Latest Cybersecurity News and Articles


Poly Network Loses Millions of Dollars in Crypto Assets

05 July 2023
The services of the company were suspended early Sunday and during the afternoon the company shared a Google spreadsheet showing crypto assets that have been stolen by the attackers.

Japan’s Largest Port Halts Operations After Ransomware Attack

05 July 2023
All container loading and unloading operations at the terminals using trailers have been canceled, causing massive financial losses to the port and severe disruption to the circulation of goods to and from Japan.

Secrets, Secrets Are No Fun. Secrets, Secrets (Stored in Plain Text Files) Hurt Someone

05 July 2023
Secrets are meant to be hidden or, at the very least, only known to a specific and limited set of individuals (or systems). Otherwise, they aren't really secrets. In personal life, a secret revealed can damage relationships, lead to social stigma, or, at the very least, be embarrassing. In a developer's or application security engineer's professional life, the consequences of exposing secrets

Teen among suspects arrested in Android banking malware scheme

05 July 2023
Preliminary findings suggest that seven men, two women aged 19 to 27, and a 16-year-old facilitated the scam by providing their bank accounts, Internet banking credentials, and Singpass credentials to perpetrators for monetary gain.

75% of consumers prepared to ditch brands hit by ransomware

05 July 2023
81% of consumers report feeling “very scared or worried” about their data being held by organizations lacking robust resilience against ransomware. After an attack, one in three consumers demands evidence of resilient backup and recovery strategies.

Ghostscript Bug Could Allow Rogue Documents to Run System Commands

05 July 2023
Ghostscript reads in PostScript program code, which describes how to construct the pages in a document, and converts it, or renders it, into a format more suitable for displaying or printing, such as raw pixel data or a PNG graphics file.

Node.js Users Beware: Manifest Confusion Attack Opens Door to Malware

05 July 2023
The npm registry for the Node.js JavaScript runtime environment is susceptible to what's called a manifest confusion attack that could potentially allow threat actors to conceal malware in project dependencies or perform arbitrary script execution during installation. "A npm package's manifest is published independently from its tarball," Darcy Clarke, a former GitHub and npm engineering manager

Instagram's Twitter Alternative 'Threads' Launch Halted in Europe Over Privacy Concerns

05 July 2023
Instagram Threads, the upcoming Twitter competitor from Meta, will not be launched in the European Union due to privacy concerns, according to Ireland's Data Protection Commission (DPC). The development was reported by the Irish Independent, which said the watchdog has been in contact with the social media giant about the new product and confirmed the release won't extend to the E.U. "at this

HWL Ebsworth hack: Russian gang released ‘sensitive personal and government information’, Australian cybersecurity chief says

05 July 2023
HWL Ebsworth hack: Russian gang released ‘sensitive personal and government information’, Australian cybersecurity chief says National cybersecurity coordinator Darren Goldie says ransomware gang ALPHV/Blackcat is responsible for posting the material onlineGet our morning and afternoon news emails, free app or daily news podcastSensitive and personal government information has been stolen from law firm HWL Ebsworth by a Russian ransomware gang and posted online, Australia’s new cybersecurity chief says.The significant breach was confirmed by new national cybersecurity coordinator, Darren Goldie, who said he was still working with the law firm to understand how many Australians have been affected.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...

Swedish Data Protection Authority Warns Companies Against Google Analytics Use

04 July 2023
The Swedish data protection watchdog has warned companies against using Google Analytics due to risks posed by U.S. government surveillance, following similar moves by Austria, France, and Italy last year. The development comes in the aftermath of an audit initiated by the Swedish Authority for Privacy Protection (IMY) against four companies CDON, Coop, Dagens Industri, and Tele2. "In its audits

Manufacturing companies hit by ransomware had their data encrypted: Report

04 July 2023
the percentage of manufacturing organizations that used back backups to recover data has increased, with 73% of the manufacturing organizations surveyed using backups this year versus 58% in the previous year.

U.S. Law Firms Targeted in New GuLoader Campaign

04 July 2023
GuLoader is increasingly prevalent as a malware loader within phishing campaigns. Morphisec Labs uncovered a GuLoader campaign that has been targeting law firms (46.4%), alongside investment (17.9%) and healthcare (21.4%) firms, in the U.S. The campaign has been ongoing since April.

New Malware Alert: EarlyRAT Linked to North Korean Hacking Group

04 July 2023
EarlyRAT is a straightforward program that immediately starts gathering system data and sending it via a POST request to the C2 server. The execution of commands on the infected system is EarlyRAT’s second main purpose.

New Python Tool Checks NPM Packages for Manifest Confusion Issues

04 July 2023
A malicious actor could manipulate the manifest data of a new package, and potentially expose developers to risks such as cache poisoning, installation of unknown dependencies, execution of unknown scripts, and possibly even downgrade attacks.

DDoSia Attack Tool Evolves with Encryption, Targeting Multiple Sectors

04 July 2023
DDoSia is attributed to a pro-Russian hacker group called NoName(057)16. Launched in 2022 and a successor of the Bobik botnet, the attack tool is designed for staging distributed denial-of-service (DDoS) attacks against targets.

Microsoft Denies Major 30 Million Customer-Breach

04 July 2023
“At this time, our analysis of the data shows that this is not a legitimate claim and an aggregation of data. We have seen no evidence that our customer data has been accessed or compromised,” Microsoft noted.

Thirty-three US Hospitals Hit By Ransomware This Year

04 July 2023
According to Emsisoft data, at least 19 healthcare providers hit by ransomware attacks operate 33 hospitals and at least 16 of the 19 had data exfiltrated. Data exfiltration last year occurred in 68% of cases.

Major Data Leaks on TikTok, Instagram, and Yahoo

04 July 2023
A SOCRadar dark web analyst recently discovered an alleged database leak for Instagram. The leaked data reportedly contains over 17 million records in JSON format. The nature of the data suggests that it may have been collected from open source.

DDoSia Attack Tool Evolves with Encryption, Targeting Multiple Sectors

04 July 2023
The threat actors behind the DDoSia attack tool have come up with a new version that incorporates a new mechanism to retrieve the list of targets to be bombarded with junk HTTP requests in an attempt to bring them down. The updated variant, written in Golang, "implements an additional security mechanism to conceal the list of targets, which is transmitted from the [command-and-control] to the

Anonymous Sudan Claims to Have Stolen 30 Million Microsoft’s Customer Accounts

04 July 2023
Attackers said “We announce that we have successfully hacked Microsoft and have access to a large database containing more than 30 million Microsoft accounts, email and password. Price for full database : 50,000 USD.”