Latest Cybersecurity News and Articles
28 June 2023
Researchers spotted a trojanized version of the Super Mario 3: Mario Forever installer spreading Windows malware called Umbral Stealer. The installer is being promoted on gaming forums and social media groups. Researchers recommend users check their system performance and CPU usage regularly and implement proper cybersecurity hygiene to stay safe.
28 June 2023
A ransomware threat called 8Base that has been operating under the radar for over a year has been attributed to a "massive spike in activity" in May and June 2023.
"The group utilizes encryption paired with 'name-and-shame' techniques to compel their victims to pay their ransoms," VMware Carbon Black researchers Deborah Snyder and Fae Carlisle said in a report shared with The Hacker News. "8Base
28 June 2023
Switzerland’s Federal Intelligence Service (FIS) explained that this cyber espionage was a “compensatory measure … where there has been a reduction in the number of intelligence staff deployed in the target countries.”
28 June 2023
The newly discovered malware is designed to collect various information from compromised machines, such as BIOS and hardware data, and send it to a command-and-control server.
28 June 2023
The Series A round was led by Sante Ventures, with participation from the Icahn School of Medicine at Mount Sinai, AIX Ventures, Continuum Health Ventures, TA Group Holdings, and UCSF.
28 June 2023
"The packages in question seem to be published in pairs, each pair working in unison to fetch additional resources which are subsequently decoded and/or executed," software supply chain security firm Phylum said in a report released last week.
28 June 2023
The Anatsa Android banking trojan is being distributed via the Google Play Store, with over 30,000 installations recorded. The trojan collects financial information and performs on-device fraud. The malware has already amassed over 30,000 installations. mobile users need to exercise caution with app installations; they must carefully proceed to download apps.
28 June 2023
The two issues, which were discovered in the search feature of Soko, have been collectively tracked as CVE-2023-28424 (CVSS score: 9.1). They were addressed within 24 hours of responsible disclosure on March 17, 2023.
28 June 2023
Multiple SQL injection vulnerabilities have been disclosed in Gentoo Soko that could lead to remote code execution (RCE) on vulnerable systems.
"These SQL injections happened despite the use of an Object-Relational Mapping (ORM) library and prepared statements," SonarSource researcher Thomas Chauchefoin said, adding they could result in RCE on Soko because of a "misconfiguration of the database.
27 June 2023
Lindy Cameron discusses the shared opportunities and threats to both nations in cyberspace at UK-INDIA Week 2023.
27 June 2023
Joseph James "PlugwalkJoe" O'Connor, a 24-year-old from the United Kingdom who earned his 15 minutes of fame by participating in the July 2020 hack of Twitter, has been sentenced to five years in a U.S. prison. That may seem like harsh punishment for a brief and very public cyber joy ride. But O'Connor also pleaded guilty in a separate investigation involving a years-long spree of cyberstalking and cryptocurrency theft enabled by "SIM swapping," a crime wherein fraudsters trick a mobile provider into diverting a customer's phone calls and text messages to a device they control.
27 June 2023
The phone monitoring app, which is used to spy on thousands of people using Android phones, said in a notice on its login page that on June 21, “a security incident occurred involving obtaining unauthorized access to the data of website users??.”
27 June 2023
Researchers at Censys have analyzed the attack surfaces of more than 50 Federal Civilian Executive Branch (FCEB) organizations and sub-organizations and discovered more than 13,000 distinct hosts across 100 autonomous systems.
27 June 2023
The company, which manages three residential facilities in Pennsylvania, discovered suspicious activity in its internal systems used for business operations and immediately implemented measures to contain the situation.
27 June 2023
CISA has recently released the first series of final security guidance resources under the organization's Secure Cloud Business Applications (SCuBA) project.
27 June 2023
Researchers at cybersecurity firm Security Joes discovered the method, which utilizes legitimate DLLs with RWX (read, write, execute) sections for evading EDR hooks and injecting code into remote processes.
27 June 2023
The Nevada-based identity verification company said the acquisition of San Francisco-based Berbix will help it optimize the digital capturing and back-end processing of driver's licenses and passports at faster speeds and with greater accuracy.
27 June 2023
The Cl0p ransomware group added five new victims of MOVEit attacks to its dark web leak site, including the industrial control systems giants Schneider Electric and Siemens Energy.
27 June 2023
A new process injection technique dubbed Mockingjay could be exploited by threat actors to bypass security solutions to execute malicious code on compromised systems.
"The injection is executed without space allocation, setting permissions or even starting a thread," Security Joes researchers Thiago Peixoto, Felipe Duarte, and
Ido Naor said in a report shared with The Hacker News. "The
27 June 2023
Cybersecurity researchers have discovered a new ongoing campaign aimed at the npm ecosystem that leverages a unique execution chain to deliver an unknown payload to targeted systems.
"The packages in question seem to be published in pairs, each pair working in unison to fetch additional resources which are subsequently decoded and/or executed," software supply chain security firm Phylum said in