Latest Cybersecurity News and Articles


FTC charges Amazon for keeping children's voice recordings

08 June 2023
Amazon will be required to overhaul how it deletes data and implement new privacy guidelines following FTC and Department of Justice charges.

Ascension Seton Reports Data Breach of Two Websites Impacting User Information

08 June 2023
Ascension Seton said it did not have specific details about what information had been affected but that some users’ personal details, such as name, address, SSNs, credit card numbers, and insurance information may be at risk.

Clop Ransomware Gang Likely Exploiting MOVEit Transfer Vulnerability Since 2021

08 June 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have published a joint advisory regarding the active exploitation of a recently disclosed critical flaw in Progress Software's MOVEit Transfer application to drop ransomware. "The Cl0p Ransomware Gang, also known as TA505, reportedly began exploiting a previously unknown SQL injection

Cyber unicorn Snyk acquiring Israeli startup Enso Security for over $50 million

08 June 2023
Snyk said it plans to leverage Enso’s Application Security Posture Management (ASPM) solution to offer a developer security platform providing a holistic view of application security posture.

New Fractureiser Malware Used CurseForge Minecraft Mods to Infect Windows, Linux

08 June 2023
Hackers used the popular Minecraft modding platforms Bukkit and CurseForge to distribute a new 'Fractureiser' information-stealing malware through uploaded modifications and by injecting malicious code into existing projects.

Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions

08 June 2023
Cisco on Wednesday announced patches for a critical vulnerability in its Expressway series and TelePresence Video Communication Server (VCS) enterprise collaboration and video communication solutions.

BBC and other organizations targeted in recent MOVEit vulnerability

08 June 2023
Organizations from around the world, including the BBC and British Airways, have been warned that stolen data will be published if demands aren’t met in a recent hack.

Kimsuky's Hack: Targeting North Korean Affairs for Intel

08 June 2023
SentinelOne identified the North Korean Kimsuky group targeting experts in North Korean affairs and media to gather intelligence and steal subscription information for news outlets reporting on the country's affairs. These actions likely contribute to its broader goal of gathering strategic intelligence and influencing North Korea's decision-making processes.

Zipper Manufacturing Giant YKK Confirms Cyberattack Targeted its U.S. Networks

08 June 2023
“There is no evidence that personal or financial information or intellectual property was compromised," Jessica Kennett Cork, VP of corporate communications at YKK Corporation of America said.

Biden taps Senate Intel Committee staff director to lead NCSC

08 June 2023
The president announced on Wednesday that he would nominate Michael Casey, a longtime Democratic staff director for the Senate Intelligence Committee, to be director of the National Counterintelligence and Security Center (NCSC).

Japanese Pharmaceutical Giant Eisai Suffers Ransomware Attack

08 June 2023
The attack has affected servers both within and outside Japan and resulted in some of the group’s IT functions, including logistics systems, being taken offline. There’s no clear indication yet whether sensitive data has been leaked.

How to Improve Your API Security Posture

08 June 2023
APIs, more formally known as application programming interfaces, empower apps and microservices to communicate and share data. However, this level of connectivity doesn't come without major risks. Hackers can exploit vulnerabilities in APIs to gain unauthorized access to sensitive data or even take control of the entire system. Therefore, it's essential to have a robust API security posture to

Dallas in the homestretch of ransomware attack recovery

08 June 2023
Most of Dallas’ network and IT infrastructure has been restored following a ransomware attack in early May that took most of the city’s services offline and disrupted operations, the city said Monday.

Update: Barracuda Urges Customers to Replace Hacked Email Security Appliances

08 June 2023
“If you have not replaced your appliance after receiving notice in your UI, contact support now,” Barracuda said. “Barracuda’s remediation recommendation at this time is full replacement of the impacted ESG.”

How to make developers love security

08 June 2023
Lack of business context, unclear prioritization, disputes over ownership and responsibility, long feedback loops, and insufficient ability to make change are some of the top issues inhibiting successful developer-security collaboration.

US government's TikTok ban extended to include contractors

08 June 2023
The rule would apply to all contracts, even those below the "simplified acquisition threshold" of $250,000, purchases of commercial and off-the-shelf equipment, and commercial services.

High-risk vulnerabilities patched in ABB Aspect building management system

08 June 2023
The two vulnerabilities affect versions before 3.07.01 and could result in remote code execution (RCE), and privilege escalation within the Aspect Control Engine software, potentially giving an attacker complete control over the BMS.

OneDrive to Enum Them All

08 June 2023
OneDrive can be used for user enumeration as it creates a unique URL for each user that is tied to their Azure/M365 account. This is possible because OneDrive doesn't require a login attempt, is completely silent, and there's no rate-limiting.

Service Rents Email Addresses for Account Signups – Krebs on Security

08 June 2023
Kopeechka is offering to help cybercriminals cut costs associated with large-scale spam and account creation campaigns by paying people to sell their email credentials and allowing customers to rent access to established accounts at major providers.

Outpost24 Acquires External Attack Surface Management Provider Sweepatic to Reduce Risk Exposure of Internet-Facing Assets

08 June 2023
Outpost24, a leading cybersecurity risk management platform, announced the acquisition of Sweepatic. Based in Leuven (BE), Sweepatic is an innovative external attack surface management (EASM) platform.