Latest Cybersecurity News and Articles


Onfido acquires Airside to boost identity verification for individuals and businesses

22 May 2023
Cybersecurity firm Onfido acquired Airside Mobile to deliver user-controlled, shareable digital identity designed with data privacy and time-saving convenience at its core.

Indonesian Cybercriminals Exploit AWS for Profitable Crypto Mining Operations

22 May 2023
A financially motivated threat actor of Indonesian origin has been observed leveraging Amazon Web Services (AWS) Elastic Compute Cloud (EC2) instances to carry out illicit crypto mining operations. Cloud security company's Permiso P0 Labs, which first detected the group in November 2021, has assigned it the moniker GUI-vil (pronounced Goo-ee-vil). "The group displays a preference for Graphical

UK Councils Caught in Capita Unsecured AWS Bucket Data Leak

22 May 2023
The bad news train keeps rolling for Capita, with more local British councils surfacing to say their data was put on the line by an unsecured AWS bucket, and, separately, pension clients warning of possible data theft in March's mega breach.

DarkBERT could help automate dark web mining for cyber threat intelligence

22 May 2023
Researchers have developed DarkBERT, a language model pre-trained on dark web data, to help cybersecurity pros extract cyber threat intelligence (CTI) from the Internet’s virtual underbelly.

BlackCat Ransomware Deploys New Signed Kernel Driver

22 May 2023
Trend Micro researchers reported on an incident involving the BlackCat ransomware that took place in February 2023. The researchers highlighted a new capability, which involved the utilization of a signed kernel driver for evasion.

Facebook Parent Meta Hit With Record Fine for Transferring European User Data to US

22 May 2023
The European Union slapped Meta with a record $1.3 billion privacy fine Monday and ordered it to stop transferring user data across the Atlantic, the latest salvo in a decadelong case sparked by U.S. cyberespionage fears.

UK Man Sentenced to 13 Years for Running Multi-Million Fraud Website

22 May 2023
Tejay Fletcher, 35, from London, was found guilty of running a multi-million-pound fraud website that led to at least £100m ($124.2m) being stolen globally. Of this, £43m ($53.4m) was taken from UK victims.

Critical infrastructure security spending to grow 83% by 2027: ABI Research

22 May 2023
Critical infrastructure providers are poised to increase global spending on cybersecurity at a compound annual growth rate of 13%, according to projections ABI Research released Tuesday.

Update: Dish Ransomware Attack Impacted Nearly 300,000 People

22 May 2023
The company informed the Maine Attorney General about the data breach last week and shared a copy of the notification letter sent to impacted people. Dish told authorities that the incident impacted more than 296,000 individuals.

Bad Magic's Extended Reign in Cyber Espionage Goes Back Over a Decade

22 May 2023
New findings about a hacker group linked to cyber attacks targeting companies in the Russo-Ukrainian conflict area reveal that it may have been around for much longer than previously thought. The threat actor, tracked as Bad Magic (aka Red Stinger), has not only been linked to a fresh sophisticated campaign, but also to an activity cluster that first came to light in May 2016. "While the

Royal Gang Builds Its Own Malware Loader

22 May 2023
The Royal ransomware group is enhancing its downloader malware by adopting tactics and techniques that seem to be directly influenced by other post-Conti groups. The malware loader appears to be at its nascent stage and has a single purpose of deploying Cobalt Strike.  Organizations are urged to timely report TTPs of the threat so that other organizations can fend it off.

Europe: The DDoS battlefield

22 May 2023
DDoS attacks appear to reflect major geo-political challenges and social tensions and have become an increasingly significant part in the hybrid warfare arsenal, according to Arelion.

Cloned CapCut Websites Push Information Stealing Malware

22 May 2023
The malicious websites were discovered by Cyble, which reports seeing two campaigns distributing different malware strains. No specific information about how victims are directed on these sites was provided.

FIN7 Returns with Cl0p Ransomware Attacks

22 May 2023
The FIN7 gang has made a comeback with a new attack tactic involving Cl0p ransomware strains. It has previously utilized ransomware strains developed by various groups such as REvil and Maze. It uses Impacket and OpenSSH to infiltrate targeted networks and move laterally to deploy Cl0p ransomware. Organizations should use threat intelligence sharing platforms to stay updated on the latest global and internal events in real time..

Privacy Sandbox Initiative: Google to Phase Out Third-Party Cookies Starting 2024

22 May 2023
Google has announced plans to officially flip the switch on its twice-delayed Privacy Sandbox initiatives as it slowly works its way to deprecate support for third-party cookies in Chrome browser.

Are Your APIs Leaking Sensitive Data?

22 May 2023
It's no secret that data leaks have become a major concern for both citizens and institutions across the globe. They can cause serious damage to an organization's reputation, induce considerable financial losses, and even have serious legal repercussions. From the infamous Cambridge Analytica scandal to the Equifax data breach, there have been some pretty high-profile leaks resulting in massive

Ransomware threats are growing, and targeting Microsoft devices more and more

22 May 2023
Ransomware attacks have never been this popular, a new report from cybersecurity researchers Securin, Ivanti, and Cyware has stated. The report identified 12 vulnerabilities newly associated with ransomware in Q1 2023.

FTC Makes Moves to Enhance Data Privacy Oversight

22 May 2023
The FTC made a few bold moves to ramp up its oversight of data privacy, including an effort to codify sweeping changes to the Health Breach Notification Rule and releasing a policy statement warning of greater scrutiny over the use of biometric data.

Android phones are vulnerable to fingerprint brute-force attacks

22 May 2023
Researchers at Tencent Labs and Zhejiang University have presented a new attack called 'BrutePrint,' which brute-forces fingerprints on modern smartphones to bypass user authentication and take control of the device.

Investors Make $6M Bet on Manifest for SBOM Management Technology

22 May 2023
The seed round was led by First Round Capital and closes alongside news that Manifest secured two new contracts from the U.S. government to help federal agencies and the military understand what’s in the software that they use.