Latest Cybersecurity News and Articles


Ukrainian Hackers Breach Email of APT28 Leader, Who’s Wanted by FBI

12 April 2023
Ukrainian hacker group Cyber Resistance, aka Ukrainian Cyber Alliance, has claimed to have hacked the email, social media, and personal accounts of Russian GRU officer Lieutenant Colonel Sergey Alexandrovich Morgachev, the leader of APT28.

ChatGPT at work: What’s the cyber risk for employers?

12 April 2023
Companies across the world are taking measures to regulate how their employees use OpenAI’s ChatGPT at work. As with all new technologies, generative AI models like ChatGPT can be a source of both benefits and risks.

Education sector sees 34% increase in IoT attacks

12 April 2023
The education and research sector has experienced a surge in attacks targeting IoT devices with 131 weekly attacks per organization — more than twice the global average and a 34% increase from the year before, according to Check Point Research.

Hacked Sites Caught Spreading Malware via Fake Chrome Updates

12 April 2023
The attack starts by compromising websites to inject malicious JavaScript code that executes scripts when a user visits them. These scripts will download additional scripts based on whether the visitor is the targeted audience.

Seven in eight organizations are experiencing a shortfall of security talent

12 April 2023
A recent report by CyberEdge analyzed the recent threat landscape and how it affects security leaders in the workplace facing staff shortages.

Global Cyber Alliance releases election cybersecurity recommendations

12 April 2023
Ensuring digitized voting data remains secure from the time to someone votes until the election is over remains an international concern.

Researchers Warn of Little-Known Spyware That Hacked iPhone Victims With Rogue Calendar Invites

12 April 2023
Researchers at Microsoft and Citizen Lab analyzed samples of spyware created by QuaDream, an Israeli firm that has been reported to develop zero-click exploits for iPhones.

Eliminating 2% of Exposures Could Protect 90% of Critical Assets

12 April 2023
Only 2% of all exposures enable attackers with seamless access to critical assets, while 75% of exposures along attack paths lead to “dead ends.” The findings come from the latest report by XM Cyber, in collaboration with the Cyentia Institute.

Kodi Discloses Data Breach After Forum Database for Sale Online

12 April 2023
According to an announcement published by the platform on Saturday, hackers stole the forum database by logging into the Admin console using an inactive staff member's credentials.

The need for robust supply chain defenses to protect sensitive data

12 April 2023
Whether a multi-national enterprise or a small start-up, you can be at risk of a cyberattack committed by increasingly sophisticated cybercriminals.

Don Kleoppel named CISO at Greenway Health

12 April 2023
Greenway Health announced Don Kleoppel as its new Chief Information and Security Officer (CISO).

Israel-based Spyware Firm QuaDream Targets High-Risk iPhones with Zero-Click Exploit

12 April 2023
Threat actors using hacking tools from an Israeli surveillanceware vendor named QuaDream targeted at least five members of civil society in North America, Central Asia, Southeast Asia, Europe, and the Middle East. According to findings from a group of researchers from the Citizen Lab, the spyware campaign was directed against journalists, political opposition figures, and an NGO worker in 2021.

Western Digital restores local access to My Cloud Home customers following security breach

12 April 2023
Western Digital has restored a limited amount of data access to customers after an unauthorized actor got into its computer network and stole company information in late March.

The Service Accounts Challenge: Can't See or Secure Them Until It's Too Late

12 April 2023
Here's a hard question to answer: 'How many service accounts do you have in your environment?'. A harder one is: 'Do you know what these accounts are doing?'. And the hardest is probably: 'If any of your service account was compromised and used to access resources would you be able to detect and stop that in real-time?'.  Since most identity and security teams would provide a negative reply,

Information Warfare: The Role of Russia’s Joker DPR

12 April 2023
Researchers revealed details about Joker DPR, a pro-Russian hacker group that has become notable in Russia's invasion of Ukraine and often disseminates pro-Russian propaganda through social media. The group claims of collaboration with other pro-Russian hacktivist groups, including Beregini, Sprut, Limma, and Killnet, imply possible coordination with the Russian state. 

'Anonymous Sudan' Hackers Target Top Hospitals in Hyderabad, Slow Down Systems

12 April 2023
Earlier, the same group targeted airport websites in Hyderabad, New Delhi, Cochin, Goa, and the Airports Authority of India. The group claimed the attacks were carried out on IRCTC and income tax websites as well.

US cyber chiefs warn of threats from China and AI

12 April 2023
Bots like ChatGPT may not be able to pull off the next big Microsoft server worm or Colonial Pipeline ransomware super-infection but they may help criminal gangs and nation-state hackers develop some attacks against IT, according to NSA's Rob Joyce.

CISA Warns About Two New iPhone Flaws Exploited in the Wild

12 April 2023
The CISA sounded an alarm against two spyware-style zero-days that affect iPads, Macs, and iPhones. One of the flaws can be abused by any iOS application to run arbitrary code with kernel privileges. In another scenario, attackers can chain the two flaws to cause further damage. The CISA has ordered federal agencies to patch the security flaws by May 1. 

Microsoft April 2023 Patch Tuesday fixes one zero-day, 97 flaws

12 April 2023
While not actively exploited, Microsoft Office, Word, and Publisher remote code execution vulnerabilities were fixed today that can be exploited simply by opening malicious documents.

CAN Injection Attack - A New Tactic to Steal Smart Vehicles

12 April 2023
Attackers have found a way through the wiring of headlights to inject malicious code and steal connected smart cars. The technique allows them to send their own signals to the vehicle's central system. Experts suggest keeping the vehicle in a private enclosed area or a well-monitored car parking can prevent an attacker from gaining access to the vehicle.