Latest Cybersecurity News and Articles


White House critical infrastructure protection order is ‘outdated’ and needs rethinking, Cyberspace Solarium Commission says

07 June 2023
The document — 2013’s Presidential Policy Directive 21, or PPD-21 — established which agencies were responsible for steering protection of each of the 16 critical infrastructure sectors, today known as sector risk management agencies (SRMAs).

Ukraine Warns Against Cyberespionage Campaign Planting LonePage Malware on Targeted Systems

07 June 2023
Volodymyr Kondrashov, spokesperson for Ukraine's State Service of Special Communications and Information Protection tweeted Tuesday the campaign targets Microsoft Windows machines used by government agencies and media organizations.

CVEs Surge By 25% in 2022 to Another Record High

07 June 2023
The number of new vulnerabilities reported by the US government in 2022 increased by a quarter annually to hit 25,096, a new all-time high, according to data compiled by Skybox Security.

Leveraging large language models (LLMs) for corporate security and privacy

07 June 2023
LLMs can be trained to identify potential security threats, thus acting as an added layer of protection. Moreover, they’re fantastic tools for fostering cybersecurity awareness, capable of simulating threats, and providing real-time guidance.

New PowerDrop Malware Targeting U.S. Aerospace Industry

07 June 2023
"PowerDrop uses advanced techniques to evade detection such as deception, encoding, and encryption," according to Adlumin, which found the malware implanted in an unnamed domestic aerospace defense contractor in May 2023.

Winning the Mind Game: The Role of the Ransomware Negotiator

07 June 2023
Get exclusive insights from a real ransomware negotiator who shares authentic stories from network hostage situations and how he managed them. The Ransomware Industry Ransomware is an industry. As such, it has its own business logic: organizations pay money, in crypto-currency, in order to regain control over their systems and data. This industry's landscape is made up of approximately 10-20

CISOs focus more on business strategy than threat research

07 June 2023
CISOs and ITDMs (IT security decision-makers) continue to be most occupied with business, IT and security program strategy, but they are spending less time on threat research, awareness, and hunting compared to 2022, according to Nuspire.

ID fraud a possibility forever, claims data breach lawsuit

07 June 2023
Mercer University, based in Macon, Georgia, is facing a bunch of class action lawsuits after the personal data of nearly 100,000 people was stolen from its tech infrastructure.

NASA website flaw jeopardizes astrobiology fans

07 June 2023
Attackers could have used the flaw to redirect anyone to malicious websites, prompting users to part with their login credentials, credit card numbers, or other sensitive data.

Google Workspace Gets Passkey Authentication

07 June 2023
Passkeys are an alternative authentication method to passwords, allowing users to sign in to apps and websites with their fingerprint, with facial recognition, or with their device’s PIN or pattern.

North Korean hackers spoof venture capital firms in Japan, Vietnam and US

07 June 2023
Insikt Group researchers linked the campaign to APT38, a state-sponsored group in North Korea notorious for several high-profile attacks on cryptocurrency firms and other organizations.

Microsoft settles for $20 million with FTC over Xbox’s collection of children’s data

07 June 2023
The settlement with the Federal Trade Commission comes in response to charges that Microsoft’s Xbox gaming system illegally gathered and retained children’s personal information without alerting their parents or getting their approval.

Hackers Leak i2VPN Admin Credentials on Telegram

07 June 2023
Although the hackers did not directly release user data, the compromised admin panel credentials potentially grant access to a substantial amount of personal information and data centers.

New PowerDrop Malware Targeting U.S. Aerospace Industry

07 June 2023
An unknown threat actor has been observed targeting the U.S. aerospace industry with a new PowerShell-based malware called PowerDrop. "PowerDrop uses advanced techniques to evade detection such as deception, encoding, and encryption," according to Adlumin, which found the malware implanted in an unnamed domestic aerospace defense contractor in May 2023. "The name is derived from the tool,

Service Rents Email Addresses for Account Signups

06 June 2023
One of the most expensive aspects of any cybercriminal operation is the time and effort it takes to create large numbers of new throwaway email accounts. Now a new service offers to help dramatically cut costs associated with large-scale spam and account creation campaigns, by paying people to sell their email account credentials and letting customers temporarily rent access to a vast pool of established accounts at major providers.

CISA releases joint guide to securing remote access software

06 June 2023
CISA has released a joint guide that informs organizations how to detect and defend against malicious actors abusing remote access software.

New vulnerabilities published in 2022 increased 25%

06 June 2023
A report from Skybox Security found a 25% increase in new vulnerabilities published within 2022, a year-over-year rise the biggest seen since 2017.

57% of financial organizations use multiple cloud service providers

06 June 2023
Cloud adoption continues to increase within the financial services sector with the majority reporting that they're using some form of cloud computing.

Apple Unveils Upcoming Privacy and Security Features

06 June 2023
Apple’s Safari browser is getting an improved Private Browsing mode, which will lock when not in use, so that users can leave tabs open even if they need to step away from the device.

New Malware Campaign Leveraging Satacom Downloader to Steal Cryptocurrency

06 June 2023
A recent malware campaign has been found to leverage Satacom downloader as a conduit to deploy stealthy malware capable of siphoning cryptocurrency using a rogue extension for Chromium-based browsers. "The main purpose of the malware that is dropped by the Satacom downloader is to steal BTC from the victim's account by performing web injections into targeted cryptocurrency websites," Kaspersky