Latest Cybersecurity News and Articles


Never leak secrets to your GitHub repositories again

11 May 2023
Push protection stops the leaking of secrets by scanning a code commit before it gets pushed. Developers get alerted directly in their integrated development environment (IDE) or command line interface (CLI).

Dragos Says Ransomware Gang Accessed Limited Data but Failed at Extortion Scheme

11 May 2023
The industrial cybersecurity vendor said a known ransomware group breached its defenses and accessed threat intel reports, a SharePoint portal, and a customer support system but ultimately failed in an elaborate extortion scheme.

Company executives can’t afford to ignore cybersecurity anymore

11 May 2023
Asked about the Board and C-Suite‘s understanding of cybersecurity across the organization, only 39% of respondents think their company’s leadership has a sound understanding of cybersecurity’s role as a business enabler, according to Delinea.

Iranian Threat Groups Abuse PaperCut Flaw: Warns Microsoft

11 May 2023
A couple of Iranian state-sponsored groups were observed targeting a recently patched flaw in PaperCut MF/NG print management solutions. According to Microsoft, Mint Sandstorm and Mango Sandstorm modified their arsenal in accordance with publicly available PoC exploit codes. It is recommended defenders upgrade their PaperCut MF and PaperCut NG software to versions 20.1.7, 21.2.11, and 22.0.9 or newer, asap.

National Gallery of Canada recovering from ransomware incident

11 May 2023
The National Gallery of Canada first discovered the attack on April 23 and attempted to isolate the affected networks while hiring a cybersecurity company to conduct a forensic investigation.

Cactus Ransomware Encrypts Itself to Evade Detection

11 May 2023
Another ransomware operation has been unveiled called Cactus. Operating since at least March 2023, its unique feature is to encrypt itself to stay under the radar. The malware strain exploits known vulnerabilities in Fortinet VPN appliances. Organizations are urged to adopt a proactive defense strategy that includes applying the latest software updates.

New ransomware decryptor recovers data from partially encrypted files

11 May 2023
According to CyberArk, which developed and published the 'White Phoenix' encryptor, this tactic introduces weaknesses to the encryption, as leaving parts of the original files unencrypted creates the potential for free data recovery.

Andoryu Botnet Exploits Critical Ruckus Wireless Flaw for Widespread Attack

11 May 2023
A nascent botnet called Andoryu has been found to exploit a now-patched critical security flaw in the Ruckus Wireless Admin panel to break into vulnerable devices. The flaw, tracked as CVE-2023-25717 (CVSS score: 9.8), stems from improper handling of HTTP requests, leading to unauthenticated remote code execution and a complete compromise of wireless Access Point (AP) equipment. Andoryu was 

DarkWatchMan RAT Hides Data in Windows Registry to Evade Detection

11 May 2023
Researchers have identified a fraudulent website designed to deceive users by posing as the popular Russian platform CryptoPro CSP. Attackers drop DarkWatchman RAT during the attack to steal data. This innovative tactic places it in the category of fileless malware and indicates that the operators are highly sophisticated.

Twitter Finally Rolling Out Encrypted Direct Messages — Starting with Verified Users

11 May 2023
Twitter is officially beginning to roll out support for encrypted direct messages (DMs) on the platform, more than six months after its chief executive Elon Musk confirmed plans for the feature in November 2022. The "Phase 1" of the initiative will appear as separate conversations alongside existing direct messages on users' inboxes. Encrypted chats carry a lock icon badge to visually

GitHub Extends Push Protection to Prevent Accidental Leaks of Keys and Other Secrets

11 May 2023
GitHub has announced the general availability of a new security feature called push protection, which aims to prevent developers from inadvertently leaking keys and other secrets in their code. The Microsoft-owned cloud-based repository hosting platform, which began testing the feature a year ago, said it's also extending push protection to all public repositories at no extra cost. The

Experts challenge myths around reporting cyber attacks to help break cycle of crime

10 May 2023
Blog post from the NCSC and ICO aims to dispel common misconceptions that can discourage organisations from reporting a cyber attack.

Researchers Find Bypass for a Fixed Bug; MSFT Patches Again

10 May 2023
Microsoft patched the modified attack - tracked as CVE-2023-29324 - during this month's dump of fixes, rating the bug as "important" but not "critical." Researchers from Akamai, which found and disclosed the bug, say it merits a critical rating.

Google Announces New Privacy, Safety, and Security Features Across Its Services

10 May 2023
Google unveiled a slew of new privacy, safety, and security features today at its annual developer conference, Google I/O. The tech giant's latest initiatives are aimed at protecting its users from cyber threats, including phishing attacks and malicious websites, while providing more control and transparency over their personal data. Here is a short list of the newly introduced features -

Mastermind Behind Twitter 2020 Hack Pleads Guilty and Faces up to 70 Years in Prison

10 May 2023
Joseph James O'Connor, who also went by the online alias PlugwalkJoe, admitted to "his role in cyberstalking and multiple schemes that involve computer hacking, including the July 2020 hack of Twitter," the U.S. Department of Justice (DoJ) said.

77% of organizations plan to migrate to updated frameworks

10 May 2023
A report looks at the changes compliance, detailing how security leaders address compliance investments, framework updates, tooling and automation.

Siemens, Schneider Electric Address Few Dozen ICS Vulnerabilities

10 May 2023
Siemens has published six new advisories describing 26 vulnerabilities in Siveillance Video products, Cloud Connect 7, and more. Schneider Electric has published four new advisories that describe half a dozen vulnerabilities.

Smashing Pumpkins frontman paid ransom to a hacker who threatened to leak the band’s songs

10 May 2023
The frontman of the alternative rock band Smashing Pumpkins, Billy Corgan, revealed that he paid a ransom after a hacker stole the band’s songs and threatened to leak them.

Adobe Patches 14 Vulnerabilities in Substance 3D Painter

10 May 2023
Adobe has announced security updates for its Substance 3D Painter product to address more than a dozen vulnerabilities. This is the only product for which the software giant released updates this Patch Tuesday.

Australia's TechnologyOne halts trading after being hit by cyberattack

10 May 2023
Australia's TechnologyOne Ltd said on Wednesday it had detected an unauthorised third-party access to its back-office systems, becoming the latest target in a series of cyberattacks that has bogged companies in the country since last year.