Latest Cybersecurity News and Articles


Ambulance Victoria data breach reveals drug and alcohol tests of graduate paramedics

11 May 2023
Ambulance Victoria data breach reveals drug and alcohol tests of graduate paramedics Privacy watchdog will be asked to investigate after information became available for all employees to view on the staff intranetGet our morning and afternoon news emails, free app or daily news podcastThe confidential drug and alcohol test results of graduate paramedics were available for every Ambulance Victoria staff member to view under a significant breach that is set to be reported to the state’s privacy watchdog.According to an email sent late Thursday to members of the Victorian Ambulance Union, confidential spreadsheets relating to pre-employment testing of graduate paramedics in 2017 and 2018 were available on the staff intranet until the union alerted Ambulance Victoria to the problem. Continue reading...

Babuk Source Code Sparks Nine Different Ransomware Strains Targeting VMware ESXi Systems

11 May 2023
Multiple threat actors have capitalized on the leak of Babuk (aka Babak or Babyk) ransomware code in September 2021 to build as many as nine different ransomware families capable of targeting VMware ESXi systems.

Transact appoints David Shaw as Chief Information Security Officer

11 May 2023
David Shaw has joined Transact Campus as CISO. Shaw has experience in identity & access management, regulatory compliance and incident response.

Ransomware insurance claims jump back up

11 May 2023
The number of ransomware claims filed by U.S. clients of insurance broker Marsh spiked 77% in the first quarter of the year compared with the prior three-month period, the company told CFO Dive.

Spanish Police Takes Down Massive Cybercrime Ring, 40 Arrested

11 May 2023
The National Police of Spain said it arrested 40 individuals for their alleged involvement in an organized crime gang called Trinitarians. Among those apprehended include two hackers who carried out bank scams through phishing and smishing techniques and 15 other members of the crime syndicate, who have all been charged with a number of offenses such as bank fraud, forging documents, identity

69% of IT professionals have adopted SLOs for the first time

11 May 2023
A recent survey indicates a focus on system reliability due to the pandemic driving cloud adoption, remote workers and supply chain issues. 

RedStinger Cyber Operations Target Eastern Europe Since 2020

11 May 2023
While looking for activities from the usual suspects, one of our former coworkers at Malwarebytes Threat Intelligence Team discovered a new interesting lure that targeted the Eastern Ukraine region and reported that finding to the public.

Security leaders chime in after ex-Uber security chief is sentenced

11 May 2023
An ex-Uber chief security officer has been sentenced to probation after being found guilty of trying to cover up a 2016 data breach.

Beware! Crooks are Using Malicious QR Codes to Steal Your Money

11 May 2023
The convenience of using QR codes is being abused by cybercriminals who are creating fraudulent QR codes for survey forms or parking ticket payment portals to rob users of their money and credentials. Follow the FBI’s advisory to avoid falling victim to such scams. 

Prevent attackers from using legitimate tools against you

11 May 2023
Malicious actors are increasingly exploiting legitimate tools to accomplish their goals, which include disabling security measures, lateral movement, and transferring files. Using commonly available tools allows attackers to evade detection.

AndoryuBot Botnet Leverages RCE Bug in Ruckus Wireless Access Points

11 May 2023
Wired and wireless networking equipment maker Ruckus was targeted by a DDoS botnet threat named AndoryuBot that has been exploiting a recently patched bug in Ruckus access points (APs). Upon infection, the botnet rapidly propagates and initiates communication with its command-and-control (C2) server using the SOCKS protocol.

Webb Raises $7 Million for Blockchain Asset Transfer Privacy System

11 May 2023
The new funding, the company says, will enable it to expand its employee base and accelerate the development of privacy solutions, such as a cross-chain messaging system.

New Phishing-as-a-Service Tool “Greatness” Already Seen in the Wild

11 May 2023
To use Greatness, affiliates must deploy and configure a provided phishing kit with an API key that allows even unskilled threat actors to easily take advantage of the service’s more advanced features.

New Akira Ransomware Threatens Corporate Networks for Million-dollar Ransom

11 May 2023
MalwareHunterTeam took the wraps off of the Akira ransomware group that has been penetrating corporate networks globally and subsequently asking for up to millions of dollars in ransom payments. For those not willing to pay for decryptors, criminals suggest reducing the ransom amount just to avoid data leaks. The malware first surfaced in March.

It’s becoming more common for ransomware to lock up data

11 May 2023
Threat actors encrypted data in three in four ransomware attacks last year, the highest rate of data encryption linked to ransomware in at least four years, according to research Sophos released Wednesday.

Russian Group Possibly Behind Cyberespionage in Central Asia

11 May 2023
A possibly Russian state hacking group has been deploying a novel backdoor against international governmental targets located in Kazakhstan and Afghanistan, reports Bitdefender.

Finding bugs in AI models at DEF CON 31

11 May 2023
DEF CON’s AI Village will host the first public assessment of large language models (LLMs) at the 31st edition of the hacker convention this August, aimed at finding bugs in and uncovering the potential for misuse of AI models.

Walden says cybersecurity strategy mostly well-received

11 May 2023
A variety of different threats come in on a daily basis, but the U.S. needs to be able to build a system that can withstand malicious activity regardless of where the threat is coming from, according to Acting National Cyber Director Kemba Walden.

How Attack Surface Management Supports Continuous Threat Exposure Management

11 May 2023
According to Forrester, External Attack Surface Management (EASM) emerged as a market category in 2021 and gained popularity in 2022. In a different report, Gartner concluded that vulnerability management vendors are expanding their offerings to include Attack Surface Management (ASM) for a suite of comprehensive offensive security solutions. Recognition from global analysts has officially put

Babuk Source Code Sparks 9 Different Ransomware Strains Targeting VMware ESXi Systems

11 May 2023
Multiple threat actors have capitalized on the leak of Babuk (aka Babak or Babyk) ransomware code in September 2021 to build as many as nine different ransomware families capable of targeting VMware ESXi systems. "These variants emerged through H2 2022 and H1 2023, which shows an increasing trend of Babuk source code adoption," SentinelOne security researcher Alex Delamotte said in a report