Latest Cybersecurity News and Articles


PyPI Repository temporarily suspends user sign-ups and package uploads due to ongoing attacks

22 May 2023
The threat actors publish malicious packages to the PyPI repository and attempt to trick developers into using them using social engineering tricks, such as intentional typos in their names and high version numbers.

Rackspace gets San Antonio federal judge to toss proposed class-action suit over ransomware attack

22 May 2023
U.S. District Judge Xavier Rodriguez on Thursday sided with Rackspace in dismissing litigation that had been brought by 37 plaintiffs from across the U.S. who lost access to email and related data as a result of the December 2022 attack.

U.K. Fraudster Behind iSpoof Scam Receives 13-Year Jail Term for Cyber Crimes

22 May 2023
A U.K. national responsible for his role as the administrator of the now-defunct iSpoof online phone number spoofing service has been sentenced to 13 years and 4 months in prison. Tejay Fletcher, 35, of Western Gateway, London, was awarded the sentence on May 18, 2023. He pleaded guilty last month to a number of cyber offenses, including facilitating fraud and possessing and transferring

KeePass Exploit Allows Attackers to Recover Master Passwords from Memory

22 May 2023
A proof-of-concept (PoC) has been made available for a security flaw impacting the KeePass password manager that could be exploited to recover a victim's master password in cleartext under specific circumstances. The issue, tracked as CVE-2023-32784, impacts KeePass versions 2.x for Windows, Linux, and macOS, and is expected to be patched in version 2.54, which is likely to be released early

PyPI Repository Under Attack: User Sign-Ups and Package Uploads Temporarily Halted

21 May 2023
The maintainers of Python Package Index (PyPI), the official third-party software repository for the Python programming language, have temporarily disabled the ability for users to sign up and upload new packages until further notice. "The volume of malicious users and malicious projects being created on the index in the past week has outpaced our ability to respond to it in a timely fashion,

CommonMagic Implants Linked to CloudWizard

20 May 2023
The APT campaign employs a modular framework called CloudWizard. This framework is capable of taking screenshots, keylogging, and recording audio from the microphone. The CloudWizard framework comprises nine modules that enable a variety of hacking capabilities.

Malicious VSCode Extensions: Password Theft and Remote Shell Exploits

20 May 2023
Check Point took the wraps off of three malicious Microsoft Visual Studio extensions on May 4, 2023, aimed at exploiting VSCode Marketplace visitors. These extensions named Theme Darcula dark, python-vscode, and prettiest java, were downloaded by Windows developers nearly 46,000 times. Actors could pilfer credentials, collect system information, and establish a remote shell on the victim's machine.

Experts Warn of Voice Cloning-as-a-Service

20 May 2023
Security experts are warning of surging threat actor interest in voice cloning-as-a-service (VCaaS) offerings on the dark web, designed to streamline deepfake-based fraud.

Meet 'Jack' from Romania! Mastermind Behind Golden Chickens Malware

20 May 2023
The identity of the second threat actor behind the Golden Chickens malware has been uncovered courtesy of a fatal operational security blunder, cybersecurity firm eSentire said. The individual in question, who lives in Bucharest, Romania, has been given the codename Jack. He is one of the two criminals operating an account on the Russian-language Exploit.in forum under the name "badbullzvenom,"

Researchers tie FIN7 cybercrime family to Clop ransomware

20 May 2023
Long-running cybercrime cartel FIN7, which has made use of ransomware variants developed by groups including REvil and Maze, has added another strain to its arsenal. This time, its the Cl0p ransomware.

Newcomer MalasLocker Group Demands Ransom as Donation for Charity

20 May 2023
MalasLocker emerged as a new ransomware operation, since the end of March, targeting Zimbra servers. The group gains access to servers by exploiting vulnerabilities in Zimbra software. Instead of demanding a ransom payment, MalasLocker demands a donation to a charity to provide a decryptor and prevent data leakage. The group’s data leak site has three companies listed currently, along with Zimbra configuration details for 169 other targeted victims.

Phishing Vendor Sells IP Addresses to Duck Anomaly Detection

20 May 2023
BulletProofLink, also referred to as BulletProftLink or Anthrax, sells access to phishing kits, email templates, hosting, and automated series "at a relatively low cost".

UNC3944 Threat Group Uses Azure Built-in Tools to Abuse Azure VMs

20 May 2023
Financially-motivated UNC3944 gang was found using phishing and SIM swapping attacks to hijack Microsoft Azure admin accounts and gain access to virtual machines to steal data from victim organizations. The threat actor gains initial access to an Azure administrator's account by using stolen credentials obtained through SMS phishing. Experts recommend organizations should restrict access to remote administration channels on all Azure services.

CISA warns of Samsung ASLR bypass flaw exploited in attacks

20 May 2023
The vulnerability, tracked as CVE-2023-21492, impacts Samsung mobile devices running Android 11, 12, and 13 and is due to an insertion of sensitive information into log files.

Mustang Panda Hijacks TP-Link Routers of European Foreign Affairs Entities

20 May 2023
European foreign affairs organizations are being targeted by a Chinese state-sponsored Camaro Dragon hacking group with a custom malware variant. This group has been found infecting residential TP-Link routers with a specialized malware called Horse Shell. Attackers can execute arbitrary commands, steal files, and even leverage the malware as a SOCKS proxy to facilitate communication between various devices.

Golang Variant of Cobalt Strike 'Geacon' Targets macOS

20 May 2023
There is a growing trend in utilizing Geacon (a Golang implementation of the Cobalt Strike beacon), to target macOS devices, revealed SentinelOne. The package appeared specifically crafted to first verify its execution on a macOS system and subsequently retrieve an unsigned 'Geacon Plus' payload from a C2 server in China.

Pimcore Platform Flaws Exposed Users to Code Execution

20 May 2023
Security researchers are warning that vulnerabilities patched in the open-source Pimcore platform could have led to the execution of arbitrary code when clicking on a link.

Notorious Cyber Gang FIN7 Returns Cl0p Ransomware in New Wave of Attacks

20 May 2023
The notorious cybercrime group known as FIN7 has been observed deploying Cl0p (aka Clop) ransomware, marking the threat actor's first ransomware campaign since late 2021. Microsoft, which detected the activity in April 2023, is tracking the financially motivated actor under its new taxonomy Sangria Tempest. "In these recent attacks, Sangria Tempest uses the PowerShell script POWERTRASH to load

Microsoft Warns of Increase in Business Email Compromise Attacks

20 May 2023
Microsoft has released a new report warning companies about the alarming surge in business email compromise (BEC) attacks and the evolving tactics employed by cybercriminals.

Minas — a multi-stage cryptocurrency miner infection

20 May 2023
In June 2022, Kaspersky researchers found a suspicious shellcode running in the memory of a system process. Based on their reconstruction of the infection chain, they determined that it originated from running an encoded PowerShell script as a task.