Latest Cybersecurity News and Articles


US Agencies Publish Guidelines on Hardening Baseboard Management Controllers

16 June 2023
The joint guidance emphasizes the importance of taking proactive measures to secure and maintain BMCs effectively, adding that many organizations fail to implement even minimum security practices.

New Diicot Threat Group Targets SSH Servers with Brute-Force Malware

16 June 2023
Deploying Cayosin botnet, an off-the-shelf Mirai-based botnet agent to target routers running the Linux-based OS OpenWRT is a newly adopted tactic, indicating that the group changes its attack style after examining its targets.

75% of OT organizations had at least 1 intrusion in the last year

16 June 2023
A new report shows three-fourths of operational technology organizations reported at least one intrusion in the last year, with 56% from malware and 49% from phishing.

Proposed SEC cyber rules would benefit ‘overall health of the cybersecurity ecosystem,’ report says

16 June 2023
A report published Wednesday by the Atlantic Council’s Cyber Statecraft Initiative asserts that the SEC’s proposed rules — requiring incident disclosure within four days — substantially differ from CIRCIA regulations.

ChamelDoH: New Linux Backdoor Utilizing DNS-over-HTTPS Tunneling for Covert CnC

16 June 2023
The threat actor known as ChamelGang has been observed using a previously undocumented implant to backdoor Linux systems, marking a new expansion of the threat actor's capabilities. The malware, dubbed ChamelDoH by Stairwell, is a C++-based tool for communicating via DNS-over-HTTPS (DoH) tunneling. ChamelGang was first outed by Russian cybersecurity firm Positive Technologies in September 2021,

New Supply Chain Attack Exploits Abandoned AWS S3 Buckets to Distribute Malicious Binaries

16 June 2023
In what's a new kind of software supply chain attack aimed at open-source projects, it has emerged that threat actors could seize control of expired Amazon S3 buckets to serve rogue binaries without altering the modules themselves.

OT Security Firm Shift5 Adds $33 Million in Funding

16 June 2023
Arlington, VA-based OT security firm Shift5 has raised an additional $33 million in its Series B financing. $50 million was announced in February 2022. The total venture funding now stands at $108 million.

Real Estate Firm Hack Affects 319,500 Patients, Employees

16 June 2023
A commercial real estate company that operates over a dozen addiction recovery centers and other medical facilities is notifying 319,500 patients and employees of a recent ransomware incident that compromised their personal and health information.

Cybercriminals return to business as usual in a post-pandemic world

16 June 2023
Cloud threats have become ubiquitous, with 94% of cloud tenants targeted every month and brute-force attacks increasing from 40 million to nearly 200 million in early 2023, according to Proofpoint.

Barracuda Zero-Day Attacks Attributed to Chinese Cyberespionage Group

16 June 2023
The zero-day leveraged in the campaign, tracked as CVE-2023-2868, impacts Barracuda Email Security Gateway (ESG), specifically a module designed for the initial screening of email attachments.

New FCC privacy task force takes aim at data breaches, SIM-swaps

16 June 2023
The Federal Communications Commission will launch its first-ever privacy and data protection task force to crack down on SIM swapping and address broader data privacy concerns, Chairwoman Jessica Rosenworcel announced on Wednesday.

Oil and Gas Giant Shell Confirms it was Impacted by Cl0p Ransomware Attack

16 June 2023
Shell confirmed on Thursday it had been impacted by the Clop ransomware gang’s breach of the MOVEit file transfer tool after the group listed the British oil and gas multinational on its extortion site.

New ChromeLoader Variant Pushed via Fake Websites

16 June 2023
Researchers came across the Shampoo malware campaign that uses a malicious browser extension from the ChromeLoader family to gather sensitive personal information and inject advertisements into victims' browsing sessions. The new version of the ChromeLoader extension includes many anti-debugging and anti-analysis techniques to make detection challenging.

Activities in the Cybercrime Underground Require a New Approach to Cybersecurity

16 June 2023
As Threat Actors Continuously Adapt their TTPs in Today’s Threat Landscape, So Must You Earlier this year, threat researchers at Cybersixgill released the annual report, The State of the Cybercrime Underground. The research stems from an analysis of Cybersixgill's collected intelligence items throughout 2022, gathered from the deep, dark and clear web. The report examines the continuous

Unreleased Music Stolen and Sold on Dark Web: Hacker Fined

16 June 2023
In a significant development for IP crime, a court has granted a confiscation order against a hacker who was previously jailed for stealing unreleased music owned by Ed Sheeran and Lil Uzi Vert and selling it on the dark web.

Lawmakers suggest ‘radical transparency’ as key to shoring up US cyber posture

16 June 2023
A bipartisan pair of lawmakers Monday suggested the model Ukraine is employing to combat Russian hacking may be useful for U.S. industry and government agencies if laid out properly.

Ransomware Hackers and Scammers Utilizing Cloud Mining to Launder Cryptocurrency

16 June 2023
"Cryptocurrency mining is a crucial part of our industry, but it also holds special appeal to bad actors, as it provides a means to acquire money with a totally clean on-chain original source," blockchain analytics firm Chainalysis said.

Russian national arrested in Arizona, charged for alleged role in LockBit ransomware attacks

16 June 2023
Federal law enforcement officials arrested a Russian national in Arizona on charges related to his participation in multiple LockBit ransomware attacks against victims in the U.S., Asia, Europe and Africa, the Department of Justice said Thursday.

New Report Reveals Shuckworm's Long-Running Intrusions on Ukrainian Organizations

16 June 2023
The cyberespionage activities consist of spear-phishing campaigns that are designed to entice victims into opening booby-trapped attachments, which ultimately lead to the deployment of stealers such as Giddome, Pterodo, GammaLoad, and GammaSteel.

20-Year-Old Russian LockBit Ransomware Affiliate Arrested in Arizona

16 June 2023
The U.S. Department of Justice (DoJ) on Thursday unveiled charges against a Russian national for his alleged involvement in deploying LockBit ransomware to targets in the U.S., Asia, Europe, and Africa. Ruslan Magomedovich Astamirov, 20, of Chechen Republic has been accused of perpetrating at least five attacks between August 2020 and March 2023. He was arrested in the state of Arizona last