Latest Cybersecurity News and Articles


QR codes used in fake parking tickets, surveys to steal your money

08 May 2023
As QR codes continue to be heavily used by legitimate organizations—from Super Bowl advertisements to enforcing parking fees and fines, scammers have crept in to abuse the very technology for their nefarious purposes.

Kenya: Kabarak University ICT Manager suspended as hackers table their demand

08 May 2023
Kabarak University's Facebook account was seized by hackers who have been using it to spread malicious and misleading images and content that contravenes the institution’s Christian values and have since tabled their demands.

Cyberattack at Hong Kong healthcare group may have exposed 100,000 patients’ data

08 May 2023
OT&P Healthcare CEO Robin Green on Monday said the cyberattack took place within the clinic’s management and operating system. “That system holds both patient identity and medical records. We have no idea … how much data was taken,” he said.

White House official says Counter Ransomware Initiative focused on ‘expanding the tent,’ with Jordan, Costa Rica, Colombia joining

08 May 2023
According to White House Deputy National Security Adviser Anne Neuberger, there were more than 6,500 ransomware attacks across the globe between 2020 and 2022, prompting difficult discussions about ways to disrupt the ecosystem.

MSI Data Breach: Private Code Signing Keys Leaked on the Dark Web

08 May 2023
The threat actors behind the ransomware attack on Taiwanese PC maker MSI last month have leaked the company's private code signing keys on their dark website. "Confirmed, Intel OEM private key leaked, causing an impact on the entire ecosystem," Alex Matrosov, founder and CEO of firmware security firm Binarly, said in a tweet over the weekend. "It appears that Intel Boot Guard may not be

One Million Impacted by Data Breach at NextGen Healthcare

08 May 2023
Headquartered in Atlanta, Georgia, the company makes and sells electronic health records software and provides doctors and medical professionals with practice management services.

SideCopy Using Action RAT and AllaKore RAT to Infiltrate Indian Organizations

08 May 2023
The suspected Pakistan-aligned threat actor known as SideCopy has been observed leveraging themes related to the Indian military research organization as part of an ongoing phishing campaign.

Western Digital Confirms Customer Data Stolen by Hackers in March Breach

08 May 2023
Digital storage giant Western Digital confirmed that an "unauthorized third party" gained access to its systems and stole personal information belonging to the company's online store customers. "This information included customer names, billing and shipping addresses, email addresses and telephone numbers," the San Jose-based company said in a disclosure last week. "In addition, the database

New Akira Ransomware Operation Targeting the Enterprise

08 May 2023
Launched in March 2023, Akira claims to have already conducted attacks on sixteen companies. These companies are in various industries, including education, finance, real estate, manufacturing, and consulting.

Join Our Webinar: Learn How to Defeat Ransomware with Identity-Focused Protection

08 May 2023
Are you concerned about ransomware attacks? You're not alone. In recent years, these attacks have become increasingly common and can cause significant damage to organizations of all sizes. But there's good news - with the right security measures in place, such as real-time MFA and service account protection, you can effectively protect yourself against these types of attacks. That's why we're

SideCopy Using Action RAT and AllaKore RAT to infiltrate Indian Organizations

08 May 2023
The suspected Pakistan-aligned threat actor known as SideCopy has been observed leveraging themes related to the Indian military research organization as part of an ongoing phishing campaign. This involves using a ZIP archive lure pertaining to India's Defence Research and Development Organization (DRDO) to deliver a malicious payload capable of harvesting sensitive information, Fortinet

Franklin Jackson named new CIO at CyberCatch Holdings, Inc

08 May 2023
This week, CyberCatch Holdings, Inc. announced Franklin Jackson will serve as the company's Vice President, CIO and Head of Global Security Advisory Services.

Australia: Sydney-based cancer center is the latest victim of a cyberattack

08 May 2023
It seems hardly a day goes by without another report of a cybercrime incident. With Medibank still fresh in our minds, the latest attack is on a Sydney-based cancer treatment facility, Crown Princess Mary Cancer Centre in Westmead Hospital.

Twitter Admits to ‘Security Incident’ Involving Circles Tweets

08 May 2023
A privacy breach at Twitter published tweets that were never supposed to be seen by anyone but the poster’s closest friends to the site at large, the company has admitted after weeks of stonewalling reports.

Review your on-prem ADCS infrastructure before attackers do it for you

08 May 2023
Attacks through Active Directory Certificate Services are fairly easy for bad actors to perform but basic vigilance and built-in Windows protections can help mitigate the risk of a breach.

CERT-UA Warns of an Ongoing SmokeLoader Malware Campaign

08 May 2023
SmokeLoader acts as a loader for other malware, once it is executed it will inject malicious code into the currently running explorer process (explorer.exe) and downloads another payload to the system.

How to Set Up a Threat Hunting and Threat Intelligence Program

08 May 2023
Threat hunting is an essential component of your cybersecurity strategy. Whether you're getting started or in an advanced state, this article will help you ramp up your threat intelligence program. What is Threat Hunting? The cybersecurity industry is shifting from a reactive to a proactive approach. Instead of waiting for cybersecurity alerts and then addressing them, security organizations are

New Cactus Ransomware Encrypts Itself to Evade Antivirus

08 May 2023
Researchers at Kroll corporate investigation and risk consulting firm believe that Cactus obtains initial access into the victim network by exploiting known vulnerabilities in Fortinet VPN appliances.

FluHorse: New Android Threat Stealing 2FA Codes and Passwords

08 May 2023
Check Point spotted a new malware strain, named FluHorse, masquerading as popular Android apps from East Asia. Each of these apps has been installed over 100,000 times. FluHorse is created to pilfer personal information such as usernames, passwords, and 2FA codes. Individuals and organizations must take proactive measures to safeguard against these threats. 

New PaperCut RCE exploit created that bypasses existing detections

08 May 2023
VulnCheck explains that Sysmon-based detections relying on process creation analysis are already beaten by existing PoCs that use alternate child process creation pathways.