Latest Cybersecurity News and Articles


Hackers Publish Sensitive Employee Data Stolen During CommScope Ransomware Attack

18 April 2023
The North Carolina–based company, which designs and manufactures network infrastructure products for a range of customers, including hospitals, schools, and U.S. federal agencies, was listed on the data leak site of the Vice Society ransomware gang.

YouTube Videos Distributing Aurora Stealer Malware via Highly Evasive Loader

18 April 2023
Cybersecurity researchers have detailed the inner workings of a highly evasive loader named "in2al5d p3in4er" (read: invalid printer) that's used to deliver the Aurora information stealer malware. "The in2al5d p3in4er loader is compiled with Embarcadero RAD Studio and targets endpoint workstations using advanced anti-VM (virtual machine) technique," cybersecurity firm Morphisec said in a report

PowerShell Data Theft: Vice Society Ransomware's Latest Weapon

18 April 2023
Researchers revealed that the Vice Society ransomware group is utilizing a specialized tool based on PowerShell to escape detection and automate the data extraction process. With the adoption of increasingly sophisticated tools, Vice Society has become a formidable threat to organizations globally.

DeFi Protocol Hundred Finance Loses $7M in Latest Exploit

18 April 2023
Hundred Finance confirmed the exploit on April 15, noting that it had contacted the hacker for negotiations. The platform is also working with security teams to resolve the issue and has urged anyone with information on the incident to reach out.

Cyber venture capital funding slows to a trickle, a sharp decline from 2022 investment

18 April 2023
The flow of venture capital funding to cybersecurity firms hit a steep decline in the first quarter of 2023 compared with year-ago figures, lending more credence to the notion the industry may be oversaturated with vendors and overlapping tools.

Goldoson Android Malware Infects Over 100 Million Google Play Store Downloads

18 April 2023
A new Android malware strain named Goldoson has been detected in the official Google Play Store spanning more than 60 legitimate apps that collectively have over 100 million downloads. An additional eight million installations have been tracked through ONE store, a leading third-party app storefront in South Korea. The rogue component is part of a third-party software library used by the apps in

Creative Software Maker Affinity Informs Customers of Forum Breach

18 April 2023
The company said a hacker gained access to forum user data after compromising an administrator’s account. The attacker may have accessed information such as username, reputation, join date, post count, email addresses, and the last used IP address.

New Chameleon Banking Trojan Targets Android Users in Poland and Australia

18 April 2023
The news Chameleon banking trojan is capable of changing app icon and stealing users' passwords, text messages, and other sensitive data. The malware distribution is ongoing since January and specifically targets users in Poland and Australia. Researchers believe that the trojan is still in its early stages of development and comes with limited capabilities, as of now.

Authorisation software firm Cerbos secures $7.5m

18 April 2023
Cerbos is an open-source authorization layer to implement roles and permissions in software applications. Cerbos Cloud streamlines the implementation and management of authorization policies.

DFIR via XDR: How to expedite your investigations with a DFIRent approach

18 April 2023
Rapid technological evolution requires security that is resilient, up to date and adaptable. In this article, we will cover the transformation in the field of DFIR (digital forensics and incident response) in the last couple years, focusing on the digital forensics' aspect and how XDR fits into the picture. Before we dive into the details, let's first break down the main components of DFIR and

New Chameleon Android Malware Mimics Banking, Government, and Crypto Apps

18 April 2023
The mobile malware was discovered by cybersecurity firm Cyble, which reports seeing distribution through compromised websites, Discord attachments, and Bitbucket hosting services.

Montana on cusp of becoming first state to block TikTok downloads

18 April 2023
The bill, SB 419, makes it illegal for app stores to give users the option to download the app and also illegal for the company to operate within the state. The bill does not, however, make it illegal for people who already have TikTok to use it.

An Analysis of the BabLock Ransomware

18 April 2023
Although primarily based on LockBit, the ransomware is a hodgepodge of other different ransomware parts pieced together into what Trend Micro security researchers now call BabLock.

Update: Black Basta claims it's selling off stolen Capita data

18 April 2023
Black Basta, the extortionists who claimed they were the ones who lately broke into Capita, have reportedly put up for sale sensitive details, including bank account information, addresses, and passport photos, stolen from the IT outsourcing giant.

Phishing Attacks Surge as Threat Actors Leverage New AI Tools

18 April 2023
Phishing campaigns worldwide rose nearly 50% in 2022 compared to 2021 driven partly by phishing kits and new AI tools accessible to threat actors, according to zero trust security vendor Zscaler’s ThreatLabz Phishing Report.

Iranian Hackers Using SimpleHelp Remote Support Software for Persistent Access

18 April 2023
The Iranian threat actor known as MuddyWater is continuing its time-tested tradition of relying on legitimate remote administration tools to commandeer targeted systems. While the nation-state group has previously employed ScreenConnect, RemoteUtilities, and Syncro, a new analysis from Group-IB has revealed the adversary's use of the SimpleHelp remote support software in June 2022. MuddyWater,

Israeli Spyware Vendor QuaDream to Shut Down Following Citizen Lab and Microsoft Expose

18 April 2023
Israeli spyware vendor QuaDream is allegedly shutting down its operations in the coming days, less than a week after its hacking toolset was exposed by Citizen Lab and Microsoft.

HHS updates cybersecurity best practices, shares free workforce training

18 April 2023
The Health Industry Cybersecurity Practices (HICP), one of the most critical cybersecurity resources for healthcare provider organizations, has been updated with two additional volumes and supporting mitigation resources.

LockBit Ransomware Now Targeting Apple macOS Devices

18 April 2023
Threat actors behind the LockBit ransomware operation have developed new artifacts that can encrypt files on devices running Apple's macOS operating system. The development, which was reported by the MalwareHunterTeam over the weekend, appears to be the first time a big-game ransomware crew has created a macOS-based payload. Additional samples identified by vx-underground show that the macOS

APT28 exploits known vulnerability to carry out reconnaissance and deploy malware on Cisco routers

17 April 2023
APT28 accesses poorly maintained Cisco routers and deploys malware on unpatched devices using CVE-2017-6742.