified SQL injection vulnerability, tagged as CVE-2023-36934, could potentially allow unauthenticated attackers to gain unauthorized

Cybercriminals can Break Voice Authentication with 99% Success Rate

07 July 2023
Computer scientists at the University of Waterloo have discovered a method of attack that can successfully bypass voice authentication security systems with up to a 99% success rate after only six tries.

Truebot's Activity Spikes, U.S and Canada Authorities Issue Warning

07 July 2023
A joint advisory from the CISA, the FBI, the MS-ISAC, and the Canadian Centre for Cyber Security (CCCS) discovered a rise in the use of the Truebot malware by threat actors. Notably, these actors are increasingly exploiting the CVE-2022-31199 flaw to target organizations in the U.S. and Canada with the malware. Organizations are also advised to use IOCs to hunt for signs of malicious activity pointing to a Truebot infection.