Latest Cybersecurity News and Articles


Credit union fraud rates increased by more than 70% in 2022

11 April 2023
A recent report focused on the rise and adoption of artificial intelligence, an impending recession and the return of pre-pandemic fraud techniques.

Fivecast Completes Series A Raise With New US and Existing Australian VC Investors

11 April 2023
The Australian open-source intelligence (OSINT) software company has closed its Series A funding round with almost US$20 million raised to fuel its expansion and service contracts in key markets.

CISA Issues Advisories on Critical ICS and SCADA Vulnerabilities

11 April 2023
Multiple advisories have been released by the CISA covering bugs found in ICS and SCADA software from several vendors including Rockwell Automation, Hitachi Energy, JTEKT Electronics, Korenix, mySCADA Technologies, and Industrial Control Links. ScadaFlex II series controllers by Industrial Control Links suffered a critical bug with a CVSS score of 9.1, enabling attackers to modify, delete, or create files on the system.

Why reporting an incident only makes the cybersecurity community stronger

11 April 2023
CISOs and cyber leaders may not see reporting a breach as the most pleasant of tasks, but experts say mandatory and voluntary sharing of intelligence around incidents can only improve the readiness and resilience of responders.

US Government Scrambles to Investigate Military Intel Leak on Russia-Ukraine Conflict

11 April 2023
A series of video game servers have emerged as key distribution points for a cache of perhaps as many as 100 intelligence documents containing secret and top-secret information about the war in Ukraine.

Newly Discovered "By-Design" Flaw in Microsoft Azure Could Expose Storage Accounts to Hackers

11 April 2023
A "by-design flaw" uncovered in Microsoft Azure could be exploited by attackers to gain access to storage accounts, move laterally in the environment, and even execute remote code. "It is possible to abuse and leverage Microsoft Storage Accounts by manipulating Azure Functions to steal access-tokens of higher privilege identities, move laterally, potentially access critical business assets, and

Mike Johnson hired as Rivian Chief Information Security Officer

11 April 2023
Mike Johnson has been hired has Rivian Automotive's Chief Information Security Officer. Johnson’s cybersecurity career spans more than 25 years.

Potential Outcomes of the US National Cybersecurity Strategy

11 April 2023
On March 1, 2023, the Biden administration published its National Cybersecurity Strategy. This is not an executive order, but an outline of how the administration will guide the evolution of cybersecurity at the national level.

New Mexico Governor signs cybersecurity legislation

11 April 2023
The Cybersecurity Act was signed into law in New Mexico establishing an office to oversee cybersecurity and information security functions.

Cybercriminals Turn to Android Loaders on Dark Web to Evade Google Play Security

11 April 2023
Malicious loader programs capable of trojanizing Android applications are being traded on the criminal underground for up to $20,000 as a way to evade Google Play Store defenses. "The most popular application categories to hide malware and unwanted software include cryptocurrency trackers, financial apps, QR-code scanners, and even dating apps," Kaspersky said in a new report based on messages

Cryptocurrency Stealer Malware Distributed via 13 NuGet Packages

11 April 2023
Cybersecurity researchers have detailed the inner workings of the cryptocurrency stealer malware that was distributed via 13 malicious NuGet packages as part of a supply chain attack targeting .NET developers.

[eBook] A Step-by-Step Guide to Cyber Risk Assessment

11 April 2023
In today's perilous cyber risk landscape, CISOs and CIOs must defend their organizations against relentless cyber threats, including ransomware, phishing, attacks on infrastructure, supply chain breaches, malicious insiders, and much more. Yet at the same time, security leaders are also under tremendous pressure to reduce costs and invest wisely.  One of the most effective ways for CISOs and

South Korean Exchange GDAC Loses 23% of Its Assets After Hacking Incident

11 April 2023
According to GDAC, some of the stolen assets have been sent to foreign cryptocurrency exchanges. As a result, the exchange has also reached out to the exchanges in question and foreign authorities to prevent the funds from being laundered.

Update: Australian Finance Company Refuses Hackers’ Ransom Demand

11 April 2023
“We will not reward criminal behavior, nor do we believe that paying a ransom will result in the return or destruction of the information that was stolen,” it said in a statement to the Australian Stock Exchange.

Twitter Circle tweets are not that private anymore

11 April 2023
Numerous Twitter users are reporting a bug in which Circle tweets — which are supposed to reach a select group, like an Instagram Close Friends story — are surfacing on the algorithmically generated For You timeline.

Cryptocurrency Stealer Malware Distributed via 13 NuGet Packages

11 April 2023
Cybersecurity researchers have detailed the inner workings of the cryptocurrency stealer malware that was distributed via 13 malicious NuGet packages as part of a supply chain attack targeting .NET developers. The sophisticated typosquatting campaign, which was detailed by JFrog late last month, impersonated legitimate packages to execute PowerShell code designed to retrieve a follow-on binary

New DEV-1084 Group Linked With MuddyWater, Carries Out Destructive Attacks

11 April 2023
The Iranian nation-sponsored hacker group MuddyWater was spotted joining hands with another emerging threat actor DEV-1084 to conduct destructive attacks disguised as ransomware attacks. DEV-1084 abuses the compromised credentials from high-privilege accounts for the next phase of attacks.

Microsoft delays Exchange Online CARs deprecation until 2024

11 April 2023
Microsoft 365 administrators can utilize CARs comprising priority values, exceptions, actions, and conditions to filter client access to Exchange Online using various factors.

KFC, Pizza Hut Owner Discloses Data Breach After Ransomware Attack

11 April 2023
In the breach notification letters sent to affected people, Yum! Brands revealed that it has now found out the attackers stole some individuals' personal information, including names, driver's license numbers, and other ID card numbers.

Pay $20k and infect Android devices via Google Play store

11 April 2023
This comes after Kaspersky studied nine dark-web markets between 2019 and 2023, and found a slew of code and services for sale to infect and hijack the phones and tablets of Google Play users.