Latest Cybersecurity News and Articles
23 June 2023
Security experts came across a new campaign—from late 2022 to early 2023—by the Chinese state-sponsored threat group APT15, which used a novel backdoor called Graphican that possesses several capabilities. Symantec has published the IOCs for a better understanding of the threat to protect against it.
23 June 2023
The organization said Wednesday that it was informed on June 6 by a third-party vendor – PBI Research Services/Berwyn Group – that data was accessed by hackers exploiting the MOVEit file transfer tool.
23 June 2023
According to a survey by Panaseer, automation is considered more effective than vendor consolidation in easing industry concerns, and 96% of organizations automate at least one aspect of their cybersecurity.
23 June 2023
The North Korean APT37 (aka ScarCruft and RedEyes) group was found using a new info-stealer with wiretapping features, named FadeStealer, along with a backdoor written in GoLang that abuses the Ably platform. Apart from the ability to listen to private conversations of victims, the malware can steal a wide variety of information from Windows systems.
23 June 2023
The case for browser fingerprinting: personalizing user experience, improving fraud detection, and optimizing login security
Have you ever heard of browser fingerprinting? You should! It's an online user identification technique that collects information about a visitor's web browser and its configuration preferences to associate individual browsing sessions with a single website visitor.
With
23 June 2023
Open source is key to the success of cloud-native security as it facilitates collaboration amongst developers, architects, and users, brings strength in numbers, and allows for diverse innovation.
23 June 2023
A new strain of JavaScript dropper has been observed delivering next-stage payloads like Bumblebee and IcedID.
Cybersecurity firm Deep Instinct is tracking the malware as PindOS, which contains the name in its "User-Agent" string.
Both Bumblebee and IcedID serve as loaders, acting as a vector for other malware on compromised hosts, including ransomware. A recent report from Proofpoint
23 June 2023
Dole said the hackers accessed the names, addresses, driver’s license numbers, passport numbers, dates of birth, phone numbers, and other employment information, according to a filing with the Maine Attorney General.
23 June 2023
According to research by Insikt Group and CERT-UA, Russian hackers exploited vulnerabilities (CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026) in Roundcube Webmail software to gain unauthorized access to unpatched servers.
23 June 2023
Suspected Chinese APT groups exploited a 17-year-old Microsoft Office vulnerability in May to launch malware attacks against foreign government officials who attended a G7 summit in Hiroshima, Japan.
23 June 2023
The U.S. National Security Agency (NSA) on Thursday released guidance to help organizations detect and prevent infections of a Unified Extensible Firmware Interface (UEFI) bootkit called BlackLotus.
To that end, the agency is recommending that "infrastructure owners take action by hardening user executable policies and monitoring the integrity of the boot partition."
BlackLotus is an advanced
23 June 2023
The project is expected to feature a reference design and an implementation guide addressing four main cybersecurity challenges across the water and wastewater sector, namely asset management, data integrity, remote access, and network segmentation.
23 June 2023
Although the authenticity of these claims remains uncertain, the fact that the hacker is offering to use Escrow—a trusted third-party payment service—adds a level of credibility to the offer.
23 June 2023
In addition to backdoor capabilities and the ability to propagate through USB using the HopperTick launcher, the payload includes additional features, such as a bypass for SmadAV, an anti-virus solution popular in Southeast Asia.
23 June 2023
Internet-facing Linux systems and Internet of Things (IoT) devices are being targeted as part of a new campaign designed to illicitly mine cryptocurrency.
"The threat actors behind the attack use a backdoor that deploys a wide array of tools and components such as rootkits and an IRC bot to steal device resources for mining operations," Microsoft threat intelligence researcher Rotem Sde-Or said.
22 June 2023
The United Parcel Service (UPS) says fraudsters have been harvesting phone numbers and other information from its online shipment tracking tool in Canada to send highly targeted SMS phishing (a.k.a. "smishing") messages that spoofed UPS and other top brands. The missives addressed recipients by name, included details about recent orders, and warned that those orders wouldn't be shipped unless the customer paid an added delivery fee.
22 June 2023
IT leaders were surveyed by Kaseya about IT operations and management. Forty-five percent of respondents prioritize the improvement of IT security.
22 June 2023
RepoJacking is a security vulnerability that may lead to code execution on organizations' internal or customer environments. Millions of GitHub repositories are potentially vulnerable to it, including popular organizations such as Google and Lyft.
22 June 2023
A new phishing campaign codenamed MULTI#STORM has set its sights on India and the U.S. by leveraging JavaScript files to deliver remote access trojans on compromised systems.
"The attack chain ends with the victim machine infected with multiple unique RAT (remote access trojan) malware instances, such as Warzone RAT and Quasar RAT," Securonix researchers Den Iuzvyk, Tim Peck, and Oleg Kolesnikov
22 June 2023
Multinational shipping company UPS is alerting Canadian customers that some of their personal information might have been exposed via its online package look-up tools and abused in phishing attacks.