Latest Cybersecurity News and Articles


May ransomware activity rises behind 8base, LockBit gangs

21 June 2023
LockBit was the most active group last month, but NCC Group researchers were surprised by 8base, which started listing victims from attacks that occurred beginning in April 2022.

US and European IT decision-makers have different cloud security priorities

21 June 2023
The growing adoption of cloud has elevated cloud security fear for IT teams, as they grapple with the challenges and concerns arising from the widespread use of complex cloud environments while diligently addressing them, according to SUSE.

New DOJ unit will focus on prosecuting nation-state cybercrime

21 June 2023
The decision to put cyber on equal footing with the division’s three existing sections comes as the DOJ has ramped up its own efforts to defeat botnets, contain or eliminate malware outbreaks and pursue digital criminals around the globe.

Report: One in Three UK and Ireland Workers Susceptible to Phishing

21 June 2023
The study by KnowBe4, which analyzed a dataset of over 12.5 million users across 35,681 organizations, revealed that 35.2% of users who had received no security training were prone to clicking on suspicious links or engaging in fraudulent actions.

36% of government IT does not have a documented disaster recovery plan

21 June 2023
The experience and habits of IT departments when it comes to ransomware and data recovery were analyzed in a recent report by Arcserve. 

Chinese APT15 Hackers Resurface with New Graphican Malware to Target Central and South America

21 June 2023
Graphican is notable for using Microsoft Graph API and OneDrive to stealthily obtain its C2 infrastructure addresses in encrypted form, giving it versatility and resistance against take-downs.

Organizations actively embrace zero trust, integration remains a hurdle

21 June 2023
IT teams have made security efforts and progress in zero-trust implementation strategies to establish a new sense of normalcy following the network upheaval caused by the start of the global pandemic.

New Report Exposes Operation Triangulation's Spyware Implant Targeting iOS Devices

21 June 2023
More details have emerged about the spyware implant that's delivered to iOS devices as part of a campaign called Operation Triangulation. Kaspersky, which discovered the operation after becoming one of the targets at the start of the year, said the malware has a lifespan of 30 days, after which it gets automatically uninstalled unless the time period is extended by the attackers. The Russian

Digital-first economy introduces unforeseen risks for 89% of CISOs

21 June 2023
A new survey shows CISOs struggle to cost justify security investments despite known security gaps, face increasing personal risks, and worry about the rapid adoption of AI.

3 in 4 people at risk of being hacked due to poor password practices

21 June 2023
A new report shows that 75% of people globally don’t adhere to widely-accepted password best practices with 64% either using weak passwords or repeat variations of passwords to protect their online accounts.

Russian APT28 Hackers Breach Ukrainian Government Email Servers

21 June 2023
A threat group tracked as APT28 and linked to Russia's General Staff Main Intelligence Directorate (GRU) has breached Roundcube email servers belonging to multiple Ukrainian organizations, including government entities.

Tsunami Botnet Found Targeting Unsecured Linux SSH Servers

21 June 2023
An unidentified cybercrime group was observed brute-forcing vulnerable Linux SSH servers to drop various malware strains, including the Tsunami DDoS bot. Tsunami, also known as Kaiten, is used by a multitude of threat actors as the source code of the botnet is publicly available. administrators are recommended to use passwords that are difficult to guess and change them periodically to prevent falling victim.

New Condi Malware Hijacking TP-Link Wi-Fi Routers for DDoS Botnet Attacks

21 June 2023
Condi, unlike some botnets which propagate by means of brute-force attacks, leverages a scanner module that checks for vulnerable TP-Link Archer AX21 devices and, if so, executes a shell script retrieved from a remote server to deposit the malware.

Startup Security Tactics: Friction Surveys

21 June 2023
When we do quarterly planning, my team categorizes our goals within four evergreen outcomes: Reduce the risk of information security incidents Increase trust in Vanta's information security program Reduce the friction caused by information security controls Use security expertise to support the business In this article, I'm going to focus on number three: reducing friction. Declaring your

Critical 'nOAuth' Flaw in Microsoft Azure AD Enabled Complete Account Takeover

21 June 2023
A security shortcoming in Microsoft Azure Active Directory (AD) Open Authorization (OAuth) process could have been exploited to achieve full account takeover, researchers said. California-based identity and access management service Descope, which discovered and reported the issue in April 2023, dubbed it nOAuth. "nOAuth is an authentication implementation flaw that can affect Microsoft Azure AD

Chinese Hacker Group 'Flea' Targets American Ministries with Graphican Backdoor

21 June 2023
Foreign affairs ministries in the Americas have been targeted by a Chinese state-sponsored actor named Flea as part of a recent campaign that spanned from late 2022 to early 2023. The cyber attacks, per Broadcom's Symantec, involved a new backdoor codenamed Graphican. Some of the other targets included a government finance department and a corporation that markets products in the Americas as

Parent Company of Norton, Avast, and AVG Says Employee Data Stolen in MOVEit Ransomware Attack

21 June 2023
Gen Digital, the company behind known cybersecurity brands such as Avast, Avira, AVG, Norton, and LifeLock, has confirmed that employee’s personal information was compromised in the recent MOVEit ransomware attack.

Cyware Announces Technology Partnership with Mimecast to Extend Cyber Fusion with Advanced Email Security

21 June 2023
Cyware, a leading provider of threat intelligence management and cyber fusion solutions, announced today a strategic technology partnership with Mimecast, an advanced email and collaboration security company.

Expensive Proxies Underpin Anonymous Sudan DDoS Attacks

21 June 2023
Pro-Russian hacker group Anonymous Sudan appears to use expensive online infrastructure to perpetuate distributed denial-of-service attacks, undermining its claim to be a volunteer group operating from an impoverished East African country.

Update: Hackers warn University of Manchester students’ of imminent data leak

21 June 2023
The threat actors claim to have stolen 7 TB of data from the University of Manchester during a June 6th cyberattack in an email sent to students and shared with BleepingComputer.