Latest Cybersecurity News and Articles


University of Rochester, Nova Scotia first known MoveIT victims in North America

08 June 2023
The government of Nova Scotia and the University of Rochester are the first organizations in North America to confirm data theft as a result of the exploitation of a new vulnerability affecting popular file transfer tool MOVEit.

Enigma revives PUP labeling lawsuit against Malwarebytes

08 June 2023
The US Ninth Circuit Court of Appeals last week ruled that Enigma Software Group can pursue its long-standing complaint against rival security firm Malwarebytes for classifying its software as "potentially unwanted programs" or PUPs.

Zoom Expands Privacy Options for European Customers

08 June 2023
The key element is the option for European Economic Area (EEA) data storage. Paid customers will be able to specify certain data for meetings, webinars, and team chats to be stored within the EEA.

New PowerDrop Malware Targets U.S. Aerospace Industry

08 June 2023
The U.S. aerospace industry has recently been targeted by an unidentified threat actor leveraging a newly discovered malware that researchers named PowerDrop. Its sophisticated evasion techniques include deception, encoding, and encryption.  The company suggests conducting vulnerability scans on Windows systems and remaining vigilant for any unusual pinging activity.

Urgent Security Updates: Cisco and VMware Address Critical Vulnerabilities

08 June 2023
VMware has released security updates to fix a trio of flaws in Aria Operations for Networks that could result in information disclosure and remote code execution. The most critical of the three vulnerabilities is a command injection vulnerability tracked as CVE-2023-20887 (CVSS score: 9.8) that could allow a malicious actor with network access to achieve remote code execution. Also patched by

Kimsuky Targets Think Tanks and News Media with Social Engineering Attacks

08 June 2023
The North Korean nation-state threat actor known as Kimsuky has been linked to a social engineering campaign targeting experts in North Korean affairs with the goal of stealing Google credentials and delivering reconnaissance malware. "Further, Kimsuky's objective extends to the theft of subscription credentials from NK News," cybersecurity firm SentinelOne said in a report shared with The

Barracuda Urges Immediate Replacement of Hacked ESG Appliances

07 June 2023
Enterprise security company Barracuda is now urging customers who were impacted by a recently disclosed zero-day flaw in its Email Security Gateway (ESG) appliances to immediately replace them. "Impacted ESG appliances must be immediately replaced regardless of patch version level," the company said in an update, adding its "remediation recommendation at this time is full replacement of the

82% of security leaders believe cloud automation critical

07 June 2023
A recent survey from NetApp looks at how IT decision makers feel about the ways their organizations are working to optimize their environments.

Microsoft settles FTC charges for violating COPPA

07 June 2023
Following Federal Trade Commission (FTC) charges, Microsoft will bay $20 million to settle Children's Online Protection Act (COPPA) violations. 

Security leaders expected to expand threat management budgets

07 June 2023
To better navigate emerging risks and the current threat landscape, security leaders are expanding cybersecurity budgets to protect organizations. 

VMware fixes critical vulnerability in vRealize network analytics tool

07 June 2023
VMware issued multiple security patches today to address critical and high-severity vulnerabilities in VMware Aria Operations for Networks, allowing attackers to gain remote execution or access sensitive information.

US, Israel Provide Guidance on Securing Remote Access Software

07 June 2023
The Guide to Securing Remote Access Software (PDF) is authored by the CISA, the FBI, the NSA, the Multi-State Information Sharing and Analysis Center (MS-ISAC), and the Israel National Cyber Directorate (INCD).

Traditional malware increasingly takes advantage of ChatGPT for attacks

07 June 2023
“Between November 2022-April 2023, we noticed a 910% increase in monthly registrations for domains, both benign and malicious, related to ChatGPT,” according to the latest Network Threat Trends Research Report from Palo Alto Networks' Unit 42.

0mega ransomware gang changes tactics

07 June 2023
A number of ransomware gangs have stopped using malware to encrypt targets’ files and have switched to a data theft/extortion approach to get paid; 0mega – a low-profile and seemingly not very active threat actor – seems to be among them.

Verizon 2023 Data Breach Report shows rising cost of ransomware

07 June 2023
A new report reveals ransomware remains one of the top cyberattack methods making up 24% of all breaches.

Clop Ransomware Group Issues Extortion Notice to ‘Hundreds’ of Victims

07 June 2023
Potentially hundreds of companies globally are being extorted by the Clop ransomware group after it exploited a vulnerability in the file transfer tool MOVEit to break into computer networks around the world and steal sensitive information.

When adopting security tools, less is more, Gartner says

07 June 2023
Gartner analysts are calling for organizations to adopt a “minimum effective toolset” for enterprise security, using the fewest technologies required to observe, respond and defend against threats.

Public sector apps show higher rates of security flaws

07 June 2023
The research findings from Veracode come amid a flurry of recent initiatives by the federal government to strengthen cybersecurity, including efforts to reduce vulnerabilities in applications that perform critical government functions.

Microsoft to Pay $20 Million Penalty for Illegally Collecting Kids' Data on Xbox

07 June 2023
Microsoft has agreed to pay a penalty of $20 million to settle U.S. Federal Trade Commission (FTC) charges that the company illegally collected and retained the data of children who signed up to use its Xbox video game console without their parents' knowledge or consent. "Our proposed order makes it easier for parents to protect their children's privacy on Xbox, and limits what information

BA, Boots and BBC cyber-attack: who is behind it and what happens next?

07 June 2023
BA, Boots and BBC cyber-attack: who is behind it and what happens next? A cybercrime group has exploited a flaw in MOVEit software, and is now demanding a ransomBritish Airways, Boots and the BBC have been hit with an ultimatum to begin ransom negotiations from a cybercrime group after employees’ personal data was stolen in a hacking attack.On Wednesday it emerged that the gang behind a piece of ransomware known as Clop had posted the demand to its darkweb site, where stolen data is typically released if payments are not made by the victims. Continue reading...