Latest Cybersecurity News and Articles


The warning signs for security analyst burnout and ways to prevent

02 May 2023
Security analysts face the demanding task of investigating and resolving increasing volumes of alerts daily, while adapting to an ever-changing threat landscape and keeping up with new technology.

Fortinet warns of a spike in attacks against TBK DVR devices

02 May 2023
FortiGuard Labs researchers are warning of a spike in malicious attacks targeting TBK DVR devices. Threat actors are attempting to exploit a five-year-old authentication bypass issue, tracked as CVE-2018-9995 (CVSS score of 9.8), in TBK DVR devices.

Data-driven insights help prevent decisions based on fear

02 May 2023
Organizations have strengthened security measures and become more resilient, but threat actors are still finding ways through, according to BakerHostetler. A reduction in ransomware matters in 2022 reversed course by the end of the year.

Australian Law Firm HWL Ebsworth Hit by Russian-linked Ransomware Attack

02 May 2023
Late last week, the ALPHV/Blackcat ransomware group posted on its website that 4TB of company data had been hacked, including employee CVs, IDs, financial reports, accounting data, client documentation, credit card data, and a complete network map.

Security leaders weigh in on school district ransomware attack

02 May 2023
A Minneapolis school district is still dealing with ramifications after being the victim of a ransomware attack earlier this year. Security leaders share their thoughts. 

UK locks horns with WhatsApp over threat to break encryption

02 May 2023
The Online Safety Bill, the United Kingdom’s landmark effort to regulate social media giants, gives regulator Ofcom the power to require tech companies to identify child sex abuse material in private messages.

T-Mobile Discloses Second Data Breach Since the Start of 2023

02 May 2023
After detecting the security breach, T-Mobile proactively reset account PINs for impacted customers and now offers them two years of free credit monitoring and identity theft detection services through Transunion myTrueIdentity.

BouldSpy Android Spyware: Iranian Government's Alleged Tool for Spying on Minority Groups

02 May 2023
A new Android surveillanceware possibly used by the Iranian government has been used to spy on over 300 individuals belonging to minority groups. The malware, dubbed BouldSpy, has been attributed with moderate confidence to the Law Enforcement Command of the Islamic Republic of Iran (FARAJA). Targeted victims include Iranian Kurds, Baluchis, Azeris, and Armenian Christian groups. "The spyware

Why Telecoms Struggle with SaaS Security

02 May 2023
The telecom industry has always been a tantalizing target for cybercriminals. The combination of interconnected networks, customer data, and sensitive information allows cybercriminals to inflict maximum damage through minimal effort. It’s the breaches in telecom companies that tend to have a seismic impact and far-reaching implications — in addition to reputational damage, which can be

Bitmarck Shuts Down Systems, Services After Cyberattack

02 May 2023
The company said no customer, patient, or insured individuals' data had been accessed in the security breach — at least not according to "the current state of knowledge," according to an April 30 update posted on its temporary website.

Labor to appoint dedicated privacy commissioner to combat data breaches

02 May 2023
Labor to appoint dedicated privacy commissioner to combat data breaches The Office of the Australian Information Commissioner will also be restored to a three-commissioner structure after defunding by CoalitionGet our morning and afternoon news emails, free app or daily news podcastThe federal government will appoint a dedicated privacy commissioner to deal with the increasing threat of data breaches, the attorney general has announced.Mark Dreyfus revealed late on Tuesday evening that the Albanese government would also restore the Office of the Australian Information Commissioner (OAIC) to a three-commissioner structure, saying the appointments were necessary to deal with “the growing threats to data security and the increasing volume and complexity of privacy issues”. Continue reading...

The costly threat that many businesses fail to address

02 May 2023
Insider attacks such as fraud, sabotage, and data theft plague 71% of U.S. businesses, according to Capterra. These schemes can cost companies hundreds of thousands of dollars.

Apple releases first 'rapid' security fixes for iPhones, iPads and Macs

02 May 2023
The "rapid security patch" rollout on Monday hasn’t gone so smoothly. Some customers said that they could not install the update. When TechCrunch tested on an iPhone, iPad, and Mac, the updates downloaded but did not immediately install.

North Korea's ScarCruft Deploys RokRAT Malware via LNK File Infection Chains

02 May 2023
The North Korean threat actor known as ScarCruft began experimenting with oversized LNK files as a delivery route for RokRAT malware as early as July 2022, the same month Microsoft began blocking macros across Office documents by default.

Alert: Active Exploitation of TP-Link, Apache, and Oracle Vulnerabilities Detected

02 May 2023
The three flaws added to the Known Exploited Vulnerabilities (KEV) catalog are CVE-2023-1389 in TP-Link Archer AX-21, CVE-2021-45046 in Apache Log4j2, and CVE-2023-21839 in Oracle WebLogic Server.

LOBSHOT: A Stealthy, Financial Trojan and Info Stealer Delivered through Google Ads

02 May 2023
In yet another instance of how threat actors are abusing Google Ads to serve malware, a threat actor has been observed leveraging the technique to deliver a new Windows-based financial trojan and information stealer called LOBSHOT. "LOBSHOT continues to collect victims while staying under the radar," Elastic Security Labs researcher Daniel Stepanic said in an analysis published last week. "One

North Korea's ScarCruft Deploys RokRAT Malware via LNK File Infection Chains

02 May 2023
The North Korean threat actor known as ScarCruft began experimenting with oversized LNK files as a delivery route for RokRAT malware as early as July 2022, the same month Microsoft began blocking macros across Office documents by default. "RokRAT has not changed significantly over the years, but its deployment methods have evolved, now utilizing archives containing LNK files that initiate

Alert: Active Exploitation of TP-Link, Apache, and Oracle Vulnerabilities Detected

02 May 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three flaws to the Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The security vulnerabilities are as follows - CVE-2023-1389 (CVSS score: 8.8) - TP-Link Archer AX-21 Command Injection Vulnerability CVE-2021-45046 (CVSS score: 9.0) - Apache Log4j2 Deserialization of Untrusted

Australian law firm HWL Ebsworth hit by Russian-linked ransomware attack

01 May 2023
Australian law firm HWL Ebsworth hit by Russian-linked ransomware attack Cyberattack resulted in hacking of 4TB of data including IDs, finance reports, accounting data, client documents and credit card detailsFollow our Australia news live blog for the latest updatesGet our morning and afternoon news emails, free app or daily news podcastThe Australian commercial law firm HWL Ebsworth has fallen victim to a ransomware attack, with Russian-linked hackers claiming to have obtained client information and employee data.Late last week, the ALPHV/Blackcat ransomware group posted on its website that 4TB of company data had been hacked, including employee CVs, IDs, financial reports, accounting data, client documentation, credit card information, and a complete network map.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...

US Wellness confirms data security incident

01 May 2023
US Wellness announced it was the victim of a ransomware attack that may have involved protected health information belonging to members of its wellness clients.