Latest Cybersecurity News and Articles
03 July 2023
A recently released report tracks trends and impacts of ransomware attacks including encryption-less extortion and growth of ransomware-as-a-service.
03 July 2023
Officials across at least five US states, including Nebraska, South Dakota, Texas, Pennsylvania, and South Carolina, are investigating hacking claims by a suspected politically motivated group against websites connected to local governments.
03 July 2023
Officials across at least five US states, including Nebraska, South Dakota, Texas, Pennsylvania, and South Carolina, are investigating hacking claims by a suspected politically motivated group against websites connected to local governments.
03 July 2023
Every website owner or webmaster grapples with the issue of spam on their website forms. The volume of spam can be so overwhelming that finding useful information within it becomes quite challenging. What exacerbates this issue is that spam can populate your public pages, appearing in comments and reviews. You likely understand how this can damage your website's reputation, affect search results
03 July 2023
The claims of a direct hack of its IT systems were quashed by a TSMC spokesperson who told Information Security Media Group the data leak actually had affected Kinmax Technology Inc., one of its IT hardware suppliers.
03 July 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has placed a set of eight flaws to the Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
This includes six shortcomings affecting Samsung smartphones and two vulnerabilities impacting D-Link devices. All the flaws have been patched as of 2021.
CVE-2021-25394 (CVSS score: 6.4) - Samsung mobile
03 July 2023
Researchers have pulled back the curtain on an updated version of an Apple macOS malware called RustBucket that comes with improved capabilities to establish persistence and avoid detection by security software.
03 July 2023
U.S. prosecutors obtained a guilty plea Thursday from a third Nigerian man, Chibundu Joseph Anuebunwa, accused of participating in a business email compromise (BEC) ring in the mid-2010s.
03 July 2023
In yet another sign of a lucrative crimeware-as-a-service (CaaS) ecosystem, cybersecurity researchers have discovered a new Windows-based information stealer called Meduza Stealer that's actively being developed by its author to evade detection by software solutions.
"The Meduza Stealer has a singular objective: comprehensive data theft," Uptycs said in a new report. "It pilfers users' browsing
03 July 2023
Cait Conley, a senior adviser to CISA Director Jen Easterly, will assume “additional responsibilities,” including supervising election security and protecting voters from disinformation campaigns.
03 July 2023
The Illinois law, known as the Biometric Information Privacy Act (BIPA), mandates companies that collect or obtain an Illinois resident’s biometric identifier to alert that individual beforehand and get their consent in writing.
03 July 2023
According to Nexusguard, the top three DDoS attack vectors in 2022 were NTP (network time protocol) amplification, memcached, and UDP attacks. UDP-based attacks increased 121.3% year-over-year (YoY).
03 July 2023
The US Cybersecurity and Infrastructure Security Agency (CISA) has added half a dozen flaws affecting Samsung smartphones to its Known Exploited Vulnerabilities Catalog, and they have all likely been exploited by a commercial spyware vendor.
03 July 2023
The early adoption of generative AI or any nascent technology, particularly LLMs, requires comprehensive risk assessment and adherence to robust security practices throughout the entire software development life cycle (SDLC).
03 July 2023
CISA, in an advisory issued Thursday, said the deserialization of untrusted data vulnerability identified in Medtronic's Paceart Optima, versions 1.11 and earlier, is exploitable remotely and has a low attack complexity.
03 July 2023
Threat actors associated with the BlackCat ransomware have been observed employing malvertising tricks to distribute rogue installers of the WinSCP file transfer application.
"Malicious actors used malvertising to distribute a piece of malware via cloned webpages of legitimate organizations," Trend Micro researchers said in an analysis published last week. "In this case, the distribution
03 July 2023
Iranian threat actor Charming Kitten introduced the new version of its PowerStar backdoor malware. The updated malware utilizes the InterPlanetary File System (IPFS) and publicly accessible cloud hosting for its decryption function and configuration details. The latest iteration of the backdoor unveils enhanced operational security measures, rendering the malware even more challenging to analyze and gather intelligence on.
01 July 2023
Cybersecurity firm Avast has released a free decryptor for the Akira ransomware. Akira first appeared in March 2023 and made a name for itself by quickly amassing victims as it targeted organizations worldwide in a broad range of sectors.
01 July 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned today of ongoing distributed denial-of-service (DDoS) attacks after U.S. organizations across multiple industry sectors were hit.
01 July 2023
Tracked as CVE-2023-3460 (CVSS score of 9.8), the recently identified security defect in Ultimate Member plugin allows attackers to add a new user account to the administrators group.