Latest Cybersecurity News and Articles
02 June 2023
According to a report focusing on Chief Information Security Officer (CISO) perspectives, 50% identified cloud security as their top concern.
02 June 2023
The most severe of these is CVE-2023-32707, a privilege escalation issue that allows low-privileged users with the ‘edit_user’ capability to escalate privileges to administrator, via a specially crafted web request.
02 June 2023
A trove of documents, images, and videos from the offices of Iranian President Ebrahim Raisi posted online Monday appear to be authentic, cybersecurity experts familiar with the matter told CyberScoop on Wednesday.
02 June 2023
The misconfiguration led to the exposure of approximately 250,000 files. 42,000 of them contained the sensitive data of job seekers, namely: Full names, Dates of birth, Occupation history, Home addresses, Phone numbers, and Email addresses.
02 June 2023
The Cyber Incident Reporting Council will issue a report to Congress "in the next month or two" with recommendations on ways to achieve harmony across a complex network of federal cyber mandates.
02 June 2023
A recently discovered Chinese phishing gang has expanded its campaigns to the Middle East with new scams designed to harvest personal and payment data from victims, according to Group-IB.
02 June 2023
A new report analyzed the most prevalent cyberattack trends and identified an 87% increase in the total number of attacks over the course of last year.
02 June 2023
Israeli cybersecurity firm Check Point, which dubbed the Go-based malware TinyNote, said it functions as a first-stage payload capable of "basic machine enumeration and command execution via PowerShell or Goroutines."
02 June 2023
Horabot enables the threat actor to control the victim’s Outlook mailbox, exfiltrate contacts’ email addresses, and send phishing emails with malicious HTML attachments to all addresses in the victim’s mailbox.
02 June 2023
A number of Discord communities focused on cryptocurrency have been hacked this past month after their administrators were tricked into running malicious Javascript code disguised as a Web browser bookmark.
02 June 2023
Last week, the organization published a notice informing that ransomware actors maintained access to its systems between March 28 and April 17, 2023, when the breach was discovered.
02 June 2023
Spanish-speaking users in Latin America have been at the receiving end of a new botnet malware dubbed Horabot since at least November 2020.
"Horabot enables the threat actor to control the victim's Outlook mailbox, exfiltrate contacts' email addresses, and send phishing emails with malicious HTML attachments to all addresses in the victim's mailbox," Cisco Talos researcher Chetan Raghuprasad
02 June 2023
A catastrophic “once-in-200-years” cyber event could cause $33bn in losses for the cyber-insurance sector, according to the new Through the Looking Glass report from Guy Carpenter.
02 June 2023
"Progress has discovered a vulnerability in MOVEit Transfer that could lead to escalated privileges and potential unauthorized access to the environment," reads a security advisory from Progress.
02 June 2023
QBot operators are exploiting a DLL hijacking flaw in the Windows 10 WordPad executable known as write.exe to avoid detection. The infection may lead to the exposure of a user's email address which could be utilized in future phishing attacks. Furthermore, the impacted device can be infected by downloading other payloads, such as Cobalt Strike, for initial access. Experts revealed attackers can spread laterally throughout the network.
02 June 2023
A 25% increase in the use of phishing kits has been recorded in 2022, according to Group-IB. The key phishing trends observed are the increasing use of access control and advanced detection evasion techniques.
02 June 2023
Data security is reinventing itself. As new data security posture management solutions come to market, organizations are increasingly recognizing the opportunity to provide evidence-based security that proves how their data is being protected. But what exactly is data security posture, and how do you manage it?
Data security posture management (DSPM) became mainstream following the publication
02 June 2023
NCC Group identified a total of 11 vulnerabilities in Faronics Insight, including three critical-severity flaws (CVSS score of 9.6) leading to RCE. Two of these could be exploited without authentication.
02 June 2023
The Chinese nation-stage group known as Camaro Dragon has been linked to yet another backdoor that's designed to meet its intelligence-gathering goals.
Israeli cybersecurity firm Check Point, which dubbed the Go-based malware TinyNote, said it functions as a first-stage payload capable of "basic machine enumeration and command execution via PowerShell or Goroutines."
What the malware lacks in
02 June 2023
Actors behind a new malware named GobRAT were observed launching attacks against Linux routers in Japan. Cybercriminals abuse routers with publicly accessible web user interfaces. The malware strain is written in Go and established C2 communication via TLS. It can receive as many as 22 varieties of encrypted commands for execution.