Latest Cybersecurity News and Articles
10 April 2023
After the shutdown of BreachedForum, the emergence of ARES has been detected by researchers, which exhibits a behavior similar to a cartel and strives to form associations with other hackers and ransomware operators. Well-known threat actors are already leveraging the ARES platform to sell compromised data, suggesting that the group is gaining traction.
10 April 2023
Threat actors are flooding the npm open source package repository with bogus packages that briefly even resulted in a denial-of-service (DoS) attack.
"The threat actors create malicious websites and publish empty packages with links to those malicious websites, taking advantage of open-source ecosystems' good reputation on search engines," Checkmarx's Jossef Harush Kadouri said in a report
10 April 2023
The Israel Postal Company detected and prevented a cyber attack from a "hostile party" targeting their computer servers. The company shut down part of its computer systems in response to the attack on Wednesday evening.
10 April 2023
Sucuri uncovered details about a massive WordPress infection campaign, Balada Injector, that is active since 2017. The attackers are known to leverage all known and recently discovered theme and plugin vulnerabilities. The campaign has infected over one million WordPress websites over a duration of around five years.
10 April 2023
The standard uses digital certificates to secure the Border Gateway Protocol (BGP) used for exchanging routing information and ensure that the traffic comes through the legitimate network operator controlling the IP addresses on the destination path.
10 April 2023
As technology advances, cyberattacks are becoming more sophisticated. With the increasing use of technology in our daily lives, cybercrime is on the rise, as evidenced by the fact that cyberattacks caused 92% of all data breaches in the first quarter of 2022. Staying current with cybersecurity trends and laws is crucial to combat these threats, which can significantly impact business development
10 April 2023
That's according to new findings from the Microsoft Threat Intelligence team, which discovered the MuddyWater threat group targeting both on-premises and cloud infrastructures in partnership with another emerging activity cluster dubbed DEV-1084.
10 April 2023
In a statement shared on Friday, MSI confirmed the cyberattack and urged users "to obtain firmware/BIOS updates only from its official website," and to avoid using files from other sources.
10 April 2023
According to the DoJ, email communication between Shevlyakov and a Russia-based individual has revealed that he attempted to acquire a licensed copy of Metasploit Pro, a US-made penetration testing tool that cannot be purchased from Russia directly.
10 April 2023
Over one million WordPress websites are estimated to have been infected by an ongoing campaign to deploy malware called Balada Injector since 2017.
The massive campaign, per GoDaddy's Sucuri, "leverages all known and recently discovered theme and plugin vulnerabilities" to breach WordPress sites. The attacks are known to play out in waves once every few weeks.
"This campaign is easily identified
10 April 2023
The Italian data protection authority, known as Garante, last week blocked OpenAI’s popular chatbot, ordering it to temporarily stop processing Italian users’ personal information while it investigates a possible breach of EU data privacy rules.
10 April 2023
The group accepts cryptocurrency payments from members who want to access the offered data or purchase one of the available services, which span vulnerability exploitation, pen-testing, malware development, and DDoS attacks.
10 April 2023
Today, businesses face a variety of security challenges like cyber attacks, compliance requirements, and endpoint security administration. The threat landscape constantly evolves, and it can be overwhelming for businesses to keep up with the latest security trends. Security teams use processes and security solutions to curb these challenges. These solutions include firewalls, antiviruses, data
10 April 2023
The device went viral on TikTok last year, with users showing off how the cute little gadget could quickly turn them into amateur hackers. Among its capabilities is using the device to read a credit card number through a wallet and pants.
10 April 2023
Apart from three bugs in the Veritas Backup Exec Agent software, the CISA also warned about a privilege escalation flaw impacting Microsoft Windows Certificate Dialog and an information disclosure flaw in Arm Mali GPU Kernel Driver.
10 April 2023
Secret documents that provide details of US and NATO plans to help prepare Ukraine for a spring offensive against Russia have spilled onto social media platforms, the New York Times reported on Thursday.
10 April 2023
"The Local Access feature allows you to directly access your personal files from a Windows or MacOS computer that is connected to the same network as your device," Western Digital said.
10 April 2023
The vulnerability has been labeled CVE-2023-28853, with a " high " risk assessment. Mastodon versions from 2.5.0 were affected, but the developers have since closed the security gaps in versions 4.1.2, 4.0.4, and 3.5.8.
10 April 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.
This includes three high-severity flaws in the Veritas Backup Exec Agent software (CVE-2021-27876, CVE-2021-27877, and CVE-2021-27878) that could lead to the execution of privileged commands
09 April 2023
Malicious actors are incorporating harmful features into self-extracting archives created with WinRAR, which contain benign decoy files. This tactic enables them to implant backdoors on the targeted system without arousing any suspicion. An apparently empty SFX archive file can be missed by technology-based detections and easily overlooked by defenders.