Latest Cybersecurity News and Articles
22 June 2023
The European Council agreed on Wednesday to seek to reduce the level of protections provided to journalists from government surveillance and spyware in a proposed law intended to safeguard media freedoms across the bloc.
22 June 2023
The Justice Department recently announced the creation of the new National Security Cyber Section — known as NatSec Cyber — within its National Security Division.
22 June 2023
Colorado joined several other U.S. states in announcing MOVEit breaches, with its Department of Health Care Policy & Financing confirming that it is in the process of investigating an incident involving the data of state residents.
22 June 2023
In remarks at a Wednesday press conference, PM Kishida announced a review of the My Number system and ordered the relevant department to make it a priority comparable with government responses to COVID-19.
22 June 2023
Why Data Exfiltration Detection is Paramount?
The world is witnessing an exponential rise in ransomware and data theft employed to extort companies. At the same time, the industry faces numerous critical vulnerabilities in database software and company websites. This evolution paints a dire picture of data exposure and exfiltration that every security leader and team is grappling with. This
22 June 2023
A critical security flaw has been disclosed in the WordPress "Abandoned Cart Lite for WooCommerce" plugin that's installed on more than 30,000 websites.
"This vulnerability makes it possible for an attacker to gain access to the accounts of users who have abandoned their carts, who are typically customers but can extend to other high-level users when the right conditions are met," Defiant's
22 June 2023
This includes a pair of zero-days that have been weaponized in a mobile surveillance campaign called Operation Triangulation which has been active since 2019. The exact threat actor behind the campaign is not known.
22 June 2023
Senators Richard Blumenthal and Marsha Blackburn have questioned TikTok's misleading assurances and cited reports of sensitive financial information of American creators being stored in China.
22 June 2023
On Tuesday, CISA published two ICS advisories to warn of vulnerabilities in Enphase products that could lead to information leaks or command execution. Both are said to be remotely exploitable with low attack complexity.
22 June 2023
The State Department's ambassador at large for cyberspace and digital policy, Nate Fick, has expressed his concerns about the dangers posed by artificial intelligence (AI), China, and the vulnerabilities present in internet infrastructure.
22 June 2023
Proof-of-concept exploit code is now available for a high-severity flaw in Cisco Secure Client Software for Windows (formerly AnyConnect Secure Mobility Client) that can let attackers elevate privileges to SYSTEM.
22 June 2023
The Legion hacktool, marketed in Telegram and in public groups and channels, harvests credentials from misconfigured web servers and use those credentials for email abuse, researchers at Cado Labs, who discovered Legion, said in a blog post.
22 June 2023
Apple on Wednesday released a slew of updates for iOS, iPadOS, macOS, watchOS, and Safari browser to address a set of flaws it said were actively exploited in the wild.
This includes a pair of zero-days that have been weaponized in a mobile surveillance campaign called Operation Triangulation that has been active since 2019. The exact threat actor behind the campaign is not known.
22 June 2023
Researchers took the wraps off of a year-long cyberattack campaign deploying a custom Golang malware called RDStealer. The malware strain focuses on stealing credentials and extracting data from compromised hosts. Not a coincidence but all the compromised machines were Dell-manufactured devices.
21 June 2023
Updated report from the NCSC highlights the key threats that the UK legal sector face and how to improve their cyber security.
21 June 2023
A recent survey looks at the biggest challenges facing IT leaders of large organizations and their approach to modernizing their IT department.
21 June 2023
If you operate a cybercrime business that relies on disseminating malicious software, you probably also spend a good deal of time trying to disguise or "crypt" your malware so that it appears benign to antivirus and security products. In fact, the process of "crypting" malware is sufficiently complex and time-consuming that most serious cybercrooks will outsource this critical function to a handful of trusted third parties. This story explores the history and identity behind Cryptor[.]biz, a long-running crypting service that is trusted by some of the biggest names in cybercrime.
21 June 2023
IT and cybersecurity professionals were surveyed on passwordless authentication and how it would impact their organizations' credential security.
21 June 2023
The first security defect, tracked as CVE-2023-2986 (CVSS score 9.8/10), impacts the Abandoned Cart Lite for WooCommerce, a plugin that notifies customers who did not complete the purchase process, and which has more than 30,000 active installations.
21 June 2023
The North Korean threat actor known as ScarCruft has been observed using an information-stealing malware with previous undocumented wiretapping features as well as a backdoor developed using Golang that exploits the Ably real-time messaging service.
"The threat actor sent their commands through the Golang backdoor that is using the Ably service," the AhnLab Security Emergency response Center (