Latest Cybersecurity News and Articles


Goldoson Library Infects Popular Apps with Adware

19 April 2023
A recently detected Android malware named 'Goldoson' has made its way into Google Play and has been found in 60 legitimate applications, which have been downloaded a total of 100 million times. Users are suggested to always perform due diligence, especially for new apps without good reviews.

Google Patches Second Chrome Zero-Day Vulnerability of 2023

19 April 2023
Tracked as CVE-2023-2136, the security defect is described as a high-severity integer overflow issue in Skia. The bug was reported by Google Threat Analysis Group researcher Clement Lecigne and, as per Google's policy, no monetary reward was issued.

Akamai to Buy Startup Neosec for API Detection and Response

19 April 2023
The Boston-area vendor said its proposed acquisition of Silicon Valley-based Neosec will make it easier for customers to secure their APIs, by helping them discover all their APIs, assess their risk and respond to vulnerabilities and attacks.

Google Chrome Hit by Second Zero-Day Attack - Urgent Patch Update Released

19 April 2023
Google on Tuesday rolled out emergency fixes to address another actively exploited high-severity zero-day flaw in its Chrome web browser. The flaw, tracked as CVE-2023-2136, is described as a case of integer overflow in Skia, an open source 2D graphics library. Clément Lecigne of Google's Threat Analysis Group (TAG) has been credited with discovering and reporting the flaw on April 12, 2023. "

Pakistani Hackers Use Linux Malware Poseidon to Target Indian Government Agencies

19 April 2023
The Pakistan-based advanced persistent threat (APT) actor known as Transparent Tribe used a two-factor authentication (2FA) tool used by Indian government agencies as a ruse to deliver a new Linux backdoor called Poseidon.

Coro Raises $75 Million for Mid-Market Cybersecurity Platform

19 April 2023
With the new funding round, the Israel-based company adds Energy Impact Partners to its list of investors, which also includes Balderton Capital, JVP, and Sound Ventures.

PLAY Ransomware Strengthens Capabilities With New Tools, Researchers Say

19 April 2023
Custom tools also allow for more control over operations, and a decreased likelihood that a group’s particular tooling will be either reverse-engineered or adapted by other groups, the researchers noted.

Luz Mabel del Valle hired as Chief Risk Officer at FV Bank

19 April 2023
Luz Mabel del Valle has been appointed to Chief Risk Officer (CRO) at FV Bank. De Valle has also been appointed Deputy Chief Compliance Officer.

Triple-digit Increase in API and App Attacks on Tech and Retail

19 April 2023
Last year was a record-breaker in terms of API and application-based attacks on the EMEA retail sector, with detected threats surging 189%, according to a report by Akamai.

DoNot APT Hackers Attack Individuals Using Android Malware via Chatting Apps

19 April 2023
Interestingly, the malware samples were disguised as chat apps named Ten Messenger.apk and Link Chat QQ.apk This threat actor has carried out cyberattacks in the South Asian region since 2016 when it was first found to be active.

Report: Supplier cyber weaknesses impact big business

19 April 2023
A recent report, State of Cyber Security in the Supply Chain 2023, spotlights the key security weaknesses in the supply chain ecosystem.

Allurity acquires CloudComputing and Securix to expand into new markets

19 April 2023
The former brings a complete and robust offering in identity, zero trust, and information security. The latter adds substantial reinforcement in the areas of identity security, observability, and consultancy.

US, UK Agencies Warn of Nation-State Hackers Using Custom Malware on Cisco Routers

19 April 2023
Jaguar Tooth is a malware injected directly into the memory of Cisco routers running older firmware versions. Once installed, the malware exfiltrates information from the router and provides unauthenticated backdoor access to the device.

Pakistani Hackers Use Linux Malware Poseidon to Target Indian Government Agencies

19 April 2023
The Pakistan-based advanced persistent threat (APT) actor known as Transparent Tribe used a two-factor authentication (2FA) tool used by Indian government agencies as a ruse to deliver a new Linux backdoor called Poseidon. "Poseidon is a second-stage payload malware associated with Transparent Tribe," Uptycs security researcher Tejaswini Sandapolla said in a technical report published this week.

SpecterOps Scores $25M Funding to Secure ID Attack Paths

19 April 2023
The company said the Series A investment was led by Silicon Valley venture outfit Decibel. SpecterOps said the new $25 million cash infusion will be used to expand its services and training products.

Experts temporarily disrupted the RedLine Stealer operations

19 April 2023
ESET researchers announced to have temporarily disrupted the operations of the RedLine Stealer with the help of GitHub. The two companies teamed up with Flare to curb the operations of the malware operators.

Uncovering (and Understanding) the Hidden Risks of SaaS Apps

19 April 2023
Recent data breaches across CircleCI, LastPass, and Okta underscore a common theme: The enterprise SaaS stacks connected to these industry-leading apps can be at serious risk for compromise. CircleCI, for example, plays an integral, SaaS-to-SaaS role for SaaS app development. Similarly, tens of thousands of organizations rely on Okta and LastPass security roles for SaaS identity and access

Safe Security Raises $50M to Bring ML to Risk Quantification

19 April 2023
The Silicon Valley-based company said the Series B funding will allow Safe Security to capitalize on generative artificial intelligence to help nontechnical leaders better understand their organizations security postures.

Microsoft: Iranian hackers behind retaliatory cyberattacks on US orgs

19 April 2023
Microsoft believes the Iranian government is now allowing state-sponsored threat actors more freedom when conducting attacks, leading to an overall increase in cyberattacks.

U.S. and U.K. Warn of Russian Hackers Exploiting Cisco Router Flaws for Espionage

19 April 2023
U.K. and U.S. cybersecurity and intelligence agencies have warned of Russian nation-state actors exploiting now-patched flaws in networking equipment from Cisco to conduct reconnaissance and deploy malware against targets. The intrusions, per the authorities, took place in 2021 and targeted a small number of entities in Europe, U.S. government institutions, and about 250 Ukrainian victims. The