Latest Cybersecurity News and Articles
26 June 2023
Security and IT teams are routinely forced to adopt software before fully understanding the security risks. And AI tools are no exception.
Employees and business leaders alike are flocking to generative AI software and similar programs, often unaware of the major SaaS security vulnerabilities they're introducing into the enterprise. A February 2023 generative AI survey of 1,000 executives
26 June 2023
Microsoft has disclosed that it's detected a spike in credential-stealing attacks conducted by the Russian state-affiliated hacker group known as Midnight Blizzard.
The intrusions, which made use of residential proxy services to obfuscate the source IP address of the attacks, target governments, IT service providers, NGOs, defense, and critical manufacturing sectors, the tech giant's threat
26 June 2023
ChatGPT can be used to detect phishing sites based on URLs, but its false positive rate is too high to be reliable on its own. ChatGPT can assist analysts by highlighting suspicious parts of the URL and suggesting possible attack targets.
26 June 2023
The Senate's annual defense policy bill includes a provision that would require the Department of Defense to study the feasibility of establishing a separate Cyber Force.
26 June 2023
Migrating to the cloud does not alleviate an organization's cyber risk, and cloud security is a shared responsibility. Misconfigurations can magnify the risk of security issues in cloud environments.
26 June 2023
With the recently discovered vulnerabilities remote attackers could launch denial-of-service attacks, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said in an advisory released Friday.
26 June 2023
Three years after one of the most visible hacks in recent history played out in real-time in front of millions of Twitter users, one of the hackers responsible for the breach will now serve time in federal prison.
26 June 2023
Three months after arresting its administrator, U.S. federal authorities seized the domain of the notorious hacking site BreachForums. For a time, the forum was the go-to community for English-speaking cybercriminals
26 June 2023
Grafana has released security fixes for multiple versions of its application, addressing a vulnerability that enables attackers to bypass authentication and take over any Grafana account that uses Azure Active Directory for authentication.
26 June 2023

Hundreds of law firm’s clients waiting on confirmation of whether they are affected by data leaked in cyberattackFollow our Australia news live blog for the latest updatesGet our morning and afternoon news emails, free app or daily news podcastHundreds of clients of law firm HWL Ebsworth, including dozens of government agencies, have been in discussions with the firm over whether highly sensitive legal information has been exposed – while a NSW court injunction prevents those potentially affected from searching through the data posted on the dark web to check.The Russian-linked ALPHV/Blackcat ransomware group hacked the law firm in April. Earlier this month, the group published 1.1TB of the data it claimed to have stolen, later established to be 3.6TB worth of data.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...
26 June 2023
The newly discovered Chinese nation-state actor known as Volt Typhoon has been observed to be active in the wild since at least mid-2020, with the hacking crew linked to never-before-seen tradecraft to retain remote access to targets of interest.
The findings come from CrowdStrike, which is tracking the adversary under the name Vanguard Panda.
"The adversary consistently employed ManageEngine
26 June 2023
Check Point laid bare a Chinese APT operation using a self-propagating USB malware called WispRider. A European healthcare institution fell victim to it after an employee used an infected USB drive on the hospital’s system. The USB drives were further found to affect networked storage devices, significantly amplifying the scope and potential impact of this threat.
24 June 2023
The U.S. Cybersecurity and Infrastructure Security Agency has added a batch of six flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
This comprises three vulnerabilities that Apple patched this week (CVE-2023-32434, CVE-2023-32435, and CVE-2023-32439), two flaws in VMware (CVE-2023-20867 and CVE-2023-20887), and one shortcoming impacting Zyxel
24 June 2023
A U.K. citizen who took part in the massive July 2020 hack of Twitter has been sentenced to five years in prison in the U.S.
Joseph James O'Connor (aka PlugwalkJoe), 24, was awarded the sentence on Friday in the Southern District of New York, a little over a month after he pleaded guilty to the criminal schemes. He was arrested in Spain in July 2021.
The infamous Twitter breach allowed the
24 June 2023
Libra is the designation given by Unit 42 for cybercrime groups. The "muddled" moniker for the threat actor stems from the prevailing ambiguity with regard to the use of the 0ktapus framework.
24 June 2023
A new strain of JavaScript dropper has been observed delivering next-stage payloads like Bumblebee and IcedID. Cybersecurity firm Deep Instinct is tracking the malware as PindOS, which contains the name in its "User-Agent" string.
24 June 2023
Recent reports indicate that these seemingly innocuous devices, once activated, automatically connect to Wi-Fi networks and establish unauthorized connections with users’ cell phones, potentially exposing sensitive personal data.
24 June 2023
After gaining access to a system, the attackers deploy a trojanized OpenSSH package that helps them backdoor the compromised devices and steal SSH credentials to maintain persistence.
24 June 2023
Swing VPN is a legitimate VPN app developed for Android and iOS systems by Limestone Software Solutions. However, according to researcher Lecromee, the Android version of this app is a DDoS botnet and allegedly harbors malicious intent.
23 June 2023
While many security professionals leverage high-risk practices and behaviors in their cloud environments, they are confident security tools will protect against attacks.