Latest Cybersecurity News and Articles


Sixty-six percent of security leaders admit staffing challenges

13 April 2023
Staffing concerns, including talent gaps and limited budgets, remain an obstacle for security leaders to ensure the security of their organizations.

Limit Login Attempts Vulnerability – Patch Now!

13 April 2023
On April 11th, 2023, a software update was released to patch a severe vulnerability within the Limit Login Attempts WordPress security plugin. With over 600,000 installations, it’s among the most popular WordPress plugins in use.

WhatsApp Introduces New Device Verification Feature to Prevent Account Takeover Attacks

13 April 2023
Popular instant messaging app WhatsApp on Thursday announced a new account verification feature that ensures that malware running on a user's mobile device doesn't impact their account. "Mobile device malware is one of the biggest threats to people's privacy and security today because it can take advantage of your phone without your permission and use your WhatsApp to send unwanted messages,"

Push to ban ransomware payments following Australia’s biggest cyberattack

13 April 2023
The Australian government is being pushed to ban the payment of cyber ransoms, usually demanded in cryptocurrency, following a local business suffering a mass data breach and subsequent ransom demand.

Over One Million Financial Records Exposed in Data Incident Involving Fintech Company

13 April 2023
Upon further research, it was identified that the database belonged to NorthOne Bank, a financial technology company that claims to be used by over 320,000 American businesses. It is worth noting that NorthOne is not a full-service bank.

Dan Elston promoted to VP of Risk Management at BayPort Credit Union

13 April 2023
BayPort Credit Union adds a new position to its executive team announcing the promotion of Dan Elston to Vice President of Risk Management.

Hackers Impersonate Ukrainian Nuclear Plant Managing Firm; Hides Malware in Doc

13 April 2023
FortiGuard Labs detected a malicious document masquerading as a communication from Energoatom, a state-run entity responsible for managing Ukraine's nuclear power stations. Threat actors were found using the Havoc Demon backdoor camouflaged as a legitimate component of Microsoft Office. It was even signed with an invalid portal[.]office[.]com certificate.

Threat hunting programs can save organizations from costly security breaches

13 April 2023
Proactive threat hunting helps organizations save money by preventing security breaches and reducing the impact of attacks. For example, a study by IBM found that the average total cost of a breach is $4.35 million.

Hyundai Suffered Data Breach That Impacted Customers in France and Italy

13 April 2023
According to the letter, financial data were not exposed. The number of impacted individuals is still unclear. In response to the incident, the company has taken the impacted systems offline.

New Python-Based "Legion" Hacking Tool Emerges on Telegram

13 April 2023
An emerging Python-based credential harvester and a hacking tool named Legion are being marketed via Telegram as a way for threat actors to break into various online services for further exploitation. Legion, according to Cado Labs, includes modules to enumerate vulnerable SMTP servers, conduct remote code execution (RCE) attacks, exploit unpatched versions of Apache, and brute-force cPanel and

Money Ransomware: The Latest Double Extortion Group

13 April 2023
Researchers warned that the Money ransomware actors employ a human-operated intrusion approach, evidenced by the method of data exfiltration and the execution of the malware sample.

Pakistan-based Transparent Tribe Hackers Targeting Indian Educational Institutions

13 April 2023
The Transparent Tribe threat actor has been linked to a set of weaponized Microsoft Office documents in attacks targeting the Indian education sector using a continuously maintained piece of malware called Crimson RAT. While the suspected Pakistan-based threat group is known to target military and government entities in the country, the activities have since expanded to include the education

Why Shadow APIs are More Dangerous than You Think

13 April 2023
Shadow APIs are a growing risk for organizations of all sizes as they can mask malicious behavior and induce substantial data loss. For those that aren't familiar with the term, shadow APIs are a type of application programming interface (API) that isn't officially documented or supported.  Contrary to popular belief, it's unfortunately all too common to have APIs in production that no one on

Banning TikTok could weaken personal cybersecurity

13 April 2023
TikTok is not the first app to be scrutinized over the potential exposure of U.S. user data, but it is the first widely used app that the U.S. government has proposed banning over privacy and security concerns.

Hacking Play-to-Earn Blockchain Games: The Case Of Manarium

13 April 2023
Manarium uses the architecture comprising a Client-Side (in Unity) and a Service (Firebase data store), and for the winner prize distribution, the Admin will do the process, fetching the data, and calling the Smart Contract to execute a pay function.

Hybrid work environments are stressing CISOs

13 April 2023
The impact of the hybrid workforce on security posture, as well as the risks introduced by this way of working, are posing concerns for CISOs and driving them to develop new strategies for hybrid work security, according to Red Access.

Lazarus Hacker Group Evolves Tactics, Tools, and Targets in DeathNote Campaign

13 April 2023
The North Korean threat actor known as the Lazarus Group has been observed shifting its focus and rapidly evolving its tools and tactics as part of a long-running activity called DeathNote. While the nation-state adversary is known for its persistent attacks on the cryptocurrency sector, it has also targeted automotive, academic, and defense sectors in Eastern Europe and other parts of the world

Russian hackers ‘target security cameras inside Ukraine coffee shops’

13 April 2023
Russians hackers have logged into private security cameras in Ukraine coffee shops to collect intelligence on aid convoys passing by, a top US security official said on Tuesday.

FDA to medical device manufacturers: ‘Get your house in order’

13 April 2023
By October 1, the Food and Drug Administration will have tackled two critical medical device security issues: new submissions designed without security in mind and SBOMs to direct network defenders on where these vulnerabilities lie.

RedLine Stealer Spotted in a New Campaign Leveraging ChatGPT

13 April 2023
Cybercriminals were found using ChatGPT and Google Bard's popularity to spread the RedLine Stealer malware in at least 10 countries and steal private user information. The highest number of impacted users are in Greece, followed by those in India, the U.S. Mexico, and Bangladesh.