Latest Cybersecurity News and Articles


42% of IT professionals aren't fully prepared for AI

14 June 2023
According to a survey, 42% if IT leaders believe existing IT infrastructure is not fully prepared for the demands of AI, despite widespread adoption.

42% if IT professionals aren't fully prepared for AI

14 June 2023
According to a survey, 42% if IT leaders believe existing IT infrastructure is not fully prepared for the demands of AI, despite widespread adoption.

WordPress Stripe payment plugin bug leaks customer order details

14 June 2023
Security analysts at Patchstack have discovered that the popular plugin is vulnerable to CVE-2023-34000, an unauthenticated insecure direct object reference (IDOR) flaw that could expose sensitive details to attackers.

ICS Patch Tuesday: Siemens Addresses Over 180 Third-Party Component Vulnerabilities

14 June 2023
Siemens has released a dozen new advisories covering roughly 200 vulnerabilities, with a majority of these flaws impacting third-party components. Schneider Electric has released four advisories covering five vulnerabilities.

Chinese Hackers Exploit VMware Zero-Day to Backdoor Windows and Linux Systems

14 June 2023
The Chinese state-sponsored group known as UNC3886 has been found to exploit a zero-day flaw in VMware ESXi hosts to backdoor Windows and Linux systems. The VMware Tools authentication bypass vulnerability, tracked as CVE-2023-20867 (CVSS score: 3.9), "enabled the execution of privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs without authentication of guest credentials

Deep dive into the Pikabot cyber threat

14 June 2023
Pikabot operates as a backdoor, enabling remote access to compromised systems, and receives commands from a C2 server. It uses anti-analysis techniques and deploys an injector to run tests before injecting its core module into a specified process.

Lack of trust reported as top security challenge

14 June 2023
Security leader's trust in an organization and their employees' ability to prevent a cyberattack was analyzed in a recent report by Kroll. 

New PikaBot Trojan Executes Diverse Range of Commands

14 June 2023
Researchers have dissected a new modular malware trojan, dubbed Pikabot, that can execute a diverse range of malicious commands. The trojan self-terminates if the system’s language is Georgian, Kazakh, Uzbek, or Tajik. To stay safe, organizations must deploy the necessary detection tools to root out malware in the initial stage.

Over 181,000 Patients' Records at Pennsylvania Cardiology Group Breached

14 June 2023
The breach of the cardiology group first occurred on Feb 2 in data maintained by Commonwealth Health Physician Network-Cardiology, aka Great Valley Cardiology (GVC). The breach wasn't discovered until April 13, the system said in a news release.

Managing MDM threats to protect an organization

14 June 2023
This episode of The Security Podcasts focuses on MDM threats and features AJ Nash, VP and Distinguished Fellow of Intelligence at ZeroFox.  

France accuses Russians of impersonating French government and media to spread disinformation

14 June 2023
The campaign impersonated four of France's most popular daily newspapers — 20 Minutes, Le Monde, Le Parisien, and Le Figaro — publishing “at least 58 articles” on the fake sites to push these false narratives, according to VIGINIUM.

BatCloak: Obfuscation Solution Outwitting 80% of AV Engines

14 June 2023
Trend Micro cautioned about the utilization of BatCloak, a tool designed to obfuscate batch files and evade antivirus detection engines with an 80% success rate. This ongoing research showcases the continuous evolution of the BatCloak engine, aiming to achieve compatibility with a wide range of malware families. This serves as evidence of the prevalence of this technique in the contemporary threat landscape.

Pirated Windows 10 ISOs Install Clipper Malware via EFI Partitions

14 June 2023
Hackers are distributing Windows 10 using torrents that hide cryptocurrency hijackers in the Extensible Firmware Interface (EFI) partition. Since standard antivirus tools do not scan the EFI partition, the malware can potentially bypass detections.

Thales to Buy Tesserent for $119.1M to Aid Australian Growth

14 June 2023
A French conglomerate plans to purchase Australia's largest publicly traded cybersecurity company to expand its cyber service delivery capability in the high-growth Oceania market.

New Research Shows Potential of Electromagnetic Fault Injection Attacks Against Drones

14 June 2023
New research shows the potential of electromagnetic fault injection (EMFI) attacks against unmanned aerial vehicles, with experts showing how drones that don’t have any known vulnerabilities could be hacked.

Severe Vulnerabilities Reported in Microsoft Azure Bastion and Container Registry

14 June 2023
Two "dangerous" security vulnerabilities have been disclosed in Microsoft Azure Bastion and Azure Container Registry that could have been exploited to carry out cross-site scripting (XSS) attacks. "The vulnerabilities allowed unauthorized access to the victim's session within the compromised Azure service iframe, which can lead to severe consequences, including unauthorized data access,

Apple's Safari Private Browsing Now Automatically Removes Tracking Parameters in URLs

14 June 2023
"Advanced tracking and fingerprinting protections go even further to help prevent websites from using the latest techniques to track or identify a user's device," Apple said.

Microsoft: Windows 10 21H2 has reached end of servicing

14 June 2023
Since Windows 10 21H2 (aka Windows 10 November 2021 Update) will no longer receive security updates, customers are advised to upgrade to the latest release to avoid exposing their systems to attacks exploiting unpatched security vulnerabilities.

State-Owned Bank in South Africa Confirms Akira Ransomware Attack

14 June 2023
The Development Bank of Southern Africa said Monday that it was hit with a ransomware attack, adding that servers, log files, and documents were encrypted by the Akira gang last month.

US Government Provides Guidance on Software Security Guarantee Requirements

14 June 2023
Per M-23-16, attestation for critical software should be obtained no later than three months after the CISA's M-22-18 attestation common form is approved by OMB under the Paperwork Reduction Act (PRA).