Latest Cybersecurity News and Articles


Polish authorities crack down on DDoS-for-hire service active since 2013

19 June 2023
Polish police officers of the country's Central Bureau for Combating Cybercrime detained two suspects believed to have been involved in operating a DDoS-for-hire service (aka booter or stresser) active since at least 2013.

US Navy, NATO, and NASA are using a shady Chinese company’s encryption chips

19 June 2023
Due to the complexity of the hardware supply chain, encryption chips sold by the subsidiary of a company flagged in the Entity List have found their way into the storage hardware of military and intelligence networks across the West.

State-Backed Hackers Employ Advanced Methods to Target Middle Eastern and African Governments

19 June 2023
Governmental entities in the Middle East and Africa have been at the receiving end of sustained cyber-espionage attacks that leverage never-before-seen and rare credential theft and Exchange email exfiltration techniques. "The main goal of the attacks was to obtain highly confidential and sensitive information, specifically related to politicians, military activities, and ministries of foreign

New Study Takes a Deep Dive Into Lookalike Attacks

19 June 2023
Cyberattacks using malicious lookalike domains, email addresses, and other types of registered identifiers are rising, domain name system (DNS) security provider Infoblox found.

Update: Microsoft admits DDOS as cause of recent cloud outages

19 June 2023
The Associated Press reported that in response to its inquiries about the cause of the outage, Microsoft admitted that Anonymous Sudan and DDoS orchestrated by the group were the cause of the outages.

Genetic testing firm accused by FTC of violating customers’ privacy

19 June 2023
The Federal Trade Commission is accusing the genetic testing firm 1Health.io of allegedly failing to secure customers’ genetic and health data and for duping them about the potential for getting their data erased.

Microsoft Blames Massive DDoS Attack for Azure, Outlook, and OneDrive Disruptions

19 June 2023
Microsoft on Friday attributed a string of service outages aimed at Azure, Outlook, and OneDrive earlier this month to an uncategorized cluster it tracks under the name Storm-1359. "These attacks likely rely on access to multiple virtual private servers (VPS) in conjunction with rented cloud infrastructure, open proxies, and DDoS tools," the tech giant said in a post on Friday. Storm-#### (

Cybersecurity culture improves despite the dark clouds of the past year

19 June 2023
While not directly linked, the disparity between falling material breaches and incidents and overall security postures might partly be explained by the positive cultural gains that CISOs have observed.

Update: Reddit hackers threaten to leak data stolen in February breach

19 June 2023
In a "Reddit Files" post on the BlackCat ransomware gang's data leak site, the threat actors claim to have stolen 80 GB of compressed data from the company during the February 5th attack and now plan on leaking the data.

Millions of Oregon, Louisiana state IDs stolen in MOVEit breach

17 June 2023
According to press releases by the Louisiana Office of Motor Vehicles and the Oregon Driver & Motor Vehicle Services, both agencies used the MOVEit Transfer software, which was breached during these attacks.

A simple bug exposed access to thousands of smart security alarm systems

17 June 2023
U.S. power and electronics giant Eaton has fixed a security vulnerability that allowed a security researcher to remotely access thousands of smart security alarm systems.

From Cryptojacking to DDoS Attacks: Diicot Expands Tactics with Cayosin Botnet

17 June 2023
Cybersecurity researchers have discovered previously undocumented payloads associated with a Romanian threat actor named Diicot, revealing its potential for launching distributed denial-of-service (DDoS) attacks. "The Diicot name is significant, as it's also the name of the Romanian organized crime and anti-terrorism policing unit," Cado Security said in a technical report. "In addition,

Third MOVEit bug fixed a day after PoC exploit made public

17 June 2023
Details of the latest vulnerability, tracked as CVE-2023-35708, were made public Thursday; proof-of-concept (PoC) exploit for the flaw, now fixed today, also emerged on Thursday. Progress Software issued a fix for it on Friday.

Gurvinder Rekhi named VP and CIO at the University of Dayton

16 June 2023
Gurvinder Rekhi was hired as the University of Dayton VP and CIO. Rekhi joins the university with more than 25 years of IT and leadership experience.

Rhysida ransomware leaks documents stolen from Chilean Army

16 June 2023
The Rhysida ransomware gang has now published 30% of all the data they claim to have stolen from the Chilean Army's network after initially adding it to their data leak site and claiming the attack.

FTC charges genetic testing organization for privacy concerns

16 June 2023
Genetic testing firm 1Health has been charged by the Federal Trade Commission (FTC) for leaving personal genetic and health data unsecured. 

Clop ransomware gang starts extorting MOVEit data-theft victims

16 June 2023
The Clop ransomware gang has started extorting companies impacted by the MOVEit data theft attacks, first listing the company's names on a data leak site—an often-employed tactic before public disclosure of stolen information

MOVEit Transfer customers warned of new flaw as PoC info surfaces

16 June 2023
Until security updates are released for affected MOVEit Transfer versions, Progress "strongly" recommends modifying firewall rules to deny HTTP and HTTPs traffic to MOVEit Transfer on ports 80 and 443 as a temporary workaround.

Balada Injector Campaign Hacks WordPress Sites Using Unpatched Plugins

16 June 2023
Balada leverages functions written in the Go language to spread itself and maintain persistence by executing a series of attacks, cross-site infections, and installation of backdoors.

Two Energy Department Entities Breached as Part of Massive MOVEit Transfer Compromise

16 June 2023
Multiple federal agencies, including two Department of Energy entities, were victims of a cyberattack that resulted from a widespread vulnerability in MOVEit file transfer software, federal officials said Thursday.