Latest Cybersecurity News and Articles


US extradites Nigerian charged over $6m email fraud scam

17 April 2023
They used a technique dubbed Business Email Compromise (BEC). As part of this, it's claimed, the fraudsters broke into people's email accounts, too, and chatted via mobile apps to organize their crimes.

Hackers Start Abusing Action1 RMM in Ransomware Attacks

17 April 2023
Action1 is a remote monitoring and management (RMM) product that is commonly used by managed service providers (MSPs) and the enterprise to remotely manage endpoints on a network.

Australians report record $3.1bn losses to scams, with real amount even higher, ACCC says

17 April 2023
This was found in the Targeting Scams report from the Australian Competition and Consumer Commission, which compiles data from Scamwatch, ReportCyber, major banks, and money remitters, based on an analysis of more than 500,000 reports.

Volvo's Brazil Retailer Exposed Sensitive Database Credentials, Laravel App Key, Git Repository Link

17 April 2023
On February 17, 2023, the Cybernews research team discovered public access to sensitive files hosted on dimasvolvo.com.br website, belonging to an independent Volvo retailer in the Santa Catarina region of Brazil.

What it will look like if China launches cyberattacks in the U.S.

17 April 2023
While much of the cybersecurity world’s attention is on fending off Russian hacks against Ukraine, American officials are increasingly worried about another growing threat: attacks by China on U.S. soil.

Google Uncovers APT41's Use of Open Source GC2 Tool to Target Media and Job Sites

17 April 2023
A Chinese nation-state group targeted an unnamed Taiwanese media organization to deliver an open source red teaming tool known as Google Command and Control (GC2) amid broader abuse of Google's infrastructure for malicious ends. The tech giant's Threat Analysis Group (TAG) attributed the campaign to a threat actor it tracks under the geological and geographical-themed moniker HOODOO, which is

Tour of the Underground: Master the Art of Dark Web Intelligence Gathering

17 April 2023
The Deep, Dark Web – The Underground – is a haven for cybercriminals, teeming with tools and resources to launch attacks for financial gain, political motives, and other causes. But did you know that the underground also offers a goldmine of threat intelligence and information that can be harnessed to bolster your cyber defense strategies? The challenge lies in continuously monitoring the right

New Zaraza Bot Credential-Stealer Sold on Telegram Targeting 38 Web Browsers

17 April 2023
"Zaraza bot targets a large number of web browsers and is being actively distributed on a Russian Telegram hacker channel popular with threat actors," cybersecurity company Uptycs said in a report published last week.

CYFIRMA raises an undisclosed amount in Pre-Series B funding for product innovation

17 April 2023
The funds raised will be used for product innovation and entering new global markets in North America, Europe, and MENA region in addition to growing the existing markets in SEA, including India, Singapore, and Japan.

Experts found the first LockBit encryptor that targets macOS systems

17 April 2023
The LockBit group is the first ransomware gang that has created encryptors to target macOS systems, MalwareHunterTeam warns. The researchers discovered the LockBit encryptors in a ZIP archive uploaded to VirusTotal.

Federal, International Agencies Release Principles to Enhance Security of Tech Products

17 April 2023
The authoring agencies urged technology and software manufacturers “to revamp their design and development programs to permit only secure-by-design and -default products to be shipped to customers.”

Beware of Movie365 and Similar Sites Offering Free Movies Online

17 April 2023
If you’ve ever searched for free online movie streaming sites, you’ve probably come across Movie365 and other similar sites. While these sites promise access to the latest movies, they’re often not what they seem.

Google Launches New Cybersecurity Initiatives to Strengthen Vulnerability Management

17 April 2023
The company further emphasized that it's committing to publicly disclose incidents when it finds evidence of active exploitation of vulnerabilities across its product portfolio.

Russia accuses NATO of launching 5,000 cyberattacks since 2022

17 April 2023
The FSB claims that despite many of the attacks being presented as activities by the "IT Army of Ukraine," it was able to discern the involvement of pro-west hacker groups like "Anonymous," "Sailens," "Goast clan," "Ji-En-Ji," "SquadZOZ," and others.

Vice Society Ransomware Using Stealthy PowerShell Tool for Data Exfiltration

17 April 2023
Threat actors associated with the Vice Society ransomware gang have been observed using a bespoke PowerShell-based tool to fly under the radar and automate the process of exfiltrating data from compromised networks.

Microsoft shares guidance to detect BlackLotus UEFI bootkit attacks

17 April 2023
Analyzing devices compromised with BlackLotus, the Microsoft Incident Response team identified several points in the malware installation and execution process that allow its detection.

Vice Society Ransomware Using Stealthy PowerShell Tool for Data Exfiltration

17 April 2023
Threat actors associated with the Vice Society ransomware gang have been observed using a bespoke PowerShell-based tool to fly under the radar and automate the process of exfiltrating data from compromised networks. "Threat actors (TAs) using built-in data exfiltration methods like [living off the land binaries and scripts] negate the need to bring in external tools that might be flagged by

New Zaraza Bot Credential-Stealer Sold on Telegram Targeting 38 Web Browsers

17 April 2023
A novel credential-stealing malware called Zaraza bot is being offered for sale on Telegram while also using the popular messaging service as a command-and-control (C2). "Zaraza bot targets a large number of web browsers and is being actively distributed on a Russian Telegram hacker channel popular with threat actors," cybersecurity company Uptycs said in a report published last week. "Once the

Australians report record $3.1bn losses to scams, with real amount even higher, ACCC says

16 April 2023
Australians report record $3.1bn losses to scams, with real amount even higher, ACCC says Investment fraud amounts for biggest share at $1.5bn, followed by remote access and payment redirection rortsFollow our Australia news live blog for the latest updatesGet our morning and afternoon news emails, free app or daily news podcastAustralians lost a record amount of more than $3.1bn to scams in 2022, up from the $2bn lost in 2021, a new report from the Australian Competition and Consumer Commission has revealed.The Targeting Scams report, which compiles data from Scamwatch, ReportCyber, major banks and money remitters, was based on an analysis of more than 500,000 reports.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...

Labour glitch put voting intentions data of millions at risk

16 April 2023
Labour glitch put voting intentions data of millions at risk Exclusive: Experts say sensitive information could potentially have been harvested and used for targeted election interferenceThe voting intentions of millions of Britons in local authority wards across the country could have been at risk of misuse as a result of a glitch in the Labour party’s main phone-banking system, the Guardian understands.Experts had warned that the sensitive data could potentially have been harvested via an automated programme and used for targeted election interference by campaign groups or even hostile states. Continue reading...