Latest Cybersecurity News and Articles


Chinese APT15 Re-emerges with New Graphican Malware

23 June 2023
Security experts came across a new campaign—from late 2022 to early 2023—by the Chinese state-sponsored threat group APT15, which used a novel backdoor called Graphican that possesses several capabilities. Symantec has published the IOCs for a better understanding of the threat to protect against it. 

Largest Public Pension Fund in US Affected by MOVEit Breach

23 June 2023
The organization said Wednesday that it was informed on June 6 by a third-party vendor – PBI Research Services/Berwyn Group – that data was accessed by hackers exploiting the MOVEit file transfer tool.

Increased spending doesn’t translate to improved cybersecurity posture

23 June 2023
According to a survey by Panaseer, automation is considered more effective than vendor consolidation in easing industry concerns, and 96% of organizations automate at least one aspect of their cybersecurity.

APT37 Found Using FadeStealer to Eavesdrop on Victims

23 June 2023
The North Korean APT37 (aka ScarCruft and RedEyes) group was found using a new info-stealer with wiretapping features, named FadeStealer, along with a backdoor written in GoLang that abuses the Ably platform. Apart from the ability to listen to private conversations of victims, the malware can steal a wide variety of information from Windows systems.

The Power of Browser Fingerprinting: Personalized UX, Fraud Detection, and Secure Logins

23 June 2023
The case for browser fingerprinting: personalizing user experience, improving fraud detection, and optimizing login security Have you ever heard of browser fingerprinting? You should! It's an online user identification technique that collects information about a visitor's web browser and its configuration preferences to associate individual browsing sessions with a single website visitor.  With

Cloud-native security hinges on open source

23 June 2023
Open source is key to the success of cloud-native security as it facilitates collaboration amongst developers, architects, and users, brings strength in numbers, and allows for diverse innovation.

Powerful JavaScript Dropper PindOS Distributes Bumblebee and IcedID Malware

23 June 2023
A new strain of JavaScript dropper has been observed delivering next-stage payloads like Bumblebee and IcedID. Cybersecurity firm Deep Instinct is tracking the malware as PindOS, which contains the name in its "User-Agent" string. Both Bumblebee and IcedID serve as loaders, acting as a vector for other malware on compromised hosts, including ransomware. A recent report from Proofpoint 

Update: Dole says February ransomware attack breached data of almost 3,900 US workers

23 June 2023
Dole said the hackers accessed the names, addresses, driver’s license numbers, passport numbers, dates of birth, phone numbers, and other employment information, according to a filing with the Maine Attorney General.

CISA orders govt agencies to patch bugs exploited by Russian hackers

23 June 2023
According to research by Insikt Group and CERT-UA, Russian hackers exploited vulnerabilities (CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026) in Roundcube Webmail software to gain unauthorized access to unpatched servers.

Chinese Hackers Targeted G7 Summit Through MS Office Flaw

23 June 2023
Suspected Chinese APT groups exploited a 17-year-old Microsoft Office vulnerability in May to launch malware attacks against foreign government officials who attended a G7 summit in Hiroshima, Japan.

NSA Releases Guide to Combat Powerful BlackLotus Bootkit Targeting Windows Systems

23 June 2023
The U.S. National Security Agency (NSA) on Thursday released guidance to help organizations detect and prevent infections of a Unified Extensible Firmware Interface (UEFI) bootkit called BlackLotus. To that end, the agency is recommending that "infrastructure owners take action by hardening user executable policies and monitoring the integrity of the boot partition." BlackLotus is an advanced 

NIST wants to help prevent a major cyberattack on the water sector

23 June 2023
The project is expected to feature a reference design and an implementation guide addressing four main cybersecurity challenges across the water and wastewater sector, namely asset management, data integrity, remote access, and network segmentation.

Military Satellite Access Sold on Russian Hacker Forum for $15,000

23 June 2023
Although the authenticity of these claims remains uncertain, the fact that the hacker is offering to use Escrow—a trusted third-party payment service—adds a level of credibility to the offer.

Camaro Dragon’s WispRider Malware Self-Propagates Through USB Flash Drives

23 June 2023
In addition to backdoor capabilities and the ability to propagate through USB using the HopperTick launcher, the payload includes additional features, such as a bypass for SmadAV, an anti-virus solution popular in Southeast Asia.

New Cryptocurrency Mining Campaign Targets Linux Systems and IoT Devices

23 June 2023
Internet-facing Linux systems and Internet of Things (IoT) devices are being targeted as part of a new campaign designed to illicitly mine cryptocurrency. "The threat actors behind the attack use a backdoor that deploys a wide array of tools and components such as rootkits and an IRC bot to steal device resources for mining operations," Microsoft threat intelligence researcher Rotem Sde-Or said.

SMS Phishers Harvested Phone Numbers, Shipment Data from UPS Tracking Tool

22 June 2023
The United Parcel Service (UPS) says fraudsters have been harvesting phone numbers and other information from its online shipment tracking tool in Canada to send highly targeted SMS phishing (a.k.a. "smishing") messages that spoofed UPS and other top brands. The missives addressed recipients by name, included details about recent orders, and warned that those orders wouldn't be shipped unless the customer paid an added delivery fee.

40% of IT workers admit to working 50+ hour weeks consecutively

22 June 2023
IT leaders were surveyed by Kaseya about IT operations and management. Forty-five percent of respondents prioritize the improvement of IT security.

GitHub Dataset Research Reveals Millions Potentially Vulnerable to RepoJacking

22 June 2023
RepoJacking is a security vulnerability that may lead to code execution on organizations' internal or customer environments. Millions of GitHub repositories are potentially vulnerable to it, including popular organizations such as Google and Lyft.

MULTI#STORM Campaign Targets India and U.S. with Remote Access Trojans

22 June 2023
A new phishing campaign codenamed MULTI#STORM has set its sights on India and the U.S. by leveraging JavaScript files to deliver remote access trojans on compromised systems. "The attack chain ends with the victim machine infected with multiple unique RAT (remote access trojan) malware instances, such as Warzone RAT and Quasar RAT," Securonix researchers Den Iuzvyk, Tim Peck, and Oleg Kolesnikov

UPS discloses data breach after exposed customer info used in SMS phishing

22 June 2023
Multinational shipping company UPS is alerting Canadian customers that some of their personal information might have been exposed via its online package look-up tools and abused in phishing attacks.