Latest Cybersecurity News and Articles


Suspected Iranian Hackers Target Israeli Shipping and Logistics Companies

24 May 2023
Tel Aviv-based cybersecurity company ClearSky attributes these attacks “with a low confidence” to the Iranian nation-state hacker group Tortoiseshell, also called TA456 and Imperial Kitten. The threat actor has been active since at least July 2018.

Popular Android Screen Recorder App iRecorder Revealed as Trojan

24 May 2023
Cybersecurity experts from ESET made this discovery, uncovering a variant of AhMyth, an open-source remote administration tool capable of extracting sensitive data from Android devices.

What to Look for When Selecting a Static Application Security Testing (SAST) Solution

24 May 2023
If you're involved in securing the applications your organization develops, there is no question that Static Application Security Testing (SAST) solutions are an important part of a comprehensive application security strategy. SAST secures software, supports business more securely, cuts down on costs, reduces risk, and speeds time to development, delivery, and deployment of mission-critical

Data Stealing Malware Discovered in Popular Android Screen Recorder App

24 May 2023
Google has removed a screen recording app named "iRecorder - Screen Recorder" from the Play Store after it was found to sneak in information stealing capabilities nearly a year after the app was published as an innocuous app. The app (APK package name "com.tsoft.app.iscreenrecorder"), which accrued over 50,000 installations, was first uploaded on September 19, 2021. The malicious functionality

Insurance Information Bureau of India Suffers Ransomware Attack by Russian Hackers

24 May 2023
The accounts of the system administrator and database administrator were also compromised along with 11 other accounts and several gadgets used by the IIB staff, police said.

Biden nominates Lt. Gen. Timothy Haugh for top position at NSA, Cyber Command

24 May 2023
President Joe Biden has tapped Air Force Lt. Gen. Timothy Haugh to serve as the new chief of U.S. Cyber Command and the National Security Agency, two sources familiar with the decision told The Record.

Legion Malware Upgraded to Target SSH Servers and AWS Credentials

24 May 2023
An updated version of the commodity malware called Legion comes with expanded features to compromise SSH servers and Amazon Web Services (AWS) credentials associated with DynamoDB and CloudWatch. "This recent update demonstrates a widening of scope, with new capabilities such the ability to compromise SSH servers and retrieve additional AWS-specific credentials from Laravel web applications,"

PillPack users informed of unauthorized account access

24 May 2023
Amazon Pharmacy’s PillPack arm recently began informing a subset of users that their accounts were accessed by an unknown actor. Of the 19,032 hacker accounts, 3,614 contained prescription information.

Cyware Expands in Europe with Strategic New Hires

24 May 2023
Cyware today announced the appointment of two industry veterans, Brett Candon as VP Europe, and Dan Bridges as Technical Director Europe, to lead Cyware’s launch in the European region.

IT employee impersonates ransomware gang to extort employer

24 May 2023
A press release published yesterday by the South East Regional Organised Crime Unit (SEROCU) explains that in February 2018, the convict, Ashley Liles, worked as an IT Security Analyst at an Oxford-based company that suffered a ransomware attack.

Future Exploitation Vector File Extensions as Top Level Domains

24 May 2023
The use of legitimate websites for masking malicious URLs to avoid detection and minimize suspicion is a technique that cybercriminals have used for a long time. These websites are often used as referrer URLs that redirect to the malicious URLs.

New DarkCloud Campaign Leverages Spam Emails

24 May 2023
ASEC’s AhnLab discovered a spam email campaign that distributes the DarkCloud info-stealer malware. The email contents urge recipients to review the attached payment statement, which purportedly pertains to their company account. Additionally, the threat actor installs ClipBanker on infected devices to steal a user’s crypto wallet address.

SuperMailer Abuse Explodes, Now Responsible for 14% of All Credential Phish Discovered in Inboxes

24 May 2023
This threat activity employs open redirect abuse, varied email senders, and URL randomization to bypass email security measures. The monthly volume of this activity more than doubled in three out of the past four months.

N. Korean Lazarus Group Targets Microsoft IIS Servers to Deploy Espionage Malware

24 May 2023
The infamous Lazarus Group actor has been targeting vulnerable versions of Microsoft Internet Information Services (IIS) servers as an initial breach route to deploy malware on targeted systems. The findings come from the AhnLab Security Emergency response Center (ASEC), which detailed the advanced persistent threat's (APT) continued abuse of DLL side-loading techniques to deploy malware. "The

Cyber Attacks Strike Ukraine's State Bodies in Espionage Operation

24 May 2023
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of cyber attacks targeting state bodies in the country as part of an espionage campaign. The intrusion set, attributed to a threat actor tracked by the authority as UAC-0063 since 2021, leverages phishing lures to deploy a variety of malicious tools on infected systems. The origins of the hacking crew are presently unknown. In

NCSC joins partners to issue warning about Chinese cyber activity targeting critical national infrastructure networks

23 May 2023
The advisory provides technical indicators of compromise and examples of techniques deployed by the actor to help network defenders identify malicious activity.

Fake CapCut Websites Spread Information Stealers

23 May 2023
Cybercriminals are distributing a fake version of CapCut, ByteDance's official video editor tool, to infect users with different malware. In most cases, they employ SEO poisoning techniques, utilize search ads, and leverage social media platforms to promote the tool via malicious websites created by them. Users are suggested to be sure of advertised results on the Google search engine before clicking on links.

Online pharmacy PillPack suffers data breach

23 May 2023
An unauthorized user accessed online prescription company PillPack's customer email addresses and passwords to log into their online accounts.

Treasury Department sanctions entities tied to North Korean IT scams, hacking

23 May 2023
The Treasury Department issued sanctions on Tuesday cracking down on four entities and one individual involved in malicious cyber activities supporting the Democratic People’s Republic of Korea and its weapons programs.

Industrial sector faced highest number of ransomware attacks in April

23 May 2023
The volume of ransomware attacks remained high with 352 attacks in April, the second-highest month on record, according to a recent report.