Latest Cybersecurity News and Articles
15 June 2023
The US CISA, UK NCSC, and their Australian, New Zealand, Canadian, French, and German equivalents penned the document after warning of the continued threat posed by the collective.
15 June 2023
The Swedish Authority for Privacy Protection, or IMY, on Tuesday, imposed a fine of 58 million Swedish kroner (~$5.4 million) in a statement saying Spotify should be more specific about how and for which purposes it collects individuals' data.
15 June 2023
GitLab Inc., has recently announced the appointment of Josh Lemos as Chief Information Security Officer (CISO).
15 June 2023
The revolutionary technology of GenAI tools, such as ChatGPT, has brought significant risks to organizations' sensitive data. But what do we really know about this risk? A new research by Browser Security company LayerX sheds light on the scope and nature of these risks. The report titled "Revealing the True GenAI Data Exposure Risk" provides crucial insights for data protection stakeholders and
15 June 2023
In what's a new kind of software supply chain attack aimed at open source projects, it has emerged that threat actors could seize control of expired Amazon S3 buckets to serve rogue binaries without altering the modules themselves.
"Malicious binaries steal the user IDs, passwords, local machine environment variables, and local host name, and then exfiltrates the stolen data to the hijacked
15 June 2023
A phishing operation was discovered impersonating WannaCry ransomware (WannaCry 3.0) and targeting Russian-speaking gamers. The phishing page mimics the official Enlisted Game website to spread infection. The ransomware is in fact a customized edition of an open-source ransomware tool called Crypter. This variant was specifically developed for Windows systems and was written in Python.
15 June 2023
HP's analysts report that in the campaign that started in March 2023, ChromeLoader is distributed via a network of malicious websites that promise free downloads of copyrighted music, movies, or video games.
15 June 2023
The tension between difficult economic conditions and the pace of technology innovation, including the evolution of AI, is influencing the growth of identity-led cybersecurity exposure, according to CyberArk.
15 June 2023
The ransomware bundled with the game installer pretends to be the third major version of the notorious WannaCry, even using the '.wncry' file extension on encrypted files.
15 June 2023
The seed funding was led by global cybersecurity specialist investor Ten Eleven Ventures. “Our unique ability lies in knowing the attacker’s TTPs – what they are doing to prepare for an attack or campaign,” said Ken Bagnall, CEO of Silent Push.
15 June 2023
The flaws, which exploited a weakness in the postMessage iframe, could have exposed Azure users to potential security breaches. The vulnerabilities were found in Azure Bastion and Azure Container Registry.
15 June 2023
The Russian threat actor known as Shuckworm has continued its cyber assault spree against Ukrainian entities in a bid to steal sensitive information from compromised environments.
Targets of the recent intrusions, which began in February/March 2023, include security services, military, and government organizations, Symantec said in a new report shared with The Hacker News.
"In some cases, the
15 June 2023
The Earth Preta APT group has expanded its targets to different regions and is using new arrival vectors such as MIROGO and QMAGENT. TONEDROP is a new dropper used by the group that drops the TONEINS and TONESHELL pieces of malware.
15 June 2023
Skuld, which shares overlaps with publicly available stealers like Creal Stealer, Luna Grabber, and BlackCap Grabber, is the handiwork of a developer who goes by the online alias Deathined on platforms like GitHub, Twitter, Reddit, and Tumblr.
15 June 2023
The ‘low and minimal risk’ AI tools will not be regulated, while the ‘limited risk’ ones will need to be transparent. The ‘high-risk’ AI practices, however, will be strictly regulated.
15 June 2023
Microsoft on Wednesday took the lid off a "novel and distinct Russian threat actor," which it said is linked to the General Staff Main Intelligence Directorate (GRU) and has a "relatively low success rate."
The tech giant's Threat Intelligence team, which was previously tracking the group under its emerging moniker DEV-0586, has graduated it to a named actor dubbed Cadet Blizzard.
"Cadet
15 June 2023
What makes the CVE-2023-32019 patch stand out from other security updates issued as part of the June 2023 Patch Tuesday is that it's disabled by default, even after applying this week's updates.
15 June 2023
Threat actors continued to evolve their tactics to sidestep user defenses in 2022, with multi-factor authentication (MFA) bypass kits accounting for millions of phishing messages, according to Proofpoint.
15 June 2023
At least half a dozen GitHub accounts from fake researchers associated with a fraudulent cybersecurity company have been observed pushing malicious repositories on the code hosting service.
15 June 2023
The threat actors behind the LockBit ransomware-as-a-service (RaaS) scheme have extorted $91 million following hundreds of attacks against numerous U.S. organizations since 2020.
That's according to a joint bulletin published by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), the Multi-State Information Sharing and Analysis Center (MS-ISAC