Latest Cybersecurity News and Articles


Card Skimmers and ATMs Used to Drain EBT Accounts in SoCal

03 May 2023
The suspects are accused of using card skimmers and ATMs to drain electronic benefit transfer (EBT) accounts, which are used to pay for food through the Supplemental Nutrition Assistance Program (SNAP).

How AI and other technologies have changed password management

03 May 2023
AI has changed the way security leaders look at passwords. Learn more in this Security podcast episode with Parteek Saran, founder and CEO of Uno. 

Häfele recovers from ransomware attack with new SASE platform

03 May 2023
An international manufacturer and supplier of furniture fittings, recovered from a recent ransomware attack after utilizing a single-vendor SASE platform. 

Attacks increasingly use malicious HTML email attachments

03 May 2023
Researchers warn that attackers are relying more on malicious HTML files in their attacks, with malicious files now accounting for half of all HTML attachments sent via email.

Google will remove secure website indicators in Chrome 117

03 May 2023
The lock icon will be changed in Chrome 117 with a "variant of the tune icon," a user interface element commonly linked to app settings and designed to show that it's a clickable item.

Google Introduces Passwordless Secure Sign-In with Passkeys for Google Accounts

03 May 2023
Almost five months after Google added support for passkeys to its Chrome browser, the tech giant has begun rolling out the passwordless solution across Google Accounts on all platforms. Passkeys, backed by the FIDO Alliance, are a more secure way to sign in to apps and websites without having to use a traditional password. This, in turn, can be achieved by simply unlocking their computer or

Apple and Google try anti-stalking spec for Bluetooth tags

03 May 2023
Though Tile has been selling Bluetooth Low Energy (BLE) wireless tracking tags for a decade, it wasn't until 2021, when Samsung introduced its Galaxy SmartTag and Apple introduced its AirTag, that reports of abuse of the devices became commonplace.

Chinese Hacker Group Earth Longzhi Resurfaces with Advanced Malware Tactics

03 May 2023
A Chinese state-sponsored hacking outfit has resurfaced with a new campaign targeting government, healthcare, technology, and manufacturing entities based in Taiwan, Thailand, the Philippines, and Fiji after more than six months of no activity. Trend Micro attributed the intrusion set to a cyber espionage group it tracks under the name Earth Longzhi, which is a subgroup within APT41 (aka HOODOO

Tython: Open-source Security as Code framework and SDK

03 May 2023
Tython revolutionizes how security and development teams operate and collaborate — it democratizes security for developers, enables development and security to work autonomously, and creates shared responsibility around security.

Meta Warns of Cyberespionage Campaigns Targeting Military Personnel in South Asia

03 May 2023
State-linked hackers in Pakistan have been spying on military personnel in India and the Pakistan Air Force using fake apps and websites to compromise their personal devices, Meta announced on Wednesday.

Danish Customers Targeted by Active PostNord DK Phishing Campaign

03 May 2023
According to a tip sent to Heimdal by an anonymous reader, the APT’s choice in phishing is an email in which the victim is informed about the status of an unclaimed postal package.

Malicious content lurks all over the web

03 May 2023
On average, five out of every 1,000 enterprise users attempted to download malware in Q1 2023, and new malware families and variants represented 72% of those malware downloads, according to Netskope.

How Tax Credits Could Present Near-Term Motivation for More Secure Devices

03 May 2023
During a House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection hearing on Thursday, CISA Director Jen Easterly told lawmakers that “innovation should not trump safety and security in a world where we all rely on tech.”

Level Finance Crypto Exchange Hacked to Steal $1.1 Million Worth of Tokens

03 May 2023
Hackers exploited a Level Finance smart contract vulnerability to drain 214,000 LVL tokens from the decentralized exchange and swapped them for 3,345 BNB, worth approximately $1,100,000.

1Password explains scary Secret Key and password change alerts

03 May 2023
The company first revealed in an incident report five days ago that the notifications were erroneous and linked to routine database maintenance scheduled on Thursday, April 27th.

Download the eBook: What Does it Take to be a Full-Fledged Virtual CISO?

03 May 2023
Almost half of MSP clients fell victim to a cyberattack within the last 12 months. In the SMB world, the danger is especially acute as only 50% of SMBs have a dedicated internal IT person to take care of cybersecurity. No wonder cybercriminals are targeting SMBs so heavily. No wonder SMBs are increasingly willing to pay a subscription or retainer to gain access to expert C-level cyber-assistance

Operation SpecTor: $53.4 Million Seized, 288 Vendors Arrested in Dark Web Drug Bust

03 May 2023
An international law enforcement operation has resulted in the arrest of 288 vendors who are believed to be involved in drug trafficking on the dark web, adding to a long list of criminal enterprises that have been shuttered in recent years. The effort, codenamed Operation SpecTor, also saw the authorities confiscating more than $53.4 million in cash and virtual currencies, 850 kg of drugs, and

Fake ChatGPT desktop client steals Chrome login data

03 May 2023
ChatGPT has not released an official desktop client, but this bogus version looks remarkably similar to what one would expect. The infostealer is being distributed via a zip archive carrying a file named ChatGPT For Windows Setup 1.0.0.exe.

Easily exploitable flaw in Oracle Opera could spell trouble for hotel chains

03 May 2023
A recently fixed vulnerability in Oracle Opera, a property management system widely used in hotel and resort chains, is more critical than what Oracle says and could be exploited by unauthenticated remote attackers to access sensitive information.

Mullvad VPN’s Office Raided By Police for User Data

03 May 2023
The police’s search may have been part of an investigation into hackers who often use VPN services to hide their cybercrime. Mullvad is a VPN service that is known for its strict privacy policy and does not require user registration upon connection.