Latest Cybersecurity News and Articles


Pre-pandemic techniques are fueling record fraud rates

20 April 2023
Within the largest financial institutions, insurers, and retailers, the rise and adoption of AI, an impending recession, and the return of pre-pandemic fraud techniques are driving record rates of fraud attacks, according to Pindrop.

Two Critical Flaws Found in Alibaba Cloud's PostgreSQL Databases

20 April 2023
A chain of two critical flaws has been disclosed in Alibaba Cloud's ApsaraDB RDS for PostgreSQL and AnalyticDB for PostgreSQL that could be exploited to breach tenant isolation protections and access sensitive data belonging to other customers. "The vulnerabilities potentially allowed unauthorized access to Alibaba Cloud customers' PostgreSQL databases and the ability to perform a supply chain

Prior Supply Chain Compromise at Stock Trading Automation Company Fueled 3CX Attack

20 April 2023
An investigation into last month's 3CX supply chain attack revealed that it was caused by another supply chain compromise where suspected North Korean attackers breached the site of Trading Technologies to push trojanized software builds.

Microsoft Defender update causes Windows Hardware Stack Protection mess

20 April 2023
In a confusing mess, a recent Microsoft Defender update rolled out a new security feature called 'Kernel-mode Hardware-enforced Stack Protection,' while removing the LSA protection feature.

Daggerfly Cyberattack Campaign Hits African Telecom Services Providers

20 April 2023
The campaign makes use of "previously unseen plugins from the MgBot malware framework," Symantec said. "The attackers were also seen using a PlugX loader and abusing the legitimate AnyDesk remote desktop software."

Detecting the Use of Stolen AWS Lambda Credentials

20 April 2023
The use of stolen credentials can then be detected when a logging event deviates from the baseline. A similar approach could be applied to detect AWS credentials stolen from other services.

Microsoft SQL Servers Hacked to Deploy Trigona Ransomware

20 April 2023
Before encrypting the system and deploying ransom notes, the malware disables system recovery and deletes any Windows Volume Shadow copies, making recovery impossible without the decryption key.

Lazarus Group Adds Linux Malware to Arsenal in Operation Dream Job

20 April 2023
The notorious North Korea-aligned state-sponsored actor known as the Lazarus Group has been attributed to a new campaign aimed at Linux users. The attacks are part of a persistent and long-running activity tracked under the name Operation Dream Job, ESET said in a new report published today. The findings are crucial, not least because it marks the first publicly documented example of the

Beyond Traditional Security: NDR's Pivotal Role in Safeguarding OT Networks

20 April 2023
Why is Visibility into OT Environments Crucial? The significance of Operational Technology (OT) for businesses is undeniable as the OT sector flourishes alongside the already thriving IT sector. OT includes industrial control systems, manufacturing equipment, and devices that oversee and manage industrial environments and critical infrastructures. In recent years, adversaries have recognized the

GitHub debuts pedigree check for npm packages via Actions

20 April 2023
Developers using GitHub Actions to build software packages for NPM can now add a command flag that will publish details about the code's origin. This feature is intended to further enhance the security of the open-source software supply chain.

Point32Health Confirms Service Disruption Due to Ransomware Attack

20 April 2023
A ransomware attack interrupted access to services provided by one of New England's largest healthcare insurers, though the scope of affected customers and data remains unknown.

Fortra Sheds Light on GoAnywhere MFT Zero-Day Exploit Used in Ransomware Attacks

20 April 2023
Fortra, the company behind Cobalt Strike, shed light on a zero-day remote code execution (RCE) vulnerability in its GoAnywhere MFT tool that has come under active exploitation by ransomware actors to steal sensitive data. The high-severity flaw, tracked as CVE-2023-0669 (CVSS score: 7.2), concerns a case of pre-authenticated command injection that could be abused to achieve code execution. The

ChatGPT's Data Protection Blind Spots and How Security Teams Can Solve Them

20 April 2023
In the short time since their inception, ChatGPT and other generative AI platforms have rightfully gained the reputation of ultimate productivity boosters. However, the very same technology that enables rapid production of high-quality text on demand, can at the same time expose sensitive corporate data. A recent incident, in which Samsung software engineers pasted proprietary code into ChatGPT,

Hackers actively exploit critical RCE bug in PaperCut servers

20 April 2023
Print management software developer PaperCut is warning customers to update their software immediately, as hackers are actively exploiting flaws to gain access to vulnerable servers.

npm Packages Abused; GitHub Enhances Security and Verification of Packages

20 April 2023
GitHub has released features for secure vulnerability reporting and npm package provenance. In other news, the Node.js open source package repository, npm, was overwhelmed with fake packages by malicious actors, which caused a temporary denial-of-service (DoS) attack.

Medusa ransomware crew boasts of Microsoft code leak

20 April 2023
"This leak is of more interest to programmers, since it contains the source codes of the following Bing products, Bing Maps and Cortana," the crew wrote on its website, which was screenshotted and shared by Emsisoft threat analyst Brett Callow.

Daggerfly Cyberattack Campaign Hits African Telecom Services Providers

20 April 2023
Telecommunication services providers in Africa are the target of a new campaign orchestrated by a China-linked threat actor at least since November 2022. The intrusions have been pinned on a hacking crew tracked by Symantec as Daggerfly, and which is also tracked by the broader cybersecurity community as Bronze Highland and Evasive Panda. The campaign makes use of "previously unseen plugins from

NSO Group Used 3 Zero-Click iPhone Exploits Against Human Rights Defenders

20 April 2023
Israeli spyware maker NSO Group deployed at least three novel "zero-click" exploits against iPhones in 2022 to infiltrate defenses erected by Apple and deploy Pegasus, according to the latest findings from Citizen Lab. "NSO Group customers widely deployed at least three iOS 15 and iOS 16 zero-click exploit chains against civil society targets around the world," the interdisciplinary laboratory

Threat Actors Rapidly Adopt Web3 IPFS Technology

20 April 2023
Since the content hosted on IPFS is decentralized and distributed, there are challenges in locating and removing malicious content from the ecosystem, making it akin to bullet-proof hosting.

Massive Abuse of an Abandoned Eval PHP WordPress Plugin

20 April 2023
Researchers started observing attackers making use of an unorthodox type of backdoor and reinfection method which would go completely undetected if website monitoring doesn’t happen to include the database.