Latest Cybersecurity News and Articles


Samsung Devices Under Active Exploitation! CISA Warns of Critical Flaw

20 May 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a medium-severity flaw affecting Samsung devices. The issue, tracked as CVE-2023-21492 (CVSS score: 4.4), impacts select Samsung devices running Android versions 11, 12, and 13. The South Korean electronics giant described the issue as an information disclosure flaw that could be exploited by a

ScanSource suffers ransomware attack

19 May 2023
Hybrid distributor ScanScource announced that the company had suffered a ransomware attack and has implemented their incident response plan.

Dole incurs $10.5M in direct costs from February ransomware attack

19 May 2023
About $4.8 million of those costs were related to continuing operations. The attack had a limited overall impact on its operations, with the main disruption occurring in its fresh vegetables and Chilean business.

Update: Food distributor Sysco says cyberattack potentially leaked 125,000 Social Security numbers

19 May 2023
A cyberattack on Sysco, one of the world’s largest food distributors, gave hackers access to the sensitive personal information of more than 125,000 current and former employees.

Researchers Identify Second Developer of ‘Golden Chickens’ Malware

19 May 2023
Offered under a malware-as-a-service (MaaS) model since 2018, Golden Chickens has been used by the Russia-based Cobalt Group and FIN6 cybercrime rings to target organizations in various industries, causing financial losses or more than $1.4 billion.

Accenture Ventures Invests in SpiderOak

19 May 2023
Accenture has made a strategic investment, through Accenture Ventures, in SpiderOak, a Reston, Virginia-based leader in zero-trust cybersecurity and resiliency solutions for next-generation space systems. The amount of the deal was not disclosed.

Analysis of the CloudWizard framework by Bad Magic APT

19 May 2023
A newly discovered campaign related to the Bad Magic APT involved use of a modular framework dubbed CloudWizard. Its features include taking screenshots, microphone recording, keylogging, and more.

Industrial Secure Remote Access Is Essential, but Firms Concerned About Risks

19 May 2023
Secure remote access is essential for industrial organizations, but many employees who took part in a recent survey by Cyolo expressed concerns about the associated risks.

FTC warns against biometric misuse

19 May 2023
The rising use of biometric information has caused the FTC to issue a policy warning against the new technology and its potential misuse.

Update: Luxottica confirms 2021 data breach after info of 70M leaks online

19 May 2023
After BleepingComputer contacted Luxottica about the published data, the firm confirmed that the leaked data came from a security incident that impacted a third-party contractor holding customer data.

18-year-old charged with hacking 60,000 DraftKings betting accounts

19 May 2023
The Department of Justice revealed today that an 18-year-old man named Joseph Garrison from Wisconsin had been charged with hacking into the accounts of around 60,000 users of the DraftKings sports betting website in November 2022.

Gentex Confirms Data Breach by Dunghill Ransomware Actors

19 May 2023
Dunghill sent an email to TechTarget Editorial with a link to a Tor site that allegedly contained 5 TB of sensitive corporate data, including emails, client documents, and the personal data of 10,000 Gentex employees such as Social Security numbers.

UK steel industry supplier Vesuvius says ‘cyber incident’ cost $4.6 million

19 May 2023
In a statement on Thursday to the Regulatory News Service — the formal mechanism for publicly listed companies in the U.K. to communicate to the market — Vesuvius said despite the episode, it had exceeded trading expectations.

Privacy Sandbox Initiative: Google to Phase Out Third-Party Cookies Starting 2024

19 May 2023
Google has announced plans to officially flip the switch on its twice-delayed Privacy Sandbox initiatives as it slowly works its way to deprecate support for third-party cookies in Chrome browser. To that end, the search and advertising giant said it intends to phase out third-party cookies for 1% of Chrome users globally in the first quarter of 2024. "This will support developers in conducting

Two NPM Packages for Node.js Hiding Dangerous TurkoRat Malware

19 May 2023
The packages – named nodejs-encrypt-agent and nodejs-cookie-proxy-agent – were collectively downloaded approximately 1,200 times and were available for more than two months before they were identified and taken down.

Jonathan Hale joins Security Validation as Chief Technology Officer

19 May 2023
Security Validation has recently announced the appointment of Jonathan Hale as the new Chief Technology Officer.

Eye insurance firm agrees to $2.5 million settlement with state AGs after data breach

19 May 2023
EyeMed Vision Care, a major eye insurance provider, will pay a fine of $2.5 million after settling a lawsuit from four states about a 2020 data breach that exposed the personal information of about 2.1 million people.

LockBit Leaks 1.5TB of Data Stolen From Indonesia's BSI Bank

19 May 2023
The LockBit ransomware group on Tuesday published 1.5 terabytes of personal and financial information the group said it stole from Bank Syariah Indonesia after ransom negotiations broke down.

Dr. Active Directory vs. Mr. Exposed Attack Surface: Who'll Win This Fight?

19 May 2023
Active Directory (AD) is among the oldest pieces of software still used in the production environment and can be found in most organizations today. This is despite the fact that its historical security gaps have never been amended. For example, because of its inability to apply any security measures beyond checking for a password and username match, AD (as well the resources it manages) is

Google Announces New Rating System for Android and Device Vulnerability Reports

19 May 2023
The new quality rating system, the internet giant says, should encourage researchers to provide more details on the identified security defects and should also help address them faster.