Latest Cybersecurity News and Articles
25 May 2023
The Iranian threat actor known as Agrius is leveraging a new ransomware strain called Moneybird in its attacks targeting Israeli organizations.
Agrius, also known as Pink Sandstorm (formerly Americium), has a track record of staging destructive data-wiping attacks aimed at Israel under the guise of ransomware infections.
Microsoft has attributed the threat actor to Iran's Ministry of
25 May 2023
Google on Wednesday announced the 0.1 Beta version of GUAC (short for Graph for Understanding Artifact Composition) for organizations to secure their software supply chains.
To that end, the search giant is making available the open source framework as an API for developers to integrate their own tools and policy engines.
GUAC aims to aggregate software security metadata from different sources
24 May 2023
The Cyber Signals report revealed that Microsoft detected 35 million BEC attempts with an average of 156,000 attempts daily between April 2022 and April 2023. Microsoft also noticed a pattern in which attackers used a phishing-as-a-service platform, BulletProftLink, to obtain login credentials. To protect, enterprises can enable notifications and configure mail systems to flag messages sent from external parties.
24 May 2023
Trend Micro revealed that the BlackCat ransomware group is using a signed kernel driver for evasion tactics. The driver was utilized in conjunction with a separate user client executable, with the intention of manipulating, pausing, and terminating specific processes associated with the security on the targeted endpoints. Windows admins must ensure that 'Driver Signature Enforcement' is enabled.
24 May 2023
The White House Office of Science and Technology Policy is releasing a National AI R&D Strategic Plan. The plan is meant to manage potential AI risks.
24 May 2023
According to a recent report, some cyber insurance policies aren't covering ransomware attacks as the volume of attacks continues to rise.
24 May 2023
Law enforcement and regulatory action over the past year in the US most likely dissuaded hackers from stealing cryptocurrency, making the amount stolen in the first quarter of the year the lowest compared to each of the four quarters in 2022.
24 May 2023
OAuth-related vulnerabilities found in the widely used application development framework Expo could have been exploited to take control of user accounts, according to API security firm Salt Security.
24 May 2023
The Israel-based real-time website impersonation detection and prevention solution provider has completed a $10 million seed round led by Capri Ventures and Venture Guides.
24 May 2023
Latvian network equipment manufacturer MikroTik has shipped a patch for a major security defect in its RouterOS product and confirmed the vulnerability was exploited five months ago at the Pwn2Own Toronto hacking contest.
24 May 2023
The ransomware threat is still very much alive, with 85% of organizations having suffered from at least one such attack over the past 12 months, according to Veeam’s 2023 Ransomware Trends Report.
24 May 2023
An "unauthorized third party" broke into "select Apria systems" containing personal information from April 5, 2019, to May 7, 2019, and then a second time from August 27, 2021, to October 10, 2021, according to the alert.
24 May 2023
Jessica Berlin, an independent policy and security consultant, noted that there is no international security without cybersecurity and called for a private sector task force to defend democracies in general elections and public information.
24 May 2023
"This recent update demonstrates a widening of scope, with new capabilities such the ability to compromise SSH servers and retrieve additional AWS-specific credentials from Laravel web applications," Cado Labs researcher Matt Muir said.
24 May 2023
As per a new report, despite the recognition of business threats posed by cyberattacks, UK CEOs have a lower level of understanding of cybersecurity risks than their international counterparts, with just 16% saying they have a complete understanding.
24 May 2023
At least eight websites associated with shipping, logistics, and financial services companies in Israel were targeted as part of a watering hole attack.
Tel Aviv-based cybersecurity company ClearSky attributed the attacks with low confidence to an Iranian threat actor tracked as Tortoiseshell, which is also called Crimson Sandstorm (previously Curium), Imperial Kitten, and TA456.
"The infected
24 May 2023
Point32Health, one of New England’s largest health insurers, notified current and former customers Tuesday that data including patient medical history and diagnoses was copied and taken during a ransomware attack.
24 May 2023
The findings come from the AhnLab Security Emergency response Center (ASEC), which detailed the advanced persistent threat's (APT) continued abuse of DLL side-loading techniques to deploy malware.
24 May 2023
A new report reveals that a majority of organizations believe that a ransomware attack is moderately to extremely likely to occur within the next 12 months.
24 May 2023
Security analysts at Scam Sniffer exposed a crypto phishing and scam service Inferno Drainer that swindled about $5.9 million worth of cryptocurrencies from 4,888 victims. It reportedly crafted over 689 counterfeit websites since March 27, 2023. Deploy a real-time anti-scam protection solution for internet users across organizational networks.