Latest Cybersecurity News and Articles


Mirai Variant Targets Multiple IoT Vulnerabilities in Recent Campaign

26 June 2023
Unit 42 researchers uncovered a modified version of the Mirai botnet that is actively abusing at least 22 security flaws in devices manufactured by the likes of D-Link, Arris, Zyxel, TP-Link, Tenda, Netgear, and MediaTek. The attackers aim to take control of these devices and utilize them to carry out DDoS attacks. Notably, this Mirai variant lacks the feature to brute force telnet/SSH login credentials.

Activision Blizzard Games Crippled by Hours-Long DDoS Attack

26 June 2023
The attack lasted for more than 10 hours and was mitigated late on Sunday, according to Activision Blizzard’s statement on Twitter. Blizzard has not yet identified the hacker group behind it and no one has yet come forward to claim responsibility.

An Overview of the Different Versions of the Trigona Ransomware

26 June 2023
Trigona ransomware is a relatively new family that targets compromised MSSQL servers and has been detected mainly in the technology and healthcare industries in countries such as the US, India, and Israel.

Ransomware attacks affect consumer behaviors

26 June 2023
Forty percent of consumers are skeptical of organizations' ability to protect their data adequately according to a report by Object First. 

Japanese Cryptocurrency Exchange Falls Victim to JokerSpy macOS Backdoor Attack

26 June 2023
Elastic Security Labs, which is monitoring the intrusion set under the name REF9134, said the attack led to the installation of Swiftbelt, a Swift-based enumeration tool inspired by an open-source utility called SeatBelt.

Top 10 risky behaviors of employees uncovered

26 June 2023
A new infographic reveals the top 10 risky behaviors that employees have engaged in on their work devices.

Cyberattack on Suncor Energy Impacts Payments at Petro-Canada Gas Stations

26 June 2023
The company says it has taken measures to mitigate the attack and informed the authorities of the situation. At the same time, it expects transactions with customers and suppliers to be negatively impacted until the incident is resolved.

Congress needs ‘private sector buy-in’ to address cyber workforce shortage

26 June 2023
Organizations are working to educate and train the next generation of professionals to fill critical cybersecurity vacancies, but private sector firms need to change their hiring practices to integrate this pool of talent into the workforce.

52% of reported breaches came through third-party partners

26 June 2023
According to a report by ForgeRock, identity theft and fraud remains a top concern for security leaders as it leads to large data breaches.

LastPass users furious after being locked out due to MFA resets

26 June 2023
Compounding the problem, affected users can't seek assistance since reaching out to LastPass support requires logging into their accounts which they can't do because of an infinite loop of MFA authenticator password reset prompt.

Volt Typhoon Employs Custom Web Shells for Persistent Access in Critical Infrastructure Attacks

26 June 2023
An analysis of the group's modus operandi has revealed its emphasis on operational security, carefully using an extensive set of open-source tools against a limited number of victims to carry out long-term malicious acts.

Uncovering attacker tactics through cloud honeypots

26 June 2023
As per a study by Orca Security, misconfigured and vulnerable assets are literally discovered within minutes. Exposed secrets on GitHub, HTTP, and SSH were all discovered in under five minutes. The AWS S3 Buckets were discovered in under one hour.

Federal Regulator Warns of Rising SEO Poisoning Attacks on Healthcare Sector

26 June 2023
Search engine optimization poisoning attacks, which involve intentionally manipulating search results to lead users onto malware-laced websites, are on the rise in the healthcare sector, U.S. federal regulators warn.

Japanese Cryptocurrency Exchange Falls Victim to JokerSpy macOS Backdoor Attack

26 June 2023
An unknown cryptocurrency exchange located in Japan was the target of a new attack earlier this month to deploy an Apple macOS backdoor called JokerSpy. Elastic Security Labs, which is monitoring the intrusion set under the name REF9134, said the attack led to the installation of Swiftbelt, a Swift-based enumeration tool inspired by an open-source utility called SeatBelt. JokerSky was first

Lawmakers renew effort to force data brokers to delete private information on request

26 June 2023
A bipartisan bill to protect Americans’ private online data by establishing a system for people to compel data brokers and companies to stop collecting it was reintroduced in Congress last week after a similar measure died last year.

American Airlines, Southwest Airlines Disclose Data Breaches Affecting Thousands of Pilots

26 June 2023
According to breach notifications filed on Friday with Maine's Office of the Attorney General, American Airlines said the data breach affected 5745 pilots and applicants, while Southwest reported a total of 3009.

SEC Alleges SolarWinds CFO, CISO Violated US Securities Laws

26 June 2023
The Securities and Exchange Commission accused SolarWinds CFO Bart Kalsu and CISO Tim Brown of violating securities laws in their response to a high-profile software supply chain cyberattack in 2020.

Trojanized Super Mario Bros Game Installer Spreads Malware

26 June 2023
Researchers from Cyble discovered a trojanized Super Mario Bros game installer for Windows that was used to deliver multiple malware, including an XMR miner, SupremeBot mining client, and the Open-source Umbral stealer.

How Generative AI Can Dupe SaaS Authentication Protocols — And Effective Ways To Prevent Other Key AI Risks in SaaS

26 June 2023
Security and IT teams are routinely forced to adopt software before fully understanding the security risks. And AI tools are no exception. Employees and business leaders alike are flocking to generative AI software and similar programs, often unaware of the major SaaS security vulnerabilities they're introducing into the enterprise. A February 2023 generative AI survey of 1,000 executives 

Microsoft Warns of Widescale Credential Stealing Attacks by Russian Hackers

26 June 2023
Microsoft has disclosed that it's detected a spike in credential-stealing attacks conducted by the Russian state-affiliated hacker group known as Midnight Blizzard. The intrusions, which made use of residential proxy services to obfuscate the source IP address of the attacks, target governments, IT service providers, NGOs, defense, and critical manufacturing sectors, the tech giant's threat