Latest Cybersecurity News and Articles


ChatGPT’s unknown potential keeps us guessing

07 July 2023
A survey by Malwarebytes revealed that a majority of respondents do not trust the information produced by ChatGPT and believe it poses potential safety and security risks.

Two Apps with 1.5M Installations on Google Play Found Sending User Data to China

07 July 2023
The apps, both from the same publisher, can launch without any user interaction to steal sensitive data and send it to servers in China. Despite being reported to Google, the two apps continue to be available in Google Play at the time of publishing.

Mastodon Social Network Patches Critical Flaws Allowing Server Takeover

07 July 2023
Mastodon, a popular decentralized social network, has released a security update to fix critical vulnerabilities that could expose millions of users to potential attacks. Mastodon is known for its federated model, consisting of thousands of separate servers called "instances," and it has over 14 million users across more than 20,000 instances. The most critical vulnerability, CVE-2023-36460,

CISA, FBI, MS-ISAC, and CCCS Warn of Truebot Infecting US and Canadian Organizations

07 July 2023
The threat actors behind the attacks compromised target networks by exploiting a critical remote code execution (RCE) vulnerability in the Netwrix Auditor software tracked as CVE-2022-31199.

13% of businesses continuously monitor third-party vendor security risks

07 July 2023
A new report shows that 13% of organizations continuously monitor the security risks of their third parties.

85% of organizations are adopting multicloud strategies

07 July 2023
A report reveals a large multicloud skills gap, underscoring how critical cloud skills development is for organizations.

How to cultivate a culture of continuous cybersecurity improvement

07 July 2023
Building a culture of continuous cyber improvement involves implementing a robust real-time vulnerability management strategy that includes consistent monitoring, threat intelligence integration, risk assessment, and rapid response.

New Silentbob Campaign Deploys Tsunami Backdoor and Hijacks Cloud Resources

07 July 2023
Cybersecurity researchers at Aqua unearthed an attack infrastructure that's being used as part of a "potentially massive campaign" against cloud-native environments to deploy Tsunami malware, and hijack credentials and resources.

Chinese Affiliated Spyware Uncovered on Google Play Store

07 July 2023
Security analysts at Mobile security solutions provider Pradeo uncovered details of a couple of spyware apps on the Google Play Store - File Recovery and Data Recovery and File Manager. With a collective download of over 1.5 million, these apps can automatically start without any input from the device owners and covertly send sensitive user data to multiple malicious servers in China.

Ransomware accounts for 54% of cyber threats in the health sector

07 July 2023
A report by ENISA found that ransomware accounts for 54% of cybersecurity threats in the health sector. Most of the surveyed organizations (73%) in the health sector haven’t got a program to mitigate ransomware attacks.

Update: Shell Confirms MOVEit-Related Breach After Ransomware Group Leaks Data

07 July 2023
“Some personal information relating to employees of the BG Group has been accessed without authorization,” the company said. It’s unclear exactly what type of information has been compromised, but impacted individuals are being notified.

Close Security Gaps with Continuous Threat Exposure Management

07 July 2023
CISOs, security leaders, and SOC teams often struggle with limited visibility into all connections made to their company-owned assets and networks. They are hindered by a lack of open-source intelligence and powerful technology required for proactive, continuous, and effective discovery and protection of their systems, data, and assets. As advanced threat actors constantly search for easily

BlackByte 2.0 Ransomware: Infiltrate, Encrypt, and Extort in Just 5 Days

07 July 2023
Ransomware attacks are a major problem for organizations everywhere, and the severity of this problem continues to intensify. Recently, Microsoft's Incident Response team investigated the BlackByte 2.0 ransomware attacks and exposed these cyber strikes' terrifying velocity and damaging nature. The findings indicate that hackers can complete the entire attack process, from gaining initial access

JumpCloud Resets API Keys Amid Ongoing Cybersecurity Incident

07 July 2023
JumpCloud, a provider of cloud-based identity and access management solutions, has swiftly reacted to an ongoing cybersecurity incident that impacted some of its clients.

Potential 500GB Nickelodeon Data Leak: Unreleased Shows and Scripts at Risk

07 July 2023
According to several internet forums and tweets, approximately 500GB of data, including unreleased television shows, scripts, and other materials, have been compromised from Nickelodeon’s “consumer products and experience” portal.

What’s up with Emotet?

07 July 2023
Emotet operators subsequently have put a lot of effort into avoiding any monitoring and tracking of the botnet since it came back. Currently, Emotet is silent and inactive, most probably due to failing to find an effective, new attack vector.

Update: MOVEit vulnerability snags almost 200 victims, more expected

07 July 2023
Despite the number of victims so far, experts anticipate more will come forward. “While many organizations have made a disclosure, a significant number have yet to do so,” Brett Callow, threat analyst at Emsisoft, said.

Google Releases Android Patch Update for 3 Actively Exploited Vulnerabilities

07 July 2023
Google has released its monthly security updates for the Android operating system, addressing 46 new software vulnerabilities. Among these, three vulnerabilities have been identified as actively exploited in targeted attacks. One of the vulnerabilities tracked as CVE-2023-26083 is a memory leak flaw affecting the Arm Mali GPU driver for Bifrost, Avalon, and Valhall chips. This particular

JumpCloud Resets API Keys Amid Ongoing Cybersecurity Incident

07 July 2023
JumpCloud, a provider of cloud-based identity and access management solutions, has swiftly reacted to an ongoing cybersecurity incident that impacted some of its clients. As part of its damage control efforts, JumpCloud has reset the application programming interface (API) keys of all customers affected by this event, aiming to protect their valuable data. The company has informed the concerned

Cybersecurity Agencies Sound Alarm on Rising TrueBot Malware Attacks

07 July 2023
Cybersecurity agencies have warned about the emergence of new variants of the TrueBot malware. This enhanced threat is now targeting companies in the U.S. and Canada with the intention of extracting confidential data from infiltrated systems. These sophisticated attacks exploit a critical vulnerability (CVE-2022-31199) in the widely used Netwrix Auditor server and its associated agents. This