Latest Cybersecurity News and Articles


US Government Provides Guidance on Software Security Guarantee Requirements

14 June 2023
Per M-23-16, attestation for critical software should be obtained no later than three months after the CISA's M-22-18 attestation common form is approved by OMB under the Paperwork Reduction Act (PRA).

Massive Phishing Campaign Uses 6,000 Sites to Impersonate 100 Brands

14 June 2023
The brands impersonated include Nike, Puma, Asics, Vans, Adidas, Columbia, Superdry Converse, Casio, Timberland, Salomon, Crocs, Sketchers, The North Face, UGG, Guess, Caterpillar, New Balance, Fila, Doc Martens, Reebok, Tommy Hilfiger, and others.

RDP honeypot targeted 3.5 million times in brute-force attacks

14 June 2023
An experiment using high-interaction honeypots with an RDP connection accessible from the public web shows how relentless attackers are and that they operate within a daily schedule very much like working office hours.

Hoxhunt names Petri Kuivala as Chief Information Security Officer Advisor

14 June 2023
Hoxhunt has announced the appointment of Petri Kuivala as Chief Information Security Officer (CISO) Advisor. 

CISA Issues Directive Requiring FCEB Agencies to Mitigate the Risk From Internet-Exposed Management Interfaces

14 June 2023
Agencies must remove identified networked management interfaces from exposure to the internet or protect them with Zero-Trust capabilities that implement a policy enforcement point separate from the interface itself.

Software Supply Chain: The Golden Container Ship

14 June 2023
To secure the supply chain, companies need to have a process in place that allows them to quickly fix and deploy issues within their organization, such as having a set of known golden images.

VMware ESXi Zero-Day Used by Chinese Espionage Actor to Perform Privileged Guest Operations on Compromised Hosts

14 June 2023
Chinese cyber espionage group UNC3886 has been observed developing and deploying malware on systems such as network appliances, SAN arrays, and VMware ESXi hosts that do not generally support Endpoint Detection and Response (EDR) solutions.

New Golang-based Skuld Malware Stealing Discord and Browser Data from Windows PCs

14 June 2023
A new Golang-based information stealer called Skuld has compromised Windows systems across Europe, Southeast Asia, and the U.S. "This new malware strain tries to steal sensitive information from its victims," Trellix researcher Ernesto Fernández Provecho said in a Tuesday analysis. "To accomplish this task, it searches for data stored in applications such as Discord and web browsers; information

Incorporating cloud security teams into the SOC enhances operational efficiencies

14 June 2023
Security leaders are recognizing that cloud and the way cloud security teams work today are becoming increasingly critical to business and IT operations, according to Trend Micro.

Where from, Where to — The Evolution of Network Security

14 June 2023
For the better part of the 90s and early aughts, the sysadmin handbook said, "Filter your incoming traffic, not everyone is nice out there" (later coined by Gandalf as "You shall not pass"). So CIOs started to supercharge their network fences with every appliance they could get to protect against inbound (aka INGRESS) traffic. In the wake of the first mass phishing campaigns in the early 2010s,

Fake Researcher Profiles Spread Malware through GitHub Repositories as PoC Exploits

14 June 2023
At least half of dozen GitHub accounts from fake researchers associated with a fraudulent cybersecurity company have been observed pushing malicious repositories on the code hosting service. All seven repositories, which are still available as of writing, claim to be a proof-of-concept (PoC) exploit for purported zero-day flaws in Discord, Google Chrome, and Microsoft Exchange. VulnCheck, which

Office Open XML signatures are 'practically worthless'

14 June 2023
Office Open XML (OOXML) Signatures, an Ecma/ISO standard used in Microsoft Office applications and open source OnlyOffice, have several security flaws and can be easily spoofed.

Microsoft Releases Updates to Patch Critical Flaws in Windows and Other Software

14 June 2023
Of the 73 flaws, six are rated Critical, 63 are rated Important, two are rated Moderated, and one is rated Low in severity. This also includes three issues the tech giant addressed in its Chromium-based Edge browser.

Gozi malware hacker sentenced to three years in US prison

14 June 2023
Prosecutors said 39-year-old Mihai Ionut Paunescu helped run bulletproof hosting service PowerHost[.]ro, which helped cybercriminals distribute the Gozi Virus, the Zeus Trojan, the SpyEye Trojan, and the BlackEnergy malware.

UK doctors fear ID theft threat after S3 bucket leak

14 June 2023
A UK agency for freelance doctors has potentially exposed personal details relating to 3,200 individuals via unsecured S3 buckets, which one expert said could be used to launch ID theft attacks or blackmail.

Critical Security Vulnerability Discovered in WooCommerce Stripe Gateway Plugin

14 June 2023
A security flaw has been uncovered in the WooCommerce Stripe Gateway WordPress plugin that could lead to the unauthorized disclosure of sensitive information. The flaw, tracked as CVE-2023-34000, impacts versions 7.4.0 and below. It was addressed by the plugin maintainers in version 7.4.1, which shipped on May 30, 2023. WooCommerce Stripe Gateway allows e-commerce websites to directly accept

Ukraine police raid social media bot farm accused of pro-Russia propaganda

14 June 2023
Ukraine's Cyber Police have shut down a bot farm allegedly spreading disinformation on social media in an attempt to sway public opinion within the country about the Russia-Ukraine war.

Trilateration vulnerability spotted in WhosHere Plus dating app

14 June 2023
WhosHere Plus, a dating app that uses GPS data to connect users with similar interests, has been found to be vulnerable to trilateration, which could allow users' location data to be discovered with alarming accuracy.

Microsoft Releases Updates to Patch Critical Flaws in Windows and Other Software

14 June 2023
Microsoft has rolled out fixes for its Windows operating system and other software components to remediate major security shortcomings as part of Patch Tuesday updates for June 2023. Of the 73 flaws, six are rated Critical, 63 are rated Important, two are rated Moderated, and one is rated Low in severity. This also includes three issues the tech giant addressed in its Chromium-based Edge browser

Microsoft: Azure Portal outage was caused by traffic “spike”

14 June 2023
Microsoft revealed in an update to the Azure status page that the preliminary root cause behind an outage that impacted the Azure Portal worldwide on Friday was what it described as a traffic "spike."