Latest Cybersecurity News and Articles


MIT Publishes Framework to Evaluate Cybersecurity Methods

30 June 2023
The Metior framework allows engineers and scientists to study various factors such as victim programs, attacker strategies, and obfuscation scheme configurations to determine the extent of information leakage.

WhatsApp Upgrades Proxy Feature Against Internet Shutdowns

30 June 2023
Meta's WhatsApp has rolled out updates to its proxy feature, allowing more flexibility in the kind of content that can be shared in conversations. This includes the ability to send and receive images, voice notes, files, stickers and GIFs, WhatsApp told The Hacker News. The new features were first reported by BBC Persian. Some of the other improvements include streamlined steps to simplify the

Apple opposes UK Online Safety Bill's 'spy clause'

30 June 2023
Apple has joined the rapidly growing chorus of tech organizations calling on British lawmakers to revise the nation's Online Safety Bill – which for now is in the hands of the House of Lords – so that it safeguards strong end-to-end encryption.

Cybercriminals Hijacking Vulnerable SSH Servers in New Proxyjacking Campaign

30 June 2023
An active financially motivated campaign is targeting vulnerable SSH servers to covertly ensnare them into a proxy network. "This is an active campaign in which the attacker leverages SSH for remote access, running malicious scripts that stealthily enlist victim servers into a peer-to-peer (P2P) proxy network, such as Peer2Profit or Honeygain," Akamai researcher Allen West said in a Thursday

Charming Kitten’s PowerStar Malware Evolves with Advanced Techniques

30 June 2023
The latest PowerStar variant offers remote execution of PowerShell and C# commands, persistence through various methods, dynamic configuration updates, multiple C2 channels, system reconnaissance, and monitoring of established persistence mechanisms.

IP Fabric Raises $25 Million in Series B Funding

30 June 2023
The new investment round was led by One Peak, with participation from Senovo and Presto Ventures. The company says it can help organizations address three main issues with network management — automation, complexity, and assurance.

NSA and CISA Release Guidelines to Secure CI/CD Environments

30 June 2023
The US National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) have published a comprehensive set of guidelines aimed at defending Continuous Integration/Continuous Delivery (CI/CD) environments.

MITRE Unveils Top 25 Most Dangerous Software Weaknesses of 2023: Are You at Risk?

30 June 2023
MITRE has released its annual list of the Top 25 "most dangerous software weaknesses" for the year 2023. "These weaknesses lead to serious vulnerabilities in software," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said. "An attacker can often exploit these vulnerabilities to take control of an affected system, steal data, or prevent applications from working." The list is

NCSC marks 20th anniversary of first response to state-sponsored cyber attack

29 June 2023
In June 2003, GCHQ experts were involved in responding to a cyber attack against the UK Government for the first time.

8Base Ransomware Activity Spikes, Researcher Warn

29 June 2023
Ransomware threat 8Base has been conducting double extortion attacks for over a year and its activities spiked suddenly in May and June 2023. 8Base has been connected to 67 attacks by Malwarebytes and NCC Group. Approximately 50% of the targeted victims belong to the business services, manufacturing, and construction sectors.

Russian Cybersecurity Executive Arrested for Alleged Role in 2012 Megahacks

29 June 2023
Nikita Kislitsin, formerly the head of network security for one of Russia's top cybersecurity firms, was arrested last week in Kazakhstan in response to 10-year-old hacking charges from the U.S. Department of Justice. Experts say Kislitsin's prosecution could soon put the Kazakhstan government in a sticky diplomatic position, as the Kremlin is already signaling that it intends to block his extradition to the United States.

European Cyber Agency Remains Underfunded

29 June 2023
There are multiple discrepancies in how the European Commission allocates funds to the cyber agency, Juhan Lepassaar, the executive director of the EU Agency for Cybersecurity, said during a Tuesday parliamentary hearing evaluating allocated budgets.

Details Disclosed for Critical SAP Vulnerabilities, Including Wormable Exploit Chain

29 June 2023
The vulnerabilities are tracked as CVE-2021-27610, CVE-2021-33677, CVE-2021-33684, and CVE-2023-0014, and they impact products that use the SAP Application Server for ABAP component.

Saudi Arabia's Cyber Capabilities Ranked Second Globally

29 June 2023
According to the IIMD, the development of a National Cybersecurity Authority (NCA) and the planned development of a Global Cybersecurity Forum institute in the country have both affirmed Saudi Arabia's role in the field of cybersecurity.

Cyber Command to expand 'canary in the coal mine' unit working with private sector

29 June 2023
U.S. Cyber Command is doubling the size of a little-known program that serves as one of the military's chief links to private industry in order to bolster the country’s defenses against cyber threats.

Manic Menagerie 2.0: The Evolution of a Highly Motivated Threat Actor

29 June 2023
The threat actor used a variety of tactics, techniques, and tools to evade detection and maintain access to the compromised networks, including deploying web shells, exploiting vulnerabilities, and attempting local privilege escalation.

Dark Power Ransomware on the Ascent – A Technical Insight into 2023’s Latest Ransomware Strain

29 June 2023
Dark Power is a highly advanced ransomware strain that uses advanced encryption techniques and targets various industries globally. It stops critical system services and processes, encrypts files, and drops a ransom note with payment instructions.

From MuddyC3 to PhonyC2: Iran's MuddyWater Evolves with a New Cyber Weapon

29 June 2023
The Iranian state-sponsored group dubbed MuddyWater has been attributed to a previously unseen command-and-control (C2) framework called PhonyC2 that's been put to use by the actor since 2021. Evidence shows that the custom made, actively developed framework has been leveraged in the February 2023 attack on Technion, an Israeli research institute, cybersecurity firm Deep Instinct said in a

Security analyst wanted by both Russia and the US

29 June 2023
A Russian network security specialist and former editor of Hacker magazine who is wanted by the US and Russia on cybercrime charges has been detained in Kazakhstan as the two governments seek his extradition.

31% of breaches are being identified later

29 June 2023
A report from Gigamon analyzed the difference between how secure an organization perceives itself to be and how secure it actually is.