Latest Cybersecurity News and Articles


Researchers Uncover New Linux Kernel 'StackRot' Privilege Escalation Vulnerability

06 July 2023
Details have emerged about a newly identified security flaw in the Linux kernel that could allow a user to gain elevated privileges on a target host. Dubbed StackRot (CVE-2023-3269, CVSS score: 7.8), the flaw impacts Linux versions 6.1 through 6.4. There is no evidence that the shortcoming has been exploited in the wild to date. "As StackRot is a Linux kernel vulnerability found in the memory

How Pen Testing can Soften the Blow on Rising Costs of Cyber Insurance

06 July 2023
As technology advances and organizations become more reliant on data, the risks associated with data breaches and cyber-attacks also increase. The introduction of data privacy laws, such as the GDPR, has made it mandatory for organizations to disclose breaches of personal data to those affected. As such, it has become essential for businesses to protect themselves from the financial and

New StackRot Linux kernel flaw allows privilege escalation

06 July 2023
Technical information has emerged for a serious vulnerability affecting multiple Linux kernel versions. The security issue is referred to as StackRot (CVE-2023-3269) and can be used to compromise the kernel and elevate privileges.

Silentbob Campaign: Cloud-Native Environments Under Attack

06 July 2023
Cybersecurity researchers have unearthed an attack infrastructure that's being used as part of a "potentially massive campaign" against cloud-native environments. "This infrastructure is in early stages of testing and deployment, and is mainly consistent of an aggressive cloud worm, designed to deploy on exposed JupyterLab and Docker APIs in order to deploy Tsunami malware, cloud credentials

Update: Fort Worth officials say leaked data came from Public Information Act request

06 July 2023
“IT staff validated the source of the data is previously released data in response to a Public Information Act request. The underlying server, database and storage, again, was not compromised,” the city’s IT department said.

Exploited Solar Power Product Vulnerability Could Expose Energy Organizations to Attacks

06 July 2023
Hundreds of energy organizations could be exposed to attacks due to an actively exploited vulnerability affecting a solar power monitoring product made by Contec, vulnerability intelligence company VulnCheck warned on Wednesday.

Firefox 115 Patches High-Severity Use-After-Free Vulnerabilities

06 July 2023
Mozilla on Tuesday announced the release of Firefox 115 to the stable channel with patches for a dozen security vulnerabilities, including two high-severity use-after-free bugs.

Belarusian hacker group сlaim to breach country’s leading state university

06 July 2023
The university denied any cyberattack and attributed the system's downtime to technical issues. Officials also claimed that the photos and screenshots shared by the hackers were fake and photoshopped.

INTERPOL Nabs Hacking Crew OPERA1ER's Leader Behind $11 Million Cybercrime

06 July 2023
A suspected senior member of a French-speaking hacking crew known as OPERA1ER has been arrested as part of an international law enforcement operation codenamed Nervone, Interpol has announced. "The group is believed to have stolen an estimated USD 11 million -- potentially as much as 30 million -- in more than 30 attacks across 15 countries in Africa, Asia, and Latin America," the agency said.

Malicious ad for USPS fishes for banking credentials

06 July 2023
Users clicking on seemingly legitimate ads for postal package tracking can be redirected to malicious websites that collect sensitive data, such as credit card details and banking credentials.

Are You Human? The Rising Menace of Fake Pages on Google

06 July 2023
Cybercriminals have adopted a deceptive strategy by introducing fake "Are You Human" checks. The aim of this malicious scheme is to trick unsuspecting individuals into granting unnecessary permissions, thereby exploiting their trust and potentially gaining unauthorized access to sensitive information. These websites, furthermore, exploit the granted permissions to establish a backdoor into your browser.

Support from British businesses crucial in removing over 235,000 scams, new figures reveal

05 July 2023
The sixth annual report from Active Cyber Defence (ACD) highlights success of a “whole-of-society" approach in preventing millions of cyber attacks from reaching UK organisations and citizens each year.

iHealth Solutions settles HIPAA violation charges

05 July 2023
iHealth has settled with the Office for Civil Rights over potential Health Insurance Portability and Accountability Act (HIPAA) privacy violations.

CISA updates election security team

05 July 2023
Cait Conley, Senior Advisor to the Director, will take on additional responsibilities supporting CISA’s election security efforts.

39% of businesses faced a cloud environment data breach last year

05 July 2023
A recent cloud security study found that more than a third (39%) of businesses have experienced a data breach in their cloud environment last year.

Ransomware Redefined: RedEnergy Stealer-as-a-Ransomware

05 July 2023
RedEnergy stealer uses a fake update campaign to target multiple industry verticals and possesses the ability to steal information from various browsers while also incorporating different modules for carrying out ransomware activities.

Pepsi Bottling Ventures announces data breach

05 July 2023
Pepsi Bottling Ventures suffered a data breach in late 2022. The breach may have involved information of current and former employees.

RedEnergy Stealer-as-a-Ransomware Threat Targeting Energy and Telecom Sectors

05 July 2023
A sophisticated stealer-as-a-ransomware threat dubbed RedEnergy has been spotted in the wild targeting energy utilities, oil, gas, telecom, and machinery sectors in Brazil and the Philippines through their LinkedIn pages. The malware "possesses the ability to steal information from various browsers, enabling the exfiltration of sensitive data, while also incorporating different modules for

European Entities Targeted in SmugX Campaign

05 July 2023
Check Point spotted a new campaign by a Chinese threat actor targeting diplomatic entities in Europe. Dubbed SmugX, the campaign uses HTML smuggling to deploy a new variant of PlugX RAT. The campaign reportedly overlaps with the activity of RedDelta and Mustang Panda. Organizations are advised to use the IOCs associated with the campaign to understand the attack pattern and implement effective security measures.

Ransomware Criminals Are Dumping Kids’ Private Files Online After School Hacks

05 July 2023
Complete sexual assault case folios containing these details were among more than 300,000 files dumped online in March after the 36,000-student Minneapolis Public Schools refused to pay a $1 million ransom.