Latest Cybersecurity News and Articles
24 April 2023
Threat actors have been observed leveraging a legitimate but outdated WordPress plugin to surreptitiously backdoor websites as part of an ongoing campaign, Sucuri revealed in a report published last week.
The plugin in question is Eval PHP, released by a developer named flashpixx. It allows users to insert PHP code pages and posts of WordPress sites that's then executed every time the posts are
24 April 2023
Trigona ransomware operators are targeting unsecured and internet-exposed Microsoft SQL (MS-SQL) servers, discovered AhnLab. They breach servers via brute-force attacks to crack account credentials. Before encryption, the attackers claim to steal sensitive documents that will be added to dark web leak sites if the ransom is not paid.
24 April 2023
Black Basta ransomware and extortion gang claims responsibility for the attack and has posted sensitive documents and data over the weekend, including ID documents, tax documents, sales and purchase agreements, and more.
24 April 2023
Just as criminals in the physical world are known to insert themselves into criminal investigations, cybercriminals read publicly available Open Source Intelligence (OSINT) and analyst reports.
24 April 2023
CYFIRMA detected a cyberattack in Kashmir, India, linked to the DoNot APT group that used third-party file-sharing websites to spread malware disguised as chat apps named Ten Messenger and Link Chat QQ. The malware's source code was well obfuscated and protected with the Pro Guard code obfuscator utility. It is suggested to implement multiple layers of security to minimize the impact of this threat.
24 April 2023
Money mules, individuals whose bank accounts are used by fraudsters to transfer money, are becoming an increasingly prominent aspect of cybercriminals’ economic business models too.
24 April 2023
Halcyon announced that it raised $44 million in a Series A funding round (plus $6 million in debt) led by SYN Ventures and Corner Ventures, with participation from Dell Technologies Capital.
24 April 2023
Morphisec found a campaign using a highly evasive loader, named in2al5d p3in4er, disseminating the Aurora info-stealer via links in YouTube video descriptions. It is compiled using Embarcadero RAD Studio which allows attackers to create executables for multiple platforms, with multiple configuration options.
24 April 2023
The “unauthorized access” that prompted the Guam Memorial Hospital to shut down its network in March is now being investigated by the U.S. Department of Health and Human Services, according to an acceptance letter addressed to a whistleblower.
24 April 2023
Organizations today are very aware that shadow IT exists in their “backyard”, and that the more unknown apps and uncontrolled access they have, the bigger their attack surface is.
24 April 2023
A new backdoor, named DevOpt, was discovered that uses hard-coded names for persistence and provides various features such as keylogging, stealing browser credentials, and clipper. Multifunctional malware such as DevOpt are increasingly becoming common. Organizations must make continuous improvements in their defense approaches, and implement multi-layered defense architecture.
24 April 2023
Secureworks analyzed the findings in a report published on Thursday, saying the infection chain for several of these attacks relied on a malicious Google Ad that sent users to a fake download page via a compromised WordPress site.
24 April 2023
The system is structured around databases that save and track all events and changes occurring within the OS. That should mean recovering from ransomware simply means rolling back a machine to the previously safe state within minutes.
24 April 2023
Uptycs found a new credential stealer, named Zaraza bot, being advertised on Telegram and simultaneously using the messaging service as C2 server. It can target 38 web browsers. Zaraza bot is a lightweight malware with just a 64-bit binary file. Some codes and logs are written in Russian. As a precaution, users should be wary of the links received over social media and downloading anything from unknown sources.
24 April 2023
Print management software provider PaperCut said that it has "evidence to suggest that unpatched servers are being exploited in the wild," citing two vulnerability reports from cybersecurity company Trend Micro.
24 April 2023
The round, which brought the total amount to $93M, was led by Lightspeed Venture Partners with participation from previous investors Felicis Ventures, Redpoint Ventures, and Sequoia Capital.
24 April 2023
Chinese nation-state group APT41 targeted an unnamed Taiwanese media firm to deploy Google Command and Control (GC2), an open-source red teaming tool - revealed Google’s TAG. To initiate the attack, the attackers sent phishing emails with links to password-protected files hosted on Google Drive.
24 April 2023
During the public beta, the option to report private vulnerabilities could be activated by maintainers and repository owners only on single repositories. Starting this week, they can now enable this for all repositories within their organization.
24 April 2023
Medtronic MiniMed has joined the long list of healthcare entities to report unintentional disclosures to third parties without authorization due to the use of tracking or pixel technology.
24 April 2023
A new "all-in-one" stealer malware named EvilExtractor (also spelled Evil Extractor) is being marketed for sale for other threat actors to steal data and files from Windows systems.
"It includes several modules that all work via an FTP service," Fortinet FortiGuard Labs researcher Cara Lin said. "It also contains environment checking and Anti-VM functions. Its primary purpose seems to be to