Latest Cybersecurity News and Articles


Security Pros: Before You Do Anything, Understand Your Threat Landscape

26 May 2023
Today, when threats are coming from a variety of places, not just one or a few, it becomes much harder to prepare for attacks and know what to patch or otherwise remediate because there is a lot more to address.

Withholding Single Sign-On from SaaS Customers is Bad for Business and Security

26 May 2023
Despite years of public shaming by security professionals, some SaaS vendors only offer Single Sign-On (SSO) in high-end "enterprise" product tiers. By withholding this capability from smaller organizations, they put customers' security at risk.

Phishing campaign targets ChatGPT users

26 May 2023
A clever phishing campaign aimed at stealing users’ business email account credentials by impersonating OpenAI, the company behind the ChatGPT chatbot, has been spotted by Inky researchers.

UK: New SARs guidance for employers issued by ICO

26 May 2023
The ICO published new guidance for businesses and employers on responding to Subject Access Requests (SARs). The right of access, commonly referred to SAR, gives someone the right to request a copy of their personal information from organizations.

New Info-stealer Bandit Stealer Targets Browsers, Cryptocurrency Wallets

26 May 2023
The malware tries to use runas.exe, a command-line utility program in Windows operating systems (OS) that allows users to run specific programs or commands with user credentials or permissions other than those from the current user's account.

Predator Android Spyware: Researchers Sound the Alarm on Alarming Capabilities

26 May 2023
Security researchers have shared a deep dive into the commercial Android spyware called Predator, which is marketed by the Israeli company Intellexa (previously Cytrox). Predator was first documented by Google's Threat Analysis Group (TAG) in May 2022 as part of attacks leveraging five different zero-day flaws in the Chrome web browser and Android. The spyware, which is delivered by means of

Fresh perspectives needed to manage growing vulnerabilities

26 May 2023
In the inaugural 2023 Offensive Security Vision Report by NetSPI, lack of resources, vulnerability prioritization, and business priorities, were reported as the top three barriers to timely and effective vulnerability remediation.

BlackByte Lists City of Augusta as its Latest Victim After 'Cyber Incident'

26 May 2023
In a Wednesday statement about the "network outage" posted on the city's website, Augusta Mayor Garnett Johnson said the "technical difficulties" – which disrupted some of the city's computer systems – started on Sunday, May 21.

5 Must-Know Facts about 5G Network Security and Its Cloud Benefits

26 May 2023
5G is a game changer for mobile connectivity, including mobile connectivity to the cloud. The technology provides high speed and low latency when connecting smartphones and IoT devices to cloud infrastructure. 5G networks are a critical part of all infrastructure layers between the end user and the end service; these networks transmit sensitive data that can be vital for governments and

Advanced Phishing Attacks Surge 356% in 2022

26 May 2023
Among the reasons behind this growth is the fact that malicious actors continue to gain widespread access to new tools, including artificial intelligence (AI) and machine learning (ML)-powered tools.

New Russia-Linked ICS Malware 'COSMICENERGY' can Cause Cyber-Physical Disruption

26 May 2023
The malware can create disruptions in the electrical power supply by interacting with IEC 60870-5-104 (IEC-104) devices. These devices, including RTUs, are widely used in electric transmission and distribution in Europe, the Middle East, and Asia.

North Korea Actor Kimsuky Updates its Reconnaissance Malware RandomQuery

26 May 2023
Kimsuky, the North Korean APT group, is actively distributing a variant of custom malware known as RandomQuery as part of its reconnaissance campaigns. The malware has been specifically designed to perform two primary functions: file enumeration and data exfiltration. A real-time threat intelligence exchange platform can help fend off the threats from RandomQuery and other similar custom espionage tools.

Cybercriminals masquerading as MFA vendors

26 May 2023
Cybercriminals are increasingly posing as multi-factor authentication vendors and small businesses are becoming more popular targets, according to VIPRE. Financial institutions (48%) are still the most targeted sector by a wide margin.

New Mirai Variant Targets Multiple IoT Devices

26 May 2023
On April 10, Unit 42 researchers observed a Mirai variant called IZ1H9, which used several vulnerabilities to target exposed servers and networking devices running Linux, including CVE-2023-27076, CVE-2023-26801, CVE-2023-26802, and others.

It's 2023 and Sri Lanka lacks a cybersecurity authority

26 May 2023
Sri Lanka's Ministry of Technology has confirmed it will have a cybersecurity authority soon. As per local media, state minister Kanaka Herath told the Cyber Security Conference in Colombo that efforts to create the authority in 2023 are underway.

Mercenary mayhem: A technical analysis of Intellexa's PREDATOR spyware

26 May 2023
Intellexa’s spyware products, like most recently exposed spyware tools, have multiple components that can be grouped into three major buckets aligned with consecutive stages of the attack: exploitation, privilege escalation, and malware deployment.

Four Key GDPR Trends on the Law’s Fifth Anniversary

26 May 2023
The application of the GDPR across the EU on May 25, 2018, was a landmark occasion – with the legislation replacing often disjointed and outdated data protection rules across Europe with a coordinated one designed for the modern digital age.

Microsoft Encrypted Restricted Permission Messages Deliver Phishing

26 May 2023
Trustwave researchers reported that over the recent days, they had observed phishing attacks that employed a mix of compromised Microsoft 365 accounts and .rpmsg encrypted emails to distribute the phishing message.

The essence of OT security: A proactive guide to achieving CISA’s Cybersecurity Performance Goals

26 May 2023
Recently, CISA updated the CPGs to align with NIST’s standard cybersecurity framework, establishing each of the five goals as a prioritized subset of IT and OT cybersecurity practices.

Trojanized App Infects Over 50,000 with AhRAt Trojan

26 May 2023
AhRAT is a newly discovered threat by ESET researchers on the Google Play Store that disguises itself as a screen recording application, which witnessed tens of thousands of installations. Threat actors added malicious functionality at a later stage of its release in August 2022. Organizations must use the updated IOCs to understand the attack patterns and implement necessary detection systems.