Latest Cybersecurity News and Articles


CISA, FBI, and ACSC Confirm BianLian Ransomware's Switch to Extortion-Only Attacks

17 May 2023
A joint Cybersecurity Advisory from government agencies in the U.S. and Australia, and published by the CISA, is warning organizations of the latest tactics, techniques, and procedures (TTPs) used by the BianLian ransomware group.

Transportation Needs to Improve Cyber Policy Implementation, Watchdog Finds

17 May 2023
The Department of Transportation should better implement its policies for established cyber roles, including improving training and role expectations, according to a recent GAO report.

Franklin County Public Schools Hit by Ransomware Attack

17 May 2023
According to a statement from schools Superintendent Bernice Cobbs, the decision was made to cancel classes Monday in the interest of on-campus security as the impact of the cyberattack was being reviewed.

IBM snags Polar Security to boost cloud data practice

17 May 2023
In an effort to grow its hybrid cloud and artificial intelligence capabilities, IBM announced on Tuesday that it was acquiring Polar Security, an Israel-based company specializing in data security posture management.

The Africa factor: A history of geopolitical investment & colonization

17 May 2023
In this Cybersecurity & Geopolitical Discussion episode, Phillip Ingram and Ian Thornton-Trump discuss the background and recent events in Africa with guest Lisa Forte from Red Goat Cybersecurity.

State-Sponsored Sidewinder Hacker Group's Covert Attack Infrastructure Uncovered

17 May 2023
Cybersecurity researchers have unearthed previously undocumented attack infrastructure used by the prolific state-sponsored group SideWinder to strike entities located in Pakistan and China.

OilAlpha: Emerging Houthi-linked Cyber Threat Targets Arabian Android Users

17 May 2023
A hacking group dubbed OilAlpha with suspected ties to Yemen's Houthi movement has been linked to a cyber espionage campaign targeting development, humanitarian, media, and non-governmental organizations in the Arabian peninsula. "OilAlpha used encrypted chat messengers like WhatsApp to launch social engineering attacks against its targets," cybersecurity company Recorded Future said in a

US Offering $10M Reward for Russian Man Charged With Ransomware Attacks

17 May 2023
Mikhail Pavlovich Matveev, a 30-year-old Russian national, has been charged by the US Justice Department for his alleged role in numerous ransomware attacks, including ones targeting critical infrastructure.

Lea Kissner appointed as Lacework Chief Information Security Officer

17 May 2023
With more than 20 years of security industry experience, Lea Kissner has been named the new Chief Information Security Officer (CISO) at Lacework.

University Admission Platform Leverage EDU Exposed Student Passports, Applications

17 May 2023
Among the leaked data were degree certificates, student report cards, exam results, CVs, and filled application forms, along with phone numbers, emails, and home addresses.

NextGen Facing a Dozen Lawsuits So Far Following Breach

17 May 2023
Cloud-based EHR vendor NextGen Healthcare is facing a dozen proposed class action lawsuits filed during the last week in the same Georgia federal court following the company's disclosure this month of a data breach affecting one million individuals.

RecordBreaker Info-stealer Propagates Via Fake Keygens and Cracks

17 May 2023
AhnLab has uncovered yet another campaign dropping RecordBreaker Stealer, aka Raccoon Stealer V2, disguised as illegal software, such as cracks and keygens. It utilizes various channels, including websites and YouTube, as the means of distribution. Users should double-check the legitimacy of the website before downloading any software. 

Lacroix Shuts Three Factories For a Week After Cyberattack

17 May 2023
International electronics manufacturer Lacroix has reportedly intercepted a targeted cyberattack on its activity sites in France (Beaupréau), Germany (Willich), and Tunisia (Zriba).

Identifying a Patch Management Solution: Overview of Key Criteria

17 May 2023
Software is rarely a one-and-done proposition. In fact, any application available today will likely need to be updated – or patched – to fix bugs, address vulnerabilities, and update key features at multiple points in the future. With the typical enterprise relying on a multitude of applications, servers, and end-point devices in their day-to-day operations, the acquisition of a robust patch

Yum Brands faces class action suits from employees after ransomware attack

17 May 2023
Yum Brands is facing class action litigation in U.S. federal and state courts in connection with the January ransomware attack, the company said in a filing with the Securities and Exchange Commission last week.

Threat Group UNC3944 Abusing Azure Serial Console for Total VM Takeover

17 May 2023
A financially motivated cyber actor has been observed abusing Microsoft Azure Serial Console on virtual machines (VMs) to install third-party remote management tools within compromised environments. Google-owned Mandiant attributed the activity to a threat group it tracks under the name UNC3944, which is also known as Roasted 0ktapus and Scattered Spider. "This method of attack was unique in

Credit Control Corporation Hit by Major Data Breach Impacting 286,699 Individuals

17 May 2023
The breach, which occurred between March 2nd and March 7th, resulted in the theft of sensitive information, including names, addresses, Social Security numbers, and account details. It has potentially compromised the data of 286,699 individuals.

You may not care where you download software from, but malware does

17 May 2023
Even when security practitioners commonly advise people to only download software from reputable sites, people still download files from distinctly non-reputable places and get compromised as a result.

Hackers use Azure Serial Console for stealthy access to VMs

17 May 2023
A financially motivated cybergang tracked by Mandiant as 'UNC3944' is using phishing and SIM swapping attacks to hijack Microsoft Azure admin accounts and gain access to virtual machines.

WhatsApp allows users to lock sensitive chats

17 May 2023
Once activated, Chat Lock conveniently hides the conversation in a separate folder within the app, ensuring that it remains discreet and inaccessible from the regular inbox.