Latest Cybersecurity News and Articles
26 April 2023
A new report reveals an increase in cyberattacks directed at financial institutions, food retailers and healthcare providers, with 60% of all attacks targeting these three key industries.
26 April 2023
In a recent analysis, Trend Micro came across an unfamiliar program running in the background on their honeypot. It was meant to generate money by driving traffic to specific websites and engaging with ads.
26 April 2023
Organizations in the cloud are exposed to web-borne attacks. 87% of all-SaaS adopters and 79% of CISOs in a hybrid environment experienced a web-borne security threat in the past 12 months, according to a global survey by LayerX.
26 April 2023
The advanced persistent threat (APT) group referred to as Evasive Panda has been observed targeting an international non-governmental organization (NGO) in Mainland China with malware delivered via update channels of legitimate applications like Tencent QQ.
The attack chains are designed to distribute a Windows installer for MgBot malware, ESET security researcher Facundo Muñoz said in a new
26 April 2023
Chinese APT group Gallium is deploying new Linux malware variants in cyberespionage attacks, such as a new PingPull variant and a previously undocumented backdoor tracked as 'Sword2033.'
26 April 2023
The browser serves as the primary interface between the on-premises environment, the cloud, and the web in the modern enterprise. Therefore, the browser is also exposed to multiple types of cyber threats and operational risks.
In light of this significant challenge, how are CISOs responding?
LayerX, Browser Security platform provider, has polled more than 150 CISOs across multiple verticals and
26 April 2023
NetRise announced $8 million in funding, led by Squadra Ventures, with participation by existing major investors Miramar Digital Ventures, Sorenson Ventures, and DNX Ventures.
26 April 2023
The attack began when an officer clicked on a malicious link, according to ABC7. Officials did not say whether data had been stolen during the attack. No ransomware group has come forward to claim the attack.
26 April 2023
The company raised an additional $12M from its financial partner, Arthur Ventures, to continue to bring Privileged Access Management to MSPs. According to CEO Mateo Barraza, the rebranding was necessary to accurately portray the company's mission.
26 April 2023
The incident was revealed in a trove of leaked U.S. intelligence materials that included an apparently intercepted conversation between a hacking group known as Zarya and an officer at Russia’s Federal Security Service (FSB).
26 April 2023
The maintainers of the Apache Superset open source data visualization software have released fixes to plug an insecure default configuration that could lead to remote code execution.
The vulnerability, tracked as CVE-2023-27524 (CVSS score: 8.9), impacts versions up to and including 2.0.1 and relates to the use of a default SECRET_KEY that could be abused by attackers to authenticate and access
26 April 2023
The new money comes in the form of a $20M secured note and a $10M convertible note and provides working capital and a runway for Token to compete in a crowded market for enterprise authentication products.
26 April 2023
In this instance, a fake shipping notification in Italian was observed, humorously reflecting GuLoader's Italian origins. Unlike previous cases, GuLoader was not concealed within a Zip file but rather an ISO file.
26 April 2023
A judicial magistrate first class court in Pune on April 15 passed an order convicting eleven accused of stealing in August 2018 up to $1.76 million from Cosmos Cooperative Bank.
26 April 2023
VMware has released updates to resolve multiple security flaws impacting its Workstation and Fusion software, the most critical of which could allow a local attacker to achieve code execution.
26 April 2023
VMware has released updates to resolve multiple security flaws impacting its Workstation and Fusion software, the most critical of which could allow a local attacker to achieve code execution.
The vulnerability, tracked as CVE-2023-20869 (CVSS score: 9.3), is described as a stack-based buffer-overflow vulnerability that resides in the functionality for sharing host Bluetooth devices with the
25 April 2023
While cybercriminals are exploiting the pair of bugs in PaperCut MF/NG print management software, researchers at cybersecurity firm Horizon3 revealed information about one of the bugs, identified as CVE-2023-27350, and also shared a PoC exploit code. The bug can be effectively exploited by criminals to dodge detection and run arbitrary code on susceptible PaperCut servers. Trend Micro is poised to release further details on the bugs on May 10th.
25 April 2023
A recent discovery by cybersecurity experts has revealed a new BumbleBee loader infection campaign that utilizes Google advertisements to promote trojanized versions of widely-used applications. It attempted to spread via fake installers of well-known software such as Zoom, Cisco AnyConnect, ChatGPT, and Citrix Workspace.
25 April 2023
Security analysts uncovered a new attack campaign, tracked as OCX#HARVESTER, wherein malicious payloads used as part of the campaign were found related to the More_eggs backdoor. Based on the targeted victims and the modus operandi of the More_eggs malware, researchers associated the campaign with FIN6 APT.
25 April 2023
Cloud security firm Aqua uncovered a massive crypto-mining campaign that creates backdoors and runs miners using Kubernetes (K8s) Role-Based Access Control (RBAC). In this attack, threat actors also check for the presence of other miner malware on the server and then establish persistence using the RBAC. Additionally, they deploy DaemonSets to access resources of the K8s clusters.