Latest Cybersecurity News and Articles


Update: Have I Been Pwned warns of new Zacks data breach impacting 8 million

13 June 2023
Zacks Investment Research (Zacks) has reportedly suffered an older, previously undisclosed data breach impacting 8.8 million customers, with the database now shared on a hacking forum.

Critical FortiOS and FortiProxy Vulnerability Likely Exploited - Patch Now!

13 June 2023
The vulnerability, tracked as CVE-2023-27997, concerns a heap-based buffer overflow vulnerability in FortiOS and FortiProxy SSL-VPN that could allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.

Cyberattack on German University HS Kaiserslautern Takes ‘Entire IT Infrastructure’ Offline

13 June 2023
The Kaiserslautern University of Applied Sciences (HS Kaiserslautern) has become the latest German-speaking university to be hit by a ransomware attack, following incidents affecting at least half a dozen similar institutions in recent months.

Intellihartx Notifies 490,000 Patients of GoAnywhere-Related Data Breach

13 June 2023
The affected information, the company says, includes names, addresses, insurance data and medical billing, diagnosis and medication information, birth dates, and Social Security numbers.

The multiplying impact of BEC attacks

13 June 2023
The 2023 Verizon Data Breach Investigations Report (DBIR) has confirmed what the FBI’s Internet Crime Complaint Center has pointed out earlier this year: BEC scammers are ramping up their social engineering efforts to great success.

Illinois and Minnesota Government Departments Hit by MOVEit Transfer Breaches

13 June 2023
The latest victims to come forward are government organizations: the Illinois Department of Innovation & Technology (DoIT) and the Minnesota Department of Education (MDE).

Webinar - Mastering API Security: Understanding Your True Attack Surface

13 June 2023
Believe it or not, your attack surface is expanding faster than you realize. How? APIs, of course! More formally known as application programming interfaces, API calls are growing twice as fast as HTML traffic, making APIs an ideal candidate for new security solutions aimed at protecting customer data, according to Cloudflare. According to the "Quantifying the Cost of API Insecurity" report, US

Two Russian Nationals Charged for Masterminding Mt. Gox Crypto Exchange Hack

13 June 2023
The U.S. Department of Justice (DoJ) has charged two Russian nationals in connection with masterminding the 2014 digital heist of the now-defunct cryptocurrency exchange Mt. Gox. According to unsealed indictments released last week, Alexey Bilyuchenko, 43, and Aleksandr Verner, 29, have been accused of conspiring to launder approximately 647,000 bitcoins stolen from September 2011 through at

Confidential data downloaded from UK regulator Ofcom in cyberattack

13 June 2023
Britain’s communications regulator Ofcom announced on Monday that confidential information that it held on companies it regulates was downloaded by hackers exploiting a vulnerability in the MOVEit file transfer tool.

Turkish Citizens’ Personal Data Offered Online After Government Site Hacked

13 June 2023
In a major digital security breach, a website is offering personal data about Turkish citizens, including President Recep Tayyip Erdogan, that appears to have been stolen by hackers from a government services website.

LatAm and Asia Face Growing Attacks, Report Warns

13 June 2023
Orange Cyberdefense published its Cy-Xplorer 2023 report noting that cyber extortion groups have shifted their focus from North America and Europe to Latin America. While cyber extortion victims were identified across 96 countries, certain regions witnessed a rise in popularity among threat actors throughout 2022. Cyber extortion is a problem that businesses cannot effectively address in isolation.

Microsoft Warns of AitM Phishing Attacks Against Financial Organizations

13 June 2023
A newly discovered multi-stage AitM phishing and BEC attack campaign has been targeting banking and financial organizations. The phishing kit enabled the attackers to send out more than 16,000 emails to a target’s contacts as part of the second-stage phishing campaign. To remediate the issue, it is recommended to reset the passwords for compromised users.

Critical FortiOS and FortiProxy Vulnerability Likely Exploited - Patch Now!

13 June 2023
Fortinet on Monday disclosed that a newly patched critical flaw impacting FortiOS and FortiProxy may have been "exploited in a limited number of cases" in attacks targeting government, manufacturing, and critical infrastructure sectors. The vulnerability, tracked as CVE-2023-27997 (CVSS score: 9.2), concerns a heap-based buffer overflow vulnerability in FortiOS and FortiProxy SSL-VPN that could

Bank fraud warnings are the most common text scam

12 June 2023
According to research by the Federal Trade Commission, the most common form of text message scam reported to the FTC were false bank fraud warnings.

Swiss Government Websites Face Outage After Being Targeted by Pro-Russian Threat Actor

12 June 2023
The websites of several Swiss federal agencies and state-linked companies were inaccessible on Monday, June 12, 2023, due to a cyberattack, Switzerland’s finance ministry has confirmed.

Use of multi-factor authentication nearly doubles since 2020

12 June 2023
A new report reveals the use of MFA has nearly doubled since 2020 and that phishing-resistant authenticators represent the best choice in terms of security for users.

Researchers Uncover Publisher Spoofing Bug in Microsoft Visual Studio Installer

12 June 2023
Security researchers have warned about an "easily exploitable" flaw in the Microsoft Visual Studio installer that could be abused by a malicious actor to impersonate a legitimate publisher and distribute malicious extensions. "A threat actor could impersonate a popular publisher and issue a malicious extension to compromise a targeted system," Varonis researcher Dolev Taler said. "Malicious

New SPECTRALVIPER Backdoor Targeting Vietnamese Public Companies

12 June 2023
SPECTRALVIPER is designed to contact an attacker-controlled server and awaits further commands while also adopting obfuscation methods like control flow flattening to resist analysis.

Factors influencing IT security spending

12 June 2023
Security executives are overwhelmingly craving more AI solutions in 2023 to help them battle the growing cybersecurity threat landscape, according to a report by Netrix Global.

Pink Drainer Group Impersonates Journalists to Steal Millions via Twitter and Discord

12 June 2023
Scam Sniffer used blockchain analysis to detect the Pink Drainer hacking group, which it said has now stolen over $3 million from more than 2000 victims, some of which are said to be high-profile individuals such as OpenAI CTO Mira Murati.