Latest Cybersecurity News and Articles


UK: 20 NHS trusts shared patient details with Facebook without consent

29 May 2023
The data includes granular details of pages viewed, buttons clicked and keywords searched. It is matched to the user’s IP address – an identifier linked to an individual or household – and, in many cases, details of their Facebook account.

New BrutePrint Attack Lets Attackers Unlock Smartphones with Fingerprint Brute-Force

29 May 2023
Researchers have discovered an inexpensive attack technique that could be leveraged to brute-force fingerprints on smartphones to bypass user authentication and seize control of the devices. The approach, dubbed BrutePrint, bypasses limits put in place to counter failed biometric authentication attempts by weaponizing two zero-day vulnerabilities in the smartphone fingerprint authentication (SFA

CISA warns govt agencies of recently patched Barracuda zero-day

29 May 2023
FCEB agencies must patch or mitigate the vulnerability as ordered by the BOD 22-01 binding operational directive. However, this is no longer needed since Barracuda has already patched all vulnerable devices by applying two patches over the weekend.

Sports Warehouse Fined $300,000 Over Payment Card Data Theft

29 May 2023
Investigators found that the retailer was storing nearly 20 years' worth of payment card data on its e-commerce server in plaintext format, protected by only a password, which the attacker guessed.

QBot malware abuses Windows WordPad EXE to infect devices

29 May 2023
The QBot malware operation has started to abuse a DLL hijacking flaw in the Windows 10 WordPad program to infect computers, using the legitimate program to evade detection by security software.

'Hot Pixels' Attack Checks CPU Temperature, Power Changes to Steal Data

29 May 2023
A team of researchers at Georgia Tech, the University of Michigan, and Ruhr University Bochum developed this novel attack which can retrieve pixels from the content displayed in the target's browser and infer the navigation history.

AceCryptor: Cybercriminals' Powerful Weapon, Detected in 240K+ Attacks

29 May 2023
A crypter (alternatively spelled cryptor) malware dubbed AceCryptor has been used to pack numerous strains of malware since 2016. Slovak cybersecurity firm ESET said it identified over 240,000 detections of the crypter in its telemetry in 2021 and 2022. This amounts to more than 10,000 hits per month. Some of the prominent malware families contained within AceCryptor are SmokeLoader, RedLine

3 Challenges in Building a Continuous Threat Exposure Management (CTEM) Program and How to Beat Them

29 May 2023
If you're a cybersecurity professional, you're likely familiar with the sea of acronyms our industry is obsessed with. From CNAPP, to CWPP, to CIEM and all of the myriad others, there seems to be a new initialism born each day. In this article, we'll look at another trending acronym – CTEM, which stands for Continuous Threat Exposure Management – and the often-surprising challenges that come

Enhanced Legion Credential Harvester Targets SSH Servers and AWS Credentials

29 May 2023
An updated version of the Python-based, cloud-focused hack tool called Legion—which can extract credentials from vulnerable web servers—has surfaced. The updated variant incorporates the Paramiko module to exploit SSH servers. Furthermore, it can now retrieve specific AWS credentials associated with CloudWatch, DynamoDB, and AWS Owl from Laravel web applications.

Data Breach at Dental Health Insurer MCNA Affects Nearly Nine Million Patients

29 May 2023
The Fort Lauderdale, Florida-based insurance company, said it detected unauthorized access to certain systems on March 6 and discovered that certain systems within the network were infected with malicious code.

Tortoiseshell Eyes Israeli Logistics Industry

29 May 2023
Alleged Iranian nation-state hacker group Tortoiseshell performed a watering hole attack on several shipping and logistics websites in Israel to collect information about their users. Attackers stay hidden by impersonating the genuine jQuery JavaScript framework. Organizations are urged to raise awareness for watering hole attacks and always keep the systems updated.

New GobRAT Remote Access Trojan Targeting Linux Routers in Japan

29 May 2023
"Initially, the attacker targets a router whose WEBUI is open to the public, executes scripts possibly by using vulnerabilities, and finally infects the GobRAT," the JPCERT Coordination Center (JPCERT/CC) said in a report published today.

PyPI announces mandatory use of 2FA for all software publishers

29 May 2023
The Python Package Index (PyPI) has announced that it will require every account that manages a project on the platform to have two-factor authentication (2FA) turned on by the end of the year.

New GobRAT Remote Access Trojan Targeting Linux Routers in Japan

29 May 2023
Linux routers in Japan are the target of a new Golang remote access trojan (RAT) called GobRAT. "Initially, the attacker targets a router whose WEBUI is open to the public, executes scripts possibly by using vulnerabilities, and finally infects the GobRAT," the JPCERT Coordination Center (JPCERT/CC) said in a report published today. The compromise of an internet-exposed router is followed by the

Royal messes with Texas

29 May 2023
The Royal ransomware group is on a spree in the Dallas metro area, having hit multiple government institutions in the region during the last six months. The frenzy began with an attack against the Dallas Central Appraisal District in November 2022.

Top public cloud security concerns for the media and entertainment industry

29 May 2023
A new Wasabi survey found that, while M&E organizations are still new to cloud storage (69% using cloud storage for three years or less), public cloud storage use is rising, with 89% looking to increase (74%) or maintain (15%) their cloud services.

Clever ‘File Archiver In The Browser’ phishing trick uses ZIP domains

29 May 2023
A new 'File Archivers in the Browser' phishing kit abuses ZIP domains by displaying fake WinRAR or Windows File Explorer windows in the browser to convince users to launch malicious files.

Company size doesn’t matter when it comes to cyberattacks

29 May 2023
65% of organizations in the enterprise sector suffered a cyberattack within the last 12 months, which is similar to the results among companies of all sizes (68%), according to Netwrix.

Don't Click That ZIP File! Phishers Weaponizing .ZIP Domains to Trick Victims

29 May 2023
A new phishing technique called "file archiver in the browser" can be leveraged to "emulate" a file archiver software in a web browser when a victim visits a .ZIP domain. "With this phishing attack, you simulate a file archiver software (e.g., WinRAR) in the browser and use a .zip domain to make it appear more legitimate," security researcher mr.d0x disclosed last week. Threat actors, in a

PyPI Implements Mandatory Two-Factor Authentication for Project Owners

29 May 2023
The Python Package Index (PyPI) announced last week that every account that maintains a project on the official third-party software repository will be required to turn on two-factor authentication (2FA) by the end of the year. "Between now and the end of the year, PyPI will begin gating access to certain site functionality based on 2FA usage," PyPI administrator Donald Stufft said. "In addition