Latest Cybersecurity News and Articles
01 July 2023
Since June 1, experts have warned of the vulnerability affecting the popular file transfer software, and dozens of the biggest organizations in the U.S. and Europe have since come forward to reveal that they were affected by the situation.
01 July 2023
As many as 200,000 WordPress websites are at risk of ongoing attacks exploiting a critical unpatched security vulnerability in the Ultimate Member plugin.
The flaw, tracked as CVE-2023-3460 (CVSS score: 9.8), impacts all versions of the Ultimate Member plugin, including the latest version (2.6.6) that was released on June 29, 2023.
Ultimate Member is a popular plugin that facilitates the
01 July 2023
The compromised NHS data includes records of major trauma patients across England and individuals treated after terror attacks, which the university collected for research purposes, according to media outlet The Independent on Thursday.
01 July 2023
A group of previously unknown hackers has claimed responsibility for a cyberattack on the Russian satellite communications provider Dozor-Teleport, which is used by energy companies and the country's defense and security services.
01 July 2023
Researchers have pulled back the curtain on an updated version of an Apple macOS malware called Rustbucket that comes with improved capabilities to establish persistence and avoid detection by security software.
"This variant of Rustbucket, a malware family that targets macOS systems, adds persistence capabilities not previously observed," Elastic Security Labs researchers said in a report
01 July 2023
The infection chain started with a malicious ad for the WinSCP application displayed in search engine results. Users who clicked on the ad were redirected to a cloned download webpage where they unknowingly downloaded a malware-infected ISO file.
30 June 2023
A report found that 75% of businesses report that security is a growing priority and they are spending more in security related areas than in 2022.
30 June 2023
Charming Kitten, the nation-state actor affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC), has been attributed to a bespoke spear-phishing campaign that delivers an updated version of a fully-featured PowerShell backdoor called POWERSTAR.
"There have been improved operational security measures placed in the malware to make it more difficult to analyze and collect intelligence,"
30 June 2023
National Hazard Agency, a sub-group of the LockBit ransomware gang, posted the name of Taiwan Semiconductor Manufacturing Company (TSMC), the world’s largest chip manufacturer, on LockBit’s dark web leak site on June 29, 2023.
30 June 2023
One telemedicine scheme involved telemarketers targeting elderly and disabled patients, resulting in $1.9 billion in allegedly fraudulent claims to Medicare and other government insurers.
30 June 2023
"This is an active campaign in which the attacker leverages SSH for remote access, running malicious scripts that stealthily enlist victim servers into a P2P proxy network, such as Peer2Profit or Honeygain," Akamai researcher Allen West said.
30 June 2023
The exploitation of remote services like VPNs and RDP was the most commonly seen attack technique last year, according to the Annual Cyber-Threat Report 2023 from ReliaQuest.
30 June 2023
By sharing this list, MITRE provides the broader community with valuable information regarding the most critical software security weaknesses that require immediate attention.
30 June 2023
The primary cause of cyberattacks against Japanese computer systems is the strength and quality of its manufacturing base. The size of Japanese manufacturers makes them an attractive target for criminal extortion.
30 June 2023
In today's fast-paced digital landscape, the widespread adoption of AI (Artificial Intelligence) tools is transforming the way organizations operate. From chatbots to generative AI models, these SaaS-based applications offer numerous benefits, from enhanced productivity to improved decision-making. Employees using AI tools experience the advantages of quick answers and accurate results, enabling
30 June 2023
The Iranian state-sponsored group dubbed MuddyWater has been attributed to a previously unseen command-and-control (C2) framework called PhonyC2 that's been put to use by the actor since 2021.
30 June 2023
The volume of mobile malware, phishing sites dedicated to mobiles, and mobile vulnerabilities increased significantly in 2022, according to the Global Mobile Threat Report 2023 from Zimperium.
30 June 2023
According to analysis in the Acronis Mid-Year Cyberthreats Report 2023 LockBit’s known victims totaled 280 (49% of the total reviewed) and included the Housing Authority of the City of Los Angeles (HACLA), Aguas do Porto, and Wabtec Corporation.
30 June 2023
In a new report, Sekoia analysts say that the DDoSia platform has grown significantly over the year, reaching 10,000 active members contributing firepower to the project's DDoS attacks and 45,000 subscribers on its main Telegram channel.
30 June 2023
A Cleveland-based healthcare system is notifying a not-yet-undisclosed number of individuals about an incident involving unauthorized medical records access by an employee over the past 15 years.