Latest Cybersecurity News and Articles


Iowa’s Largest School District Confirms Ransomware Attack, Data Theft

20 June 2023
Following the January ransomware attack, the school district canceled all classes for several days starting January 10, after internet and network services were also taken offline during the incident's investigation.

Western Digital Blocks Unpatched Devices From Cloud Services

20 June 2023
The move, which began on June 15, comes one month after the company released firmware updates for its My Cloud product line to address multiple security defects, including a critical path traversal bug that leads to remote code execution (RCE).

Federal Authority Warns Health Sector of TimisoaraHackerTeam Threats

20 June 2023
Federal authorities are warning the healthcare sector of an apparent resurgence of TimisoaraHackerTeam threats after a recent attack by the "obscure" ransomware group on a U.S. cancer center.

Illinois hospital attributes closure to ransomware attack

20 June 2023
In what seems to be the first announcement of its kind, two rural healthcare facilities closed last week citing a ransomware attack as part of the reasons why.

Zyxel Releases Urgent Security Updates for Critical Vulnerability in NAS Devices

20 June 2023
Zyxel has rolled out security updates to address a critical pre-authentication command injection flaw in its network-attached storage (NAS) devices that could result in the execution of arbitrary commands on affected systems.

City of Fayetteville Dealing with Debilitating Cyberattack

20 June 2023
“The City of Fayetteville has experienced a suspected cyber incident, and most online/web-based municipal services have been taken offline as a proactive measure," the city said.

Zyxel Releases Urgent Security Updates for Critical Vulnerability in NAS Devices

20 June 2023
Zyxel has rolled out security updates to address a critical security flaw in its network-attached storage (NAS) devices that could result in the execution of arbitrary commands on affected systems. Tracked as CVE-2023-27992 (CVSS score: 9.8), the issue has been described as a pre-authentication command injection vulnerability. "The pre-authentication command injection vulnerability in some Zyxel

Security leaders discuss the spread of MOVEIt vulnerability

20 June 2023
It has been several weeks since the MOVEit vulnerability began making headlines, but the span of organizations and governmental entities being affected by related data breaches have continued to grow. 

SaaS in the Real World: How Global Food Chains Can Secure Their Digital Dish

20 June 2023
The Quick Serve Restaurant (QSR) industry is built on consistency and shared resources. National chains like McDonald's and regional ones like Cracker Barrel grow faster by reusing the same business model, decor, and menu, with little change from one location to the next.  QSR technology stacks mirror the consistency of the front end of each store. Despite each franchise being independently

Experts Uncover Year-Long Cyber Attack on IT Firm Utilizing Custom Malware RDStealer

20 June 2023
A highly targeted cyber attack against an East Asian IT company involved the deployment of a custom malware written in Golang called RDStealer. "The operation was active for more than a year with the end goal of compromising credentials and data exfiltration," Bitdefender security researcher Victor Vrabie said in a technical report shared with The Hacker News. Evidence gathered by the Romanian

Over 100,000 Stolen ChatGPT Account Credentials Sold on Dark Web Marketplaces

20 June 2023
The Asia-Pacific region experienced the highest number of compromised accounts, reaching approximately 41,000. In comparison, Europe had nearly 17,000 compromised accounts, while North America ranked fifth, reporting around 4,700 instances.

EU member states are urged to restrict without delay 5G equipment from risky suppliers

20 June 2023
The European Commission told member states to impose restrictions on high-risk suppliers for 5G networks without delay, with a specific focus on the dependency on high-risk suppliers, specifically Chinese firms Huawei and ZTE.

Update: Australia's NDIS Agency Scrambles Over Risk of Leaked Sensitive Client Information in HWL Ebsworth Hack

20 June 2023
The Australian agency responsible for the national disability insurance scheme is scrambling to learn whether sensitive client information related to appeal cases has been caught up in a large cybersecurity hack on the law firm HWL Ebsworth.

UK National Crime Agency Head Calls For Hacking Law Updates

20 June 2023
A British cyber law that criminalizes hacking and other intrusion activities is outdated, often hindering law enforcement action against cyber crooks, U.K. lawmakers heard during a parliamentary hearing on cybercrime.

Ireland: Almost 16,000 state job applicants informed of possible data breach

20 June 2023
An ‘administrative error’ led to 15,471 job candidates receiving a message that contained another person’s name and the list of roles that they wished to be notified about.

Emerging Romanian Hacking Group Diicot Steals Cryptocurrency

20 June 2023
Cado Security spotted the Romanian threat actor Diicot using Cayosin, a variant of Mirai, to launch DDoS and cryptojacking attacks in its latest campaign. The campaign is ongoing and targets OpenWrt routers.  It is claimed that the hacking group is evolving tactics to expand its attack scope.

ASUS urges customers to patch critical router vulnerabilities

20 June 2023
ASUS has released new firmware with cumulative security updates that address vulnerabilities in multiple router models, warning customers to immediately update their devices or restrict WAN access until they're secured.

ASUS Releases Patches to Fix Critical Security Bugs Impacting Multiple Router Models

20 June 2023
Taiwanese company ASUS on Monday released firmware updates to address, among other issues, nine security bugs impacting a wide range of router models. Of the nine security flaws, two are rated Critical and six are rated High in severity. One vulnerability is currently awaiting analysis. The list of impacted products are GT6, GT-AXE16000, GT-AX11000 PRO, GT-AXE11000, GT-AX6000, GT-AX11000,

Three cybersecurity actions that make a difference

20 June 2023
Organizations that closely align their cybersecurity programs to business objectives are 18% more likely to achieve target revenue growth and market share and improve customer satisfaction, as well as 26% more likely to lower the cost of breaches.

Over 100,000 Stolen ChatGPT Account Credentials Sold on Dark Web Marketplaces

20 June 2023
Over 100,000 compromised OpenAI ChatGPT account credentials have found their way on illicit dark web marketplaces between June 2022 and May 2023, with India alone accounting for 12,632 stolen credentials. The credentials were discovered within information stealer logs made available for sale on the cybercrime underground, Group-IB said in a report shared with The Hacker News. "The number of