Latest Cybersecurity News and Articles
23 May 2023
The issue allowed security researcher Joseph Harris to effectively merge his own account with anyone else’s, giving him the ability to update that account’s password and take control of it.
23 May 2023
The latest activity cluster associated with the group commenced on May 5, 2023, and leverages a variant of RandomQuery that's specifically designed to enumerate files and siphon sensitive data.
23 May 2023
The stolen data, now publicly released on Cuba's extortion portal, includes financial documents, correspondence with bank employees, account movements, balance sheets, tax documents, compensation, and source code.
23 May 2023
The U.S. Cybersecurity and Infrastructure Security Agency on Friday gave federal agencies until June 9 to patch affected Samsung-made Android devices and added the flaw to its Known Exploited Vulnerabilities Catalog.
23 May 2023
Government and diplomatic entities in the Middle East and South Asia are the target of a new advanced persistent threat actor named GoldenJackal.
Russian cybersecurity firm Kaspersky, which has been keeping tabs on the group's activities since mid-2020, characterized the adversary as both capable and stealthy.
The targeting scope of the campaign is focused on Afghanistan, Azerbaijan, Iran, Iraq,
23 May 2023
Apart from targeting Ukrainian government entities, a threat actor identified by researchers as UAC-0063 “has also shown interest” in targeting Mongolia, Kazakhstan, Kyrgyzstan, Israel, and India, according to the report published on Monday.
23 May 2023
"There is NO explosion or incident taking place at or near the Pentagon reservation, and there is no immediate danger or hazards to the public," Arlington Fire & EMS said.
23 May 2023
The command injection vulnerability (CVE-2023-28771) affects Zyxel APT, USG FLEX, and VPN firewalls running versions v4.60 to v5.35 of the ZDL firmware, and Zyxel ZyWALL/USG gateways/firewalls running ZLD v4.60 to v4.73.
23 May 2023
The North Korean advanced persistent threat (APT) group known as Kimsuky has been observed using a piece of custom malware called RandomQuery as part of a reconnaissance and information exfiltration operation.
"Lately, Kimsuky has been consistently distributing custom malware as part of reconnaissance campaigns to enable subsequent attacks," SentinelOne researchers Aleksandar Milenkoski and Tom
23 May 2023
Since May 10, the production of bikes and scooters at Suzuki Motorcycle's Indian plant has reportedly been temporarily suspended with the loss of an estimated 20,000 vehicles.
23 May 2023
Despite the impact that cyber incidents have on an organization’s overall business operations, security spending remains within the purview of the IT budget, albeit a small part.
23 May 2023
Security researchers with Tencent Labs and Zhejiang University uncovered a new attack method dubbed BrutePrint to breach the security of Android smartphones via brute-force techniques. Researchers experimented with Android, iOS, and HarmonyOS-based smartphones, however, only Android phones were found susceptible to attacks.
23 May 2023
According to a report by 'Scam Sniffer,' the phishing service has created at least 689 fake websites since March 27, 2023. Most of the phishing sites came online after May 14, 2023, with analysts reporting a spike in new sites around that time.
23 May 2023
Making headlines earlier this month, Montana became the first state to ban social media platform TikTok. Security leaders weigh in.
23 May 2023
Proposed class action lawsuits are piling up in federal courts over hackers' use of a vulnerability in Fortra's GoAnywhere secure file transfer and a resulting health data breach affecting more than 3 million individuals.
23 May 2023
Such fraud schemes, perpetrated primarily by Chinese organized crime groups, have exploded in size in recent years, with Cambodia as the epicenter of the industry and Myanmar increasingly becoming a hub.
23 May 2023
The mastermind behind a criminal website that sold tools for scammers who defrauded victims globally of more than 115 million euros received a 13-year, four-month prison sentence in the UK just months after law enforcement seized the site.
23 May 2023
A financially motivated threat actor of Indonesian origin has been observed leveraging Amazon Web Services (AWS) Elastic Compute Cloud (EC2) instances to carry out illicit crypto mining operations.
23 May 2023
The most precious asset in today's information age is the secret safeguarded under lock and key. Regrettably, maintaining secrets has become increasingly challenging, as highlighted by the 2023 State of Secrets Sprawl report, the largest analysis of public GitHub activity.
The report shows a 67% year-over-year increase in the number of secrets found, with 10 million hard-coded secrets detected
23 May 2023
An unknown threat actor has been observed leveraging a malicious Windows kernel driver in attacks likely targeting the Middle East since at least May 2020.
Fortinet Fortiguard Labs, which dubbed the artifact WINTAPIX (WinTapix.sys), attributed the malware with low confidence to an Iranian threat actor.
"WinTapix.sys is essentially a loader," security researchers Geri Revay and Hossein Jazi said