Latest Cybersecurity News and Articles


AHA Tells HHS to 'Amend or Suspend' Web Tracking Guidance

27 May 2023
The AHA is urging federal regulators to back off from recent guidance that treats patient IP addresses as PHI, saying that the new rules would "reduce public access to credible health information" and create hardships for doctors and hospitals.

German Prosecutors Indict FinFisher Spyware Executives

27 May 2023
The indictment accuses the four FinFisher executives, identified only with an initial, of evading export controls by selling the FinSpy hacking tool to Turkey's intelligence agency in 2015 through a Bulgarian front company.

Lender OneMain fined $4.25 million for cybersecurity lapses

27 May 2023
OneMain Financial Group, which specializes in issuing loans to people with “nonprime” credit histories, will pay a $4.25 million penalty in New York state for cybersecurity lapses found during a government investigation.

Pegasus spyware was deployed in Armenia amid Nagorno-Karabakh war

27 May 2023
A number of individuals from Armenia contacted the digital rights organizations CyberHUB-AM, an Armenian organization, and Access Now to check their devices for evidence of such spyware.

New Stealthy Bandit Stealer Targeting Web Browsers and Cryptocurrency Wallets

27 May 2023
A new stealthy information stealer malware called Bandit Stealer has caught the attention of cybersecurity researchers for its ability to target numerous web browsers and cryptocurrency wallets.  "It has the potential to expand to other platforms as Bandit Stealer was developed using the Go programming language, possibly allowing cross-platform compatibility," Trend Micro said in a Friday report

DOD Submits Classified Cyber Strategy to Congress

27 May 2023
The Department of Defense announced on Friday that it submitted its classified 2023 cyber strategy to Congress “earlier this week” and plans to release an unclassified summary of its new cybersecurity approach “in the coming months.”

Critical OAuth Vulnerability in Expo Framework Allows Account Hijacking

27 May 2023
A critical security vulnerability has been disclosed in the Open Authorization (OAuth) implementation of the application development framework Expo.io. The shortcoming, assigned the CVE identifier CVE-2023-28131, has a severity rating of 9.6 on the CVSS scoring system. API security firm Salt Labs said the issue rendered services using the framework susceptible to credential leakage, which could

Medical Specialty Practice Says Recent Hack Affects 224,500

27 May 2023
An upstate New York medical specialty practice told regulators that hackers compromised the personal and protected health information of nearly 224,500 employees and patients in an incident discovered in March.

Update: Latitude Financial Attack Costs Company Up to $68.5 Million

27 May 2023
Latitude was able to process transactions during the incident, but "account originations and collections were closed or severely restricted." The company has since fully recovered, it says.

WinTapix Attack Campaign Targets Middle East Nations

26 May 2023
An unidentified threat actor group has been observed employing a malicious Windows kernel driver in targeted attacks, primarily focusing on the Middle East region. Fortinet security experts have dubbed the artifact as WINTAPIX (WinTapix.sys). To stay protected, users are suggested to immediately implement the driver blocklist feature in Windows to block malicious drivers.

New York Attorney General seeks fine over Sport Warehouse data breach

26 May 2023
Online sporting goods retailer Sports Warehouse must pay the state of New York 300,000 in penalties for a data breach affecting 2.5 million consumers.

Severe Flaw in Google Cloud's Cloud SQL Service Exposed Confidential Data

26 May 2023
The multi-stage attack chain identified by Dig, in a nutshell, leveraged a gap in the cloud platform's security layer associated with SQL Server to escalate the privileges of a user to that of an administrator role.

Ahead of summer holiday weekends, IT security leaders brace for deliberate cyber mischief

26 May 2023
Memorial Day weekend marks the start of the summer travel season. U.S. authorities and network defenders in the private sector are quietly paying attention to potential threats that may emerge during key holiday weekends over the next three months.

Italy's Industry Ministry reports 'heavy' cyberattack

26 May 2023
Technicians were working to "mitigate the consequences" of the attack, the ministry wrote in a statement, adding that initial checks showed no evidence of data theft. It was too early to predict when activities would be back to normal, it said.

Phishing Domains Tanked After Meta Sued Freenom

26 May 2023
The number of phishing websites tied to domain name registrar Freenom dropped precipitously in the months surrounding a recent lawsuit from social networking giant Meta, which alleged the free domain name provider has a long history of ignoring abuse complaints about phishing websites while monetizing traffic to those abusive domains.

Emby Shuts Down User Media Servers Hacked in Recent Attacks

26 May 2023
The attacks began in mid-May 2023 when the attackers started targeting Internet-exposed private Emby servers and infiltrating those configured to allow admin logins without a password on the local network.

Severe Flaw in Google Cloud's Cloud SQL Service Exposed Confidential Data

26 May 2023
A new security flaw has been disclosed in the Google Cloud Platform's (GCP) Cloud SQL service that could be potentially exploited to obtain access to confidential data. "The vulnerability could have enabled a malicious actor to escalate from a basic Cloud SQL user to a full-fledged sysadmin on a container, gaining access to internal GCP data like secrets, sensitive files, passwords, in addition

Advisory warning issued for PRC state-sponsored cyber activity

26 May 2023
The NSA and Central Security Service released a threat advisory which highlights a cluster of activity being attributed to a China state-sponsored threat group.

Shedding light on AceCryptor and its operation

26 May 2023
Since the first known appearance of AceCryptor back in 2016, many malware authors have used the services of this cryptor, even the best-known crimeware like Emotet, back when it didn’t use its own cryptor.

Dark Frost Botnet Launches Devastating DDoS Attacks on Gaming Industry

26 May 2023
Dark Frost represents the latest iteration of a botnet that appears to have been stitched together by stealing source code from various botnet malware strains such as Mirai, Gafgyt, and QBot.