Latest Cybersecurity News and Articles


Mexico-Based Hacker Targets Global Banks with Android Malware

04 July 2023
An e-crime actor of Mexican provenance has been linked to an Android mobile malware campaign targeting financial institutions globally, but with a specific focus on Spanish and Chilean banks, from June 2021 to April 2023. The activity is being attributed to an actor codenamed Neo_Net, according to security researcher Pol Thill. The findings were published by SentinelOne following a Malware

Report: Fileless Attacks Increase by 1,400%

04 July 2023
Protecting runtime environments requires at least a monitoring approach that includes scanning for known malicious files and network communications, then blocking them and alerting when they appear. However, this is still insufficient.

Malvertising Leads to BlackCat Ransomware Infection

04 July 2023
Trend Micro researchers have identified a malvertising campaign that distributes BlackCat ransomware. Adversaries create cloned webpages, including that of the open-source file transfer app WinSCP, resembling legitimate organizations. Additionally, the criminals used SpyBoy, a tool that tampers with the protective measures implemented by security agents.

Alert: 330,000 FortiGate Firewalls Still Unpatched to CVE-2023-27997 RCE Flaw

04 July 2023
No less than 330000 FortiGate firewalls are still unpatched and vulnerable to CVE-2023-27997, a critical security flaw affecting Fortinet devices that have come under active exploitation in the wild. Cybersecurity firm Bishop Fox, in a report published last week, said that out of nearly 490,000 Fortinet SSL-VPN interfaces exposed on the internet, about 69 percent remain unpatched. CVE-2023-27997

Hackers Use Proxyjacking to Profit from Compromised SSH Servers' Bandwidth

04 July 2023
A new Proxyjacking campaign has come to light that targets SSH servers and proceeds to establish Docker services, utilizing the victim's bandwidth to generate revenue. Further investigation revealed the presence of cryptocurrency miners, exploits, and hacking tools on the compromised server. Organizations are advised to implement standard security measures.

GCHQ reveals British government was hacked by foreign cyber spies 20 years ago

03 July 2023
This month marks the 20th anniversary of the first time cyber experts at GCHQ responded to a foreign state hacking the British government, the intelligence and security agency revealed on Friday.

Hacks targeting British exam boards raise fears of students cheating

03 July 2023
Police in Britain are investigating multiple incidents in which national exam papers for school-leavers were stolen by hackers and sold online to students seeking to cheat on their tests.

Ireland: Dublin Airport staff pay data hit by criminals

03 July 2023
Pay and benefits details of Dublin Airport staff were compromised in a cyberattack on professional service provider Aon, highlighting the vulnerability of supply chain attacks.

Chinese Hackers Use HTML Smuggling to Infiltrate European Ministries with PlugX

03 July 2023
A Chinese nation-state group has been observed targeting Foreign Affairs ministries and embassies in Europe using HTML smuggling techniques to deliver the PlugX remote access trojan on compromised systems.

300,000+ Fortinet firewalls vulnerable to critical FortiOS RCE bug

03 July 2023
Hundreds of thousands of FortiGate firewalls are vulnerable to a critical security issue identified as CVE-2023-27997, almost a month after Fortinet released an update that addresses the problem.

GuLoader Campaign Targets Law Firms in the US

03 July 2023
The GuLoader malware campaign utilizes a multi-stage infection chain, including a PDF lure, a GuLoader VBScript, and obfuscated Powershell scripts, to deliver the Remcos RAT.

Who’s Behind the DomainNetworks Snail Mail Scam?

03 July 2023
If you've ever owned a domain name, the chances are good that at some point you've received a snail mail letter which appears to be a bill for a domain or website-related services. In reality, these misleading missives try to trick people into paying for useless services they never ordered, don't need, and probably will never receive. Here's a look at the most recent incarnation of this scam -- DomainNetworks -- and some clues about who may be behind it.

Torrent of image-based phishing emails are harder to detect and more convincing

03 July 2023
Phishing mongers have released a torrent of image-based junk emails that embed QR codes into their bodies to successfully bypass security protections and provide a level of customization to more easily fool recipients, researchers said.

Chinese Hackers Use HTML Smuggling to Infiltrate European Ministries with PlugX

03 July 2023
A Chinese nation-state group has been observed targeting Foreign Affairs ministries and embassies in Europe using HTML smuggling techniques to deliver the PlugX remote access trojan on compromised systems. Cybersecurity firm Check Point said the activity, dubbed SmugX, has been ongoing since at least December 2022. "The campaign uses new delivery methods to deploy (most notably – HTML Smuggling)

International Police Operation Dismantles Phone Scam Network

03 July 2023
A multi-national policing operation has led to the arrest of dozens of suspects including the alleged boss of an organized crime operation that targeted elderly victims with scam phone calls, according to Europol.

HHS Says At Least 100,000 People's Data Exposed After Hacks at Government Contractors

03 July 2023
While no HHS systems or networks were compromised, attackers gained access to HHS data by exploiting the vulnerability in the MOVEit software used by third-party vendors, the official said.

One third of security breaches go unnoticed by security professionals

03 July 2023
94% of global respondents believe their hybrid cloud security offers full visibility into IT infrastructure, yet almost one-third of security breaches go undetected by IT pros, according to a Gigamon report.

Evasive Meduza Stealer Targets 19 Password Managers and 76 Crypto Wallets

03 July 2023
"The Meduza Stealer has a singular objective: comprehensive data theft," Uptycs said in a new report. "It pilfers users' browsing activities, extracting a wide array of browser-related data."

Report reveals new browser-based social engineering trends

03 July 2023
A new report shows that three of the four new malware threats in the Q1 2023 top 10 list have originated in China and Russia.

Report shows a nearly 40% increase in global ransomware attacks

03 July 2023
A recently released report tracks trends and impacts of ransomware attacks including encryption-less extortion and growth of ransomware-as-a-service.