Latest Cybersecurity News and Articles


AI Used to Create Malware, WithSecure Observes

26 May 2023
Alarm bells continue to ring in the cybersecurity world around the potential threats from AI in the hands of threat actors. In particular, malware being created through ChatGPT appears to be a reality.

D-Link fixes auth bypass and RCE flaws in D-View 8 software

26 May 2023
D-Link has fixed two critical-severity vulnerabilities in its D-View 8 network management suite that could allow remote attackers to bypass authentication and execute arbitrary code.

New COSMICENERGY Malware Exploits ICS Protocol to Sabotage Power Grids

26 May 2023
A new strain of malicious software that's engineered to penetrate and disrupt critical systems in industrial environments has been unearthed. Google-owned threat intelligence firm Mandiant dubbed the malware COSMICENERGY, adding it was uploaded to a public malware scanning utility in December 2021 by a submitter in Russia. There is no evidence that it has been put to use in the wild. "The

Barracuda Warns of Zero-Day Exploited to Breach Email Security Gateway Appliances

26 May 2023
Email protection and network security services provider Barracuda is warning users about a zero-day flaw that it said has been exploited to breach the company's Email Security Gateway (ESG) appliances. The zero-day is being tracked as CVE-2023-2868 and has been described as a remote code injection vulnerability affecting versions 5.1.3.001 through 9.2.0.006. The California-headquartered firm 

Media industry cites lack of native security for public cloud issues

25 May 2023
A survey found that, while media and entertainment organizations are still relatively new to cloud storage, public cloud storage use is on the rise. 

Operation "Total Exchange": New PowerExchange Backdoor Discovered in the UAE

25 May 2023
While investigating attacks targeting a government entity in the UAE, Fortinet researchers also discovered an implant on Microsoft Exchange servers which was a novel web shell, dubbed ExchangeLeech, due to its unique ability to harvest credentials.

YouTube Pirated Software Videos Deliver Triple Threat: Vidar Stealer, Laplas Clipper, XMRig Miner

25 May 2023
FortiGuard Labs came across an ongoing threat campaign targeting YouTube users searching for pirated software earlier this month. Videos advertising downloads of pirated software are uploaded by verified YouTube channels with large subscriber counts.

Broad coalition of advocacy groups urges Slack to protect users' messages from eavesdropping

25 May 2023
While there are no reported instances of Slack messages being weaponized, the trove of communications the platform collects from clients ranging from government agencies to activists has made user communications a target of both lawsuits and hackers.

Brazilian hackers target Portuguese financial institutions

25 May 2023
A Brazilian hacking crew targeted users of over 30 Portuguese financial institutions earlier this year in a campaign that provides the latest example of financially motivated hackers in Brazil hitting foreign targets, according to SentinelLabs.

93% of organizations have database management tools in place

25 May 2023
A survey indicates that most organizations are not planning to make changes to their database strategies over the course of the next three years.

New Buhti Ransomware Operation Relies on Repurposed Payloads

25 May 2023
While the group doesn’t develop its own ransomware, it does utilize what appears to be one custom-developed tool, an information stealer designed to search for and archive specified file types.

Dark Frost Botnet Launches Devastating DDoS Attacks on Gaming Industry

25 May 2023
A new botnet called Dark Frost has been observed launching distributed denial-of-service (DDoS) attacks against the gaming industry. "The Dark Frost botnet, modeled after Gafgyt, QBot, Mirai, and other malware strains, has expanded to encompass hundreds of compromised devices," Akamai security researcher Allen West said in a new technical analysis shared with The Hacker News. Targets include

Zyxel Issues Critical Security Patches for Firewall and VPN Products

25 May 2023
Zyxel has released software updates to address two critical security flaws affecting select firewall and VPN products that could be abused by remote attackers to achieve code execution. Both the flaws – CVE-2023-33009 and CVE-2023-33010 – are buffer overflow vulnerabilities and are rated 9.8 out of 10 on the CVSS scoring system. A brief description of the two issues is below - CVE-2023-33009 -

Iranian Agrius Hackers Targeting Israeli Organizations with Moneybird Ransomware

25 May 2023
"The use of a new ransomware, written in C++, is noteworthy, as it demonstrates the group's expanding capabilities and ongoing effort in developing new tools," Check Point researchers Marc Salinas Fernandez and Jiri Vinopal said.

IT-ISAC launches food and agriculture analysis center

25 May 2023
The food and agriculture special interest group of the Information Technology-Information Sharing and Analysis Center is now its own analysis center.

Understanding Theories and Biases to Better Inform Security Decisions

25 May 2023
Preparing a security vision and garnering support from other departments in the company requires cross-functional collaboration, and a compelling business case for security investment is critical for a security department’s success.

Cynet Protects Hospital From Lethal Infection

25 May 2023
A hospital with 2,000 employees in the E.U. deployed Cynet protections across its environment. The hospital was in the process of upgrading several expensive imaging systems that were still supported by Windows XP and Windows 7 machines. Cynet protections were in place on most of the Windows XP and Windows 7 machines during the upgrade process, ensuring that legacy operating systems would not

New PowerExchange Backdoor Used in Iranian Cyber Attack on UAE Government

25 May 2023
An unnamed government entity associated with the United Arab Emirates (U.A.E.) was targeted by a likely Iranian threat actor to breach the victim's Microsoft Exchange Server with a "simple yet effective" backdoor dubbed PowerExchange. According to a new report from Fortinet FortiGuard Labs, the intrusion relied on email phishing as an initial access pathway, leading to the execution of a .NET

CISA and Partners Update the #StopRansomware Guide Developed Through the Joint Ransomware Task Force

25 May 2023
The updated guide, developed through the Joint Ransomware Task Force, reflects lessons learned in the last few years, adding the FBI and NSA as co-authors. It offers recommendations to prevent initial intrusion and protect data using cloud backups.

Reality check: What will generative AI really do for cybersecurity?

25 May 2023
Recent rapid advances in ML have made the potential power of AI blindingly obvious. What’s much less obvious is how it is going to be usefully deployed in security contexts and whether it will deliver the major breakthroughs its proponents promise.