Latest Cybersecurity News and Articles


Biden administration announces plan to protect patient privacy

14 April 2023
As abortion access is debated within the United States, concerns have risen over the ability to protect patient privacy, including on mobile devices.

47% organizations experienced ransomware attack in the past year

14 April 2023
A recent study reveals that security teams are unprepared for ransomware and struggle with increasing regulatory complexity.

Bitrue Hot Wallet Exploit Results in $23M Cryptocurrency Theft

14 April 2023
The exchange said it will suspend all withdrawals temporarily to conduct additional security checks, and withdrawals are expected to resume on April 18, 2023. The exchange explained that they will compensate all identified users affected in full.

Non-internet facing systems have significant risk density

14 April 2023
Security leaders work hard to securing potential data vulnerabilities within their organizations using security assessments and penetration tests.

Former TSB chief information officer fined $101,000 over IT meltdown in 2018

14 April 2023
UK regulators have imposed an £81,000 (~$101,000) fine on a former TSB information officer over the bank’s IT meltdown in 2018 that left millions of customers locked out of their accounts.

GuLoader Targets US Financial Firms With Tax-Themed Phishing Lures

14 April 2023
“GuLoader, also known as CloudEyE, is a loader malware that is known to deliver additional malware, such as infostealers and Remote Access Trojans (RATs),” wrote eSentire’s Threat Response Unit (TRU).

Russia-Linked Hackers Launches Espionage Attacks on Foreign Diplomatic Entities

14 April 2023
The Russia-linked APT29 (aka Cozy Bear) threat actor has been attributed to an ongoing cyber espionage campaign targeting foreign ministries and diplomatic entities located in NATO member states, the European Union, and Africa. According to Poland's Military Counterintelligence Service and the CERT Polska team, the observed activity shares tactical overlaps with a cluster tracked by Microsoft as

Five arrested after 33,000 victims lose $98M to online investment fraud

14 April 2023
Europol and Eurojust announced today the arrest of five individuals believed to be part of a massive online investment fraud ring with at least 33,000 victims who lost an estimated €89 million (roughly $98 million).

Russian APT Hackers Actively Targeting European NATO Allies

14 April 2023
The Russian cyberespionage campaign is targeting European government agencies and diplomats to steal Western government intelligence on the war in Ukraine, says the Polish CERT and Military Counterintelligence Service.

Beware of Juice Jacking and Impersonation Attacks - Warns FCC and FBI

14 April 2023
The FCC warns against using free charging stations at airports, hotels, and shopping centers. It is also advisable to use an electrical outlet instead of USB charging ports to stay safe. Meanwhile, the FBI raises the alarm about adversaries impersonating Chinese officials to target Chinese users in the U.S. 

'RTM Locker' Cybercrime Group Now Targets Businesses via Ransomware Affiliates

14 April 2023
"The business-like set up of the group, where affiliates are required to remain active or notify the gang of their leave, shows the organizational maturity of the group, as has also been observed in other groups, such as Conti," Trellix reported.

Countering the Problem of Credential Theft

14 April 2023
While law enforcement action against Genesis resulted in the seizure of at least 10 clearnet domains, its Tor site is still running, and its administrators have indicated they will set up new infrastructure.

Linux kernel logic allowed Spectre attack on major cloud

14 April 2023
On Thursday, Eduardo (sirdarckcat) Vela Nava, from Google's product security response team, disclosed a Spectre-related security vulnerability in version 6.2 of the Linux kernel.

Kodi Confirms Data Breach: 400K User Records and Private Messages Stolen

14 April 2023
Open source media player software provider Kodi has confirmed a data breach after threat actors stole the company's MyBB forum database containing user data and private messages. What's more, the unknown threat actors attempted to sell the data dump comprising 400,635 Kodi users on the now-defunct BreachForums cybercrime marketplace. "MyBB admin logs show the account of a trusted but currently

Canada: Cyberattack at Ontario Town of St. Marys cost $1.3M, including $290K in Bitcoin ransom

14 April 2023
The report comes around nine months after the town suffered the ransomware attack, which resulted in the town locking down its IT systems and restricting access to email.

Windows Admins Warned About a Critical MSMQ QueueJumper Vulnerability

14 April 2023
All currently supported releases up to the most recent versions, Windows 11 22H2 and Windows Server 2022, are included in the list of affected Windows server and client releases.

Microsoft warns of phishing attack targeting accountants as Tax Day approaches

14 April 2023
With the USA reaching the end of its annual tax season, accountants are scrambling to gather clients' tax documents to complete and file their tax returns, making it an ideal time for threat actors to target tax preparers.

A flaw in the Kyocera Android printing app can be abused to drop malware

14 April 2023
An improper intent handling issue affecting the Kyocera Android printing app can allow malicious applications to drop malware, as reported by the Japanese Vulnerability Notes (JVN).

Severe Android and Novi Survey Vulnerabilities Under Active Exploitation

14 April 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The two flaws are listed below - CVE-2023-20963 (CVSS score: 7.8) - Android Framework Privilege Escalation Vulnerability CVE-2023-29492 (CVSS score: TBD) - Novi Survey Insecure Deserialization Vulnerability

Webinar: Tips from MSSPs to MSSPs – Building a Profitable vCISO Practice

14 April 2023
In today's fast-paced and ever-changing digital landscape, businesses of all sizes face a myriad of cybersecurity threats. Putting in place the right people, technological tools and services, MSSPs are in a great position to ensure their customers' cyber resilience.  The growing need of SMEs and SMBs for structured cybersecurity services can be leveraged by MSPs and MSSPs to provide strategic