Latest Cybersecurity News and Articles
27 April 2023
South Africans expressed financial scam concerns in a recent FICO survey showing a shift in users trust in banks depending on their scam response.
27 April 2023
The city of Lowell is alerting residents to a cyberattack that impacted the municipality's computer systems starting early on Monday. "We realized Monday morning around 3 to 5 AM that there was a breach," said City Manager Tom Golden.
27 April 2023
A study conducted among CISOs worldwide from various industries sheds light on their strategies amid a challenging threat environment, identifies obstacles from business functions, and highlights their requirements for achieving success.
27 April 2023
A little-known Russian-speaking cyber-espionage group has been linked to a new politically-motivated surveillance campaign targeting high-ranking government officials, telecom services, and public service infrastructures in Tajikistan.
The intrusion set, dubbed Paperbug by Swiss cybersecurity company PRODAFT, has been attributed to a threat actor known as Nomadic Octopus (aka DustSquad).
"The
27 April 2023
Scammers had lured a victim from Florida into parting with $480,000 after cultivating a long-term relationship, eventually coaxing him into making cryptocurrency investments.
27 April 2023
New AI technologies have raised a number of security concerns as artificially created audio and video makes it easier to commit identity fraud.
27 April 2023
The Linux flavor is specifically geared to single out ESXi hosts by terminating all virtual machines running on a compromised host prior to commencing the encryption process.
27 April 2023
Iranian state-sponsored attacker group Charming Kitten introduced a new malware, named BellaCiao, to target individuals across Europe, the Middle East, the U.S., and India. Bitdefender Labs attached every sample of the malware to a distinct victim, suggesting that the group performed highly personalized attacks.
27 April 2023
Cybersecurity researchers will show this week how they seized control of a European Space Agency (ESA) satellite in a demonstration that has been described as the world’s first ethical satellite hacking exercise.
27 April 2023
An updated version of PowerLess, a Windows backdoor, has been detected being used by Educated Manticore, a state-sponsored threat actor from Iran, to carry out phishing attacks against Israel. The bait document appears to contain academic information about Iraq from a genuine non-profit organization.
27 April 2023
Remote Access Trojans (RATs) have taken the third leading position in ANY. RUN's Q1 2023 report on the most prevalent malware types, making it highly probable that your organization may face this threat.
Though LimeRAT might not be the most well-known RAT family, its versatility is what sets it apart. Capable of carrying out a broad spectrum of malicious activities, it excels not only in data
27 April 2023
This threat actor is creating new business profiles, as well as hijacking real, reputable profiles with even millions of followers, and bombards people’s Facebook feeds with malicious click-bates promising adult-rated photo album downloads for free.
27 April 2023
The open-source e-commerce platform PrestaShop has released a new version that addresses a critical-severity vulnerability allowing any back-office user to write, update, or delete SQL databases regardless of their permissions.
27 April 2023
The threat actors behind RTM Locker have developed a ransomware strain that's capable of targeting Linux machines, marking the group's first foray into the open source operating system.
"Its locker ransomware infects Linux, NAS, and ESXi hosts and appears to be inspired by Babuk ransomware's leaked source code," Uptycs said in a new report published Wednesday. "It uses a combination of ECDH on
27 April 2023
Tracked as CVE-2023-20060, the bug was found in the web-based management interface of Cisco PCD 14 and earlier by Pierre Vivegnis of the NATO Cyber Security Centre (NCSC).
27 April 2023
A security company reported that BlueNoroff (a subgroup of Lazarus APT) has introduced a new macOS malware strain it is calling RustBucket. The malware allows attackers to download and execute various payloads. For the first-stage infection, the malware arrives packaged as an unsigned application, whereas it masquerades as a legitimate Apple bundle identifier during the second stage that is signed with an ad-hoc signature.
27 April 2023
These HiddenAds applications discovered on the Google Play Store and installed by at least 35 million users worldwide, have been found to send packets stealthily for advertising revenue in bulk.
27 April 2023
Microsoft has confirmed that the active exploitation of PaperCut servers is linked to attacks designed to deliver Cl0p and LockBit ransomware families.
The tech giant's threat intelligence team is attributing a subset of the intrusions to a financially motivated actor it tracks under the name Lace Tempest (formerly DEV-0950), which overlaps with other hacking groups like FIN11, TA505, and Evil
27 April 2023
Today, Microsoft disclosed that the Clop and LockBit ransomware gangs are behind recent attacks on PaperCut servers and using them to steal corporate data from vulnerable servers.
26 April 2023
Google patched a security hole dubbed GhostToken that affects all the users of Google Cloud Platform (GCP). This flaw enables attackers to gain access to user accounts through the installation of malicious OAuth applications obtained from either the Google Marketplace or third-party providers. Criminals can hide malicious apps by abusing this flaw.