Latest Cybersecurity News and Articles
25 May 2023
The updated #StopRansomware Guide provides best practices and resources to help organizations reduce the risk of ransomware incidents.
25 May 2023
The exposed database contained a staggering 360,308,817 records, totaling 133 GB in size. These records included a wide range of sensitive information, including user email addresses, original IP addresses, geolocation data, and server usage records.
25 May 2023
Legal and compliance leaders should address their organization’s exposure to six specific ChatGPT risks, and what guardrails to establish to ensure responsible enterprise use of generative AI tools, according to Gartner.
25 May 2023
A state-sponsored Chinese hacking group has been spying on a wide range of US critical infrastructure organizations and similar activities could be occurring globally, western intelligence agencies and Microsoft have warned.
25 May 2023
CERT-UA warned against a cyberespionage campaign by the UAC-0063 threat group targeting Ukraine, Mongolia, Kazakhstan, Kyrgyzstan, Israel, and India. To complicate investigation efforts and hinder attribution, the hackers employed the PyArmor and Themida software tools. Organizations are advised to impose restrictions on the execution of specific Windows utilities.
25 May 2023
According to Google, GUAC aggregates software security metadata and maps it to a standard vocabulary of concepts relevant to the software supply chain. They explained that this data can be accessed via a GraphQL interface.
25 May 2023
A Brazilian threat actor is targeting Portuguese financial institutions with information-stealing malware as part of a long-running campaign that commenced in 2021.
"The attackers can steal credentials and exfiltrate users' data and personal information, which can be leveraged for malicious activities beyond financial gain," SentinelOne researchers Aleksandar Milenkoski and Tom Hegel said in a
25 May 2023
The outage is affecting anything which operates through the school server, like payments in the canteen, pupil payments for other items which are based on fingerprint technology, electronic diaries, records, and messaging.
25 May 2023
To turn AI into a cybersecurity ally, organizations need to update – or perhaps create – action plans to handle the adoption of new, cutting-edge AI tools. Its key to revisit all the policies regarding technology use in a cybersecurity context.
25 May 2023
In today's digital landscape, browser security has become an increasingly pressing issue, making it essential for organizations to be aware of the latest threats to browser security. That's why the Browser Security platform LayerX is hosting a webinar featuring guest speaker Paddy Harrington, a senior analyst at Forrester and the lead author of Forrester's browser security report "Securing The
25 May 2023
The threat actors behind the nascent Buhti ransomware have eschewed their custom payload in favor of leaked LockBit and Babuk ransomware families to strike Windows and Linux systems.
"While the group doesn't develop its own ransomware, it does utilize what appears to be one custom-developed tool, an information stealer designed to search for and archive specified file types," Symantec said in a
25 May 2023
The info-stealer achieves persistent credential access by patching the installed Discord app. If the number of command-line arguments the info stealer is executed with is greater than two, then the function ‘malware::discord::inject’ is skipped.
25 May 2023
GitLab has released an emergency security update, version 16.0.1, to address a maximum severity (CVSS v3.1 score: 10.0) path traversal flaw tracked as CVE-2023-2825. It impacts GitLab Community Edition (CE) and Enterprise Edition (EE) version 16.0.0.
25 May 2023
In March 2023, the total number of breaches reported was higher than those reported in the previous three years combined, according to the joint Ransomware Index Report by Ivanti, Securin, and Cyware.
25 May 2023
While The Inquirer confirmed Cuba (the cybercrime group, not the country) had claimed responsibility for the break-in, it insisted that any documents posted by the gang on the dark web were not swiped from the newspaper.
25 May 2023
Proofpoint researchers found that advanced persistent threat actors target SMBs, governments, militaries, and major corporate entities using compromised SMB infrastructure in phishing campaigns.
25 May 2023
Ongoing attacks are targeting an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in a WordPress cookie consent plugin named Beautiful Cookie Consent Banner with more than 40,000 active installs.
25 May 2023
A stealthy China-based group managed to establish a persistent foothold into critical infrastructure organizations in the U.S. and Guam without being detected, Microsoft and the "Five Eyes" nations said on Wednesday.
The tech giant's threat intelligence team is tracking the activity, which includes post-compromise credential access and network system discovery, under the name Volt Typhoon.
The
25 May 2023
Error messages that ChatGPT and other AI language models generate can be used to uncover disinformation campaigns, hate speech and fake reviews via OSINT collection and analysis, says Nico Dekens, director of intelligence at ShadowDragon.
25 May 2023
Barracuda disclosed the flaw in its email security gateway (ESG) product via a five-paragraph advisory on its website. According to the advisory, the network security vendor discovered the flaw on May 19 before releasing patches on May 20 and 21.