Latest Cybersecurity News and Articles


BreachedForum Down, ARES Up: Cyber Threat Continues

10 April 2023
After the shutdown of BreachedForum, the emergence of ARES has been detected by researchers, which exhibits a behavior similar to a cartel and strives to form associations with other hackers and ransomware operators. Well-known threat actors are already leveraging the ARES platform to sell compromised data, suggesting that the group is gaining traction.

Hackers Flood NPM with Bogus Packages Causing a DoS Attack

10 April 2023
Threat actors are flooding the npm open source package repository with bogus packages that briefly even resulted in a denial-of-service (DoS) attack. "The threat actors create malicious websites and publish empty packages with links to those malicious websites, taking advantage of open-source ecosystems' good reputation on search engines," Checkmarx's Jossef Harush Kadouri said in a report

Cyberattacks Strike Israel Post, Irrigation Systems Leading to System Outages

10 April 2023
The Israel Postal Company detected and prevented a cyber attack from a "hostile party" targeting their computer servers. The company shut down part of its computer systems in response to the attack on Wednesday evening.

Balada Injector Infected Over a Million Sites in Last Five years

10 April 2023
Sucuri uncovered details about a massive WordPress infection campaign, Balada Injector, that is active since 2017. The attackers are known to leverage all known and recently discovered theme and plugin vulnerabilities. The campaign has infected over one million WordPress websites over a duration of around five years.

All Dutch government networks to use RPKI to prevent BGP hijacking

10 April 2023
The standard uses digital certificates to secure the Border Gateway Protocol (BGP) used for exchanging routing information and ensure that the traffic comes through the legitimate network operator controlling the IP addresses on the destination path.

Top 10 Cybersecurity Trends for 2023: From Zero Trust to Cyber Insurance

10 April 2023
As technology advances, cyberattacks are becoming more sophisticated. With the increasing use of technology in our daily lives, cybercrime is on the rise, as evidenced by the fact that cyberattacks caused 92% of all data breaches in the first quarter of 2022. Staying current with cybersecurity trends and laws is crucial to combat these threats, which can significantly impact business development

Iranian Hackers Caught Carrying Out Destructive Attacks Under Ransomware Guise

10 April 2023
That's according to new findings from the Microsoft Threat Intelligence team, which discovered the MuddyWater threat group targeting both on-premises and cloud infrastructures in partnership with another emerging activity cluster dubbed DEV-1084.

Update: MSI confirms cyberattack, warns against unofficial firmware

10 April 2023
In a statement shared on Friday, MSI confirmed the cyberattack and urged users "to obtain firmware/BIOS updates only from its official website," and to avoid using files from other sources.

DoJ: Estonian Man Tried to Acquire US-Made Hacking Tools for Russia

10 April 2023
According to the DoJ, email communication between Shevlyakov and a Russia-based individual has revealed that he attempted to acquire a licensed copy of Metasploit Pro, a US-made penetration testing tool that cannot be purchased from Russia directly.

Over 1 Million WordPress Sites Infected by Balada Injector Malware Campaign

10 April 2023
Over one million WordPress websites are estimated to have been infected by an ongoing campaign to deploy malware called Balada Injector since 2017. The massive campaign, per GoDaddy's Sucuri, "leverages all known and recently discovered theme and plugin vulnerabilities" to breach WordPress sites. The attacks are known to play out in waves once every few weeks. "This campaign is easily identified

OpenAI to Offer Remedies to Resolve Italy’s ChatGPT Ban

10 April 2023
The Italian data protection authority, known as Garante, last week blocked OpenAI’s popular chatbot, ordering it to temporarily stop processing Italian users’ personal information while it investigates a possible breach of EU data privacy rules.

BreachedForums shutdown sparks migration to ARES data leak forums

10 April 2023
The group accepts cryptocurrency payments from members who want to access the offered data or purchase one of the available services, which span vulnerability exploitation, pen-testing, malware development, and DDoS attacks.

Protecting your business with Wazuh: The open source security platform

10 April 2023
Today, businesses face a variety of security challenges like cyber attacks, compliance requirements, and endpoint security administration. The threat landscape constantly evolves, and it can be overwhelming for businesses to keep up with the latest security trends. Security teams use processes and security solutions to curb these challenges. These solutions include firewalls, antiviruses, data

Amazon Bans Flipper Zero, Claiming It Violates Policy Against Card Skimming Devices

10 April 2023
The device went viral on TikTok last year, with users showing off how the cute little gadget could quickly turn them into amateur hackers. Among its capabilities is using the device to read a credit card number through a wallet and pants.

CISA Warns of 5 Actively Exploited Security Flaws: Urgent Action Required

10 April 2023
Apart from three bugs in the Veritas Backup Exec Agent software, the CISA also warned about a privilege escalation flaw impacting Microsoft Windows Certificate Dialog and an information disclosure flaw in Arm Mali GPU Kernel Driver.

Secret US Documents on Ukraine War Plan Spill Onto Internet: Report

10 April 2023
Secret documents that provide details of US and NATO plans to help prepare Ukraine for a spring offensive against Russia have spilled onto social media platforms, the New York Times reported on Thursday.

Update: Western Digital struggles to fix massive My Cloud outage, offers workaround

10 April 2023
"The Local Access feature allows you to directly access your personal files from a Windows or MacOS computer that is connected to the same network as your device," Western Digital said.

Mastodon Vulnerability Exposes Sensitive Information: Data Leak Alert

10 April 2023
The vulnerability has been labeled CVE-2023-28853, with a " high " risk assessment. Mastodon versions from 2.5.0 were affected, but the developers have since closed the security gaps in versions 4.1.2, 4.0.4, and 3.5.8.

CISA Warns of 5 Actively Exploited Security Flaws: Urgent Action Required

10 April 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. This includes three high-severity flaws in the Veritas Backup Exec Agent software (CVE-2021-27876, CVE-2021-27877, and CVE-2021-27878) that could lead to the execution of privileged commands

Hackers Hide Backdoors Behind Malicious Self-Extracting Archives

09 April 2023
Malicious actors are incorporating harmful features into self-extracting archives created with WinRAR, which contain benign decoy files. This tactic enables them to implant backdoors on the targeted system without arousing any suspicion. An apparently empty SFX archive file can be missed by technology-based detections and easily overlooked by defenders.