Latest Cybersecurity News and Articles


Security analyst wanted by both Russia and the US

29 June 2023
A Russian network security specialist and former editor of Hacker magazine who is wanted by the US and Russia on cybercrime charges has been detained in Kazakhstan as the two governments seek his extradition.

31% of breaches are being identified later

29 June 2023
A report from Gigamon analyzed the difference between how secure an organization perceives itself to be and how secure it actually is.

US Patent and Trademark Office Notifies Filers of Years-Long Data Leak

29 June 2023
The U.S. Patent and Trademark Office (USPTO) said in a notice sent to affected trademark applicants that their private domicile address — often their home address — inadvertently appeared in public records between February 2020 and March 2023.

Fluhorse: Flutter-Based Android Malware Targets Credit Cards and 2FA Codes

29 June 2023
Cybersecurity researchers have shared the inner workings of an Android malware family called Fluhorse. The malware "represents a significant shift as it incorporates the malicious components directly within the Flutter code," Fortinet FortiGuard Labs researcher Axelle Apvrille said in a report published last week. Fluhorse was first documented by Check Point in early May 2023, detailing its

Critical Security Flaw in Social Login Plugin for WordPress Exposes Users' Accounts

29 June 2023
Tracked as CVE-2023-2982 (CVSS score: 9.8), the authentication bypass flaw impacts all versions, including and prior to 7.6.4. It was addressed on June 14, 2023, with the release of version 7.6.5 following responsible disclosure on June 2, 2023.

Enterprise SIEMs miss 76% of all MITRE ATT&CK techniques used

29 June 2023
According to industry analysts, the SIEM continues to be the "operating system of the SOC" and is not going away anytime soon.

Cyware Raises $30 Million to Accelerate Expansion of AI-Powered Global Cyber Fusion and Threat Sharing Networks

29 June 2023
The Cyware platform is used by top Fortune 1000 and MSSP security teams to transform their legacy SOCs into Cyber Fusion Centers and facilitate collaboration and automation in threat intelligence sharing and response.

CryptosLabs Scam Ring Targets French-Speaking Investors, Rakes in $525 Million

29 June 2023
Cybersecurity researchers have exposed the workings of a scam ring called CryptosLabs that's estimated to have made $525 million in illegal profits by targeting users in French-speaking individuals in France, Belgium, and Luxembourg since April 2018.

Submarine Cables at Growing Risk of Cyber-Attacks

29 June 2023
Submarine communication cables are a growing target for cyber-threat actors, with potential incidents capable of causing huge global internet disruption, a new report has found.

The Right Way to Enhance CTI with AI (Hint: It's the Data)

29 June 2023
Cyber threat intelligence is an effective weapon in the ongoing battle to protect digital assets and infrastructure - especially when combined with AI. But AI is only as good as the data feeding it. Access to unique, underground sources is key. Threat Intelligence offers tremendous value to people and companies. At the same time, its ability to address organizations' cybersecurity needs and the

North Korean Hacker Group Andariel Strikes with New EarlyRat Malware

29 June 2023
The North Korea-aligned threat actor known as Andariel leveraged a previously undocumented malware called EarlyRat in attacks exploiting the Log4j Log4Shell vulnerability last year. "Andariel infects machines by executing a Log4j exploit, which, in turn, downloads further malware from the command-and-control (C2) server," Kaspersky said in a new report. Also called Silent Chollima and Stonefly,

Android Spy App LetMeSpy Suffers Major Data Breach, Exposing Users' Personal Data

29 June 2023
Android-based phone monitoring app LetMeSpy has disclosed a security breach that allowed an unauthorized third-party to steal sensitive data associated with thousands of Android users. "As a result of the attack, the criminals gained access to email addresses, telephone numbers and the content of messages collected on accounts," LetMeSpy said in an announcement on its website, noting the

Ukraine's Critical Infrastructure Hit 3,000 Times Since 2022

29 June 2023
The State Service of Special Communications and Information Protection of Ukraine warned that such attacks may continue for years even after the fighting on the ground is over.

Study Reveals Alarming Gap in SIEM Detection of Adversary Techniques

29 June 2023
The claims come from CardinalOps’ 2023 Report on State of SIEM Detection Risk, which examined over 4000 detection rules, one million log sources, and various unique log source types from production SIEMs.

Vendor Pays $75,000 HIPAA Fine in Data Exfiltration Breach

29 June 2023
The Department of Health and Human Services on Wednesday said the HIPAA settlement with iHealth Solutions, which does business as Advantum Health, involved an investigation into the 2017 incident affecting 267 individuals.

White House releases cybersecurity budget priorities for FY 2025

29 June 2023
The Office of Management and Budget and the Office of the National Cyber Director released a memo outlining five cybersecurity budget priorities for federal departments and agencies for FY 2025 consistent with the National Cybersecurity Strategy.

Venn Software Snags $29M to Build MDM for Laptops Technology

29 June 2023
Venn said the Series A financing was led by NewSpring and provides capital for the company to make MDM for laptops a reality and provide a less costly new alternative to virtual desktop infrastructure (VDI).

Linux version of Akira ransomware targets VMware ESXi servers

29 June 2023
Like other enterprise-targeting ransomware gangs, the threat actors steal data from breached networks and encrypt files to conduct double extortion on victims, demanding payments that reach several million dollars.

Exploit released for new Arcserve UDP auth bypass vulnerability

29 June 2023
Data protection vendor Arcserve has addressed a high-severity security flaw in its Unified Data Protection (UDP) backup software that can let attackers bypass authentication and gain admin privileges.

Critical Security Flaw in Social Login Plugin for WordPress Exposes Users' Accounts

29 June 2023
A critical security flaw has been disclosed in miniOrange's Social Login and Register plugin for WordPress that could enable a malicious actor to log in as any user-provided information about email address is already known. Tracked as CVE-2023-2982 (CVSS score: 9.8), the authentication bypass flaw impacts all versions of the plugin, including and prior to 7.6.4. It was addressed on June 14, 2023