Latest Cybersecurity News and Articles


BPFDoor Backdoor Gets Stealthier with New Variant

15 May 2023
Cybersecurity experts took the wraps off of a newer variant of BPFDoor (BPF stands for Berkeley Packet Filter), which is capable of maintaining persistent access to breached systems for extended periods. The new variant has remained entirely undetected by all the virus-detection engines on VirusTotal.  To mitigate the risks associated with BPFDoor, admins should prioritize rigorous monitoring of network traffic and logs.

Rise in Attacks Against ESXi: Babuk Source Code Inspires Nine Different Ransomware Strains

15 May 2023
SentinelLabs detected 10 ransomware families employing VMware ESXi lockers, derived from the leaked 2021 Babuk source code. These variants emerged between H2 2022 and H1 2023. The report also highlights similarities between Babuk's source code and the ESXi encrypters used by Conti and REvil, indicating some connection between them.

90% of small business leaders underestimate cyber incident costs

15 May 2023
A new report reveals that 91% of SMEs with a cyber insurance policy say that their insurance provider helped them avoid potential incidents.

Newly identified RA Group compromises companies in U.S. and South Korea with leaked Babuk source code

15 May 2023
The group is swiftly expanding its operations. To date, it has compromised three organizations in the U.S. and one in South Korea across several business verticals, including manufacturing, wealth management, insurance providers, and pharmaceuticals.

Illinois Data Breach Exposes Private Information of Medicaid, SNAP, and TANF Recipients

15 May 2023
The Illinois Department of Healthcare and Family Services (HFS) and Department of Human Services (IDHS) have disclosed a data breach within the State of Illinois Application for Benefits Eligibility (ABE) system’s Manage My Case (MMC) portal.

New 'MichaelKors' Ransomware-as-a-Service Targeting Linux and VMware ESXi Systems

15 May 2023
The targeting of VMware ESXi hypervisors with ransomware to scale such campaigns is a technique known as hypervisor jackpotting. Over the years, the approach has been adopted by several ransomware groups, including Royal.

Insured companies more likely to be ransomware victims, sometimes more than once

15 May 2023
Although threat actors may not be directly correlating the insurance factor to find targets, a reason for this may be that as insurers require more from companies those able to pay for insurance are also likely to be able to afford bigger ransoms.

PharMerica Discloses Data Breach Impacting 5.8 Million Individuals

15 May 2023
PharMerica’s letter does not provide details on the type of cyberattack that it suffered, but it appears that the Money Message ransomware group is responsible for the incident the group started leaking PII and PHI allegedly stolen from PharMerica.

Update: Capita warns customers they should assume data was stolen

15 May 2023
Almost six weeks after the attack was disclosed, Capita warned Universities Superannuation Scheme (USS), the largest private pension scheme in the UK, to react to the incident under the assumption that their members' data was stolen.

CLR SqlShell Malware Targets MS SQL Servers for Cryptomining and Ransomware

15 May 2023
Poorly managed Microsoft SQL (MS SQL) servers are the target of a new campaign that's designed to propagate a category of malware called CLR SqlShell that ultimately facilitates the deployment of cryptocurrency miners and ransomware.

Financial sector has highest password reuse rate

15 May 2023
Employee exposure was measured in a report that observed a 62% password reuse rate among Fortune 1000 employees who have been exposed more than once. 

Russia-Affiliated CheckMate Ransomware Quietly Targets Popular File-Sharing Protocol

15 May 2023
After gaining access to SMB shares, threat actors behind CheckMate ransomware encrypt all files and leave a ransom note demanding payment in exchange for the decryption key.

CISA Warns of Several Old Linux Vulnerabilities Exploited in Attacks

15 May 2023
One aspect all the vulnerabilities appear to have in common is their connection to Linux, which indicates that they might have been leveraged in attacks on Linux systems.

Industrial Cellular Routers at Risk: 11 New Vulnerabilities Expose OT Networks

15 May 2023
Several security vulnerabilities have been disclosed in cloud management platforms associated with three industrial cellular router vendors that could expose operational technology (OT) networks to external attacks. The findings were presented by Israeli industrial cybersecurity firm OTORIO at the Black Hat Asia 2023 conference last week. The 11 vulnerabilities allow "remote code execution and

Philadelphia Inquirer Hit by Cyberattack Causing Newspaper’s Largest Disruption in Decades

15 May 2023
The company was working to restore print operations after a cyber incursion that prevented the printing of the newspaper’s Sunday print edition, the Inquirer reported on its website.

Former Ubiquiti Employee Gets Six Years in Jail for $2 Million Crypto Extortion Case

15 May 2023
A former employee of Ubiquiti has been sentenced to six years in jail after he pleaded guilty to posing as an anonymous hacker and a whistleblower in an attempt to extort almost $2 million worth of cryptocurrency while working at the company.

Red Stinger APT Group Targeting Ukrainian Military, Transport Orgs Since 2020

15 May 2023
Red Stinger, a newly discovered advanced persistent threat (APT) actor, has been found conducting targeted attacks in Ukraine since 2020. Military, transportation, and critical infrastructure entities were among their primary targets, along with organizations involved in the September East Ukraine referendums. The attackers utilized various techniques, including exfiltration of data like snapshots, USB drives, keystrokes, and microphone recordings.

Personal Information of 90,000 Hikers Leaked by French Tourism Company La Malle Postale

15 May 2023
Researchers also stumbled upon 70,000 customer credentials. Although leaked passwords were not in plain text, they were hashed using the easily crackable WordPress MD5/phpass hashing algorithm.

New Ransomware Gang RA Group Hits U.S. and South Korean Organizations

15 May 2023
A new ransomware group known as RA Group has become the latest threat actor to leverage the leaked Babuk ransomware source code to spawn its own locker variant. The cybercriminal gang, which is said to have been operating since at least April 22, 2023, is rapidly expanding its operations, according to cybersecurity firm Cisco Talos. "To date, the group has compromised three organizations in the

Brave unveils new "Forgetful Browsing" anti-tracking feature

15 May 2023
This new feature will clear not only cookies at the sites you specify but also data in local storage and the cache when you close a website. While this will also log users out of sites, it also prevents re-identification when they return to the site.