Latest Cybersecurity News and Articles


Adobe Reset User Passwords as Precaution Against Data Breach Risks

07 April 2023
The email states that Adobe has reset the password for the account associated with the users’ Adobe ID, as it may have been compromised in data breaches from other online services.

Sophos Patches Critical Code Execution Vulnerability in Web Security Appliance

07 April 2023
The critical issue, tracked as CVE-2023-1671 (CVSS score of 9.8), was identified in the warning page handler of the appliance and it could be exploited without authentication.

Hackers leak info on 16,000 Aussie school kids

07 April 2023
Hackers have released 16,000 Tasmanian education department documents on the dark web including school children’s personal information, the state government has confirmed.

Default static key in ThingsBoard IoT platform can give attackers admin access

07 April 2023
The flaw was fixed in ThingsBoard version 3.4.2 by generating a random key for every new installation or upgrade to version 3.4.2 or later. If admins can't upgrade immediately, they can manually change the default signing key for older versions.

Pro-Russia Hacker Group Launches DDoS Attacks Against Finnish Parliament, Technical Research Center

07 April 2023
NoName057(16) reportedly claimed it was behind DoS attacks against the Finnish parliament’s website on Tuesday, the day the country joined NATO. The country’s Technical Research Centre of Finland was also hacked, according to Finnish news site, YLE.

Report: Endpoint ransomware detections increase 627%

07 April 2023
A report shows endpoint ransomware increased 627% and malware associated with phishing campaigns continues to be a constant threat.

CISA Warns of Critical ICS Flaws in Hitachi, mySCADA, ICL, and Nexx Products

07 April 2023
The Cybersecurity and Infrastructure Security Agency (CISA) has published eight Industrial Control Systems (ICS) advisories warning of critical flaws affecting products from Hitachi Energy, mySCADA Technologies, Industrial Control Links, and Nexx.

Balada Injector: Synopsis of a Massive Ongoing WordPress Malware Campaign

07 April 2023
During the many years of Balada Injector’s operation since 2017, Sucuri researchers have observed consistent patterns of infection waves on a pretty regular basis. These waves tended to occur every couple of weeks, sometimes once a month.

Ransomware Attack at NJ County Police Department Locks Up Criminal Investigative Files

07 April 2023
The FBI, NJ State Homeland Security's office, and the New Jersey attorney general’s office were all notified of the incident and are assisting in the investigation, several officials said.

Researchers Uncover Thriving Phishing Kit Market on Telegram Channels

07 April 2023
In yet another sign that Telegram is increasingly becoming a thriving hub for cybercrime, researchers have found that threat actors are using the messaging platform to peddle phishing kits and help set up phishing campaigns. "To promote their 'goods,' phishers create Telegram channels through which they educate their audience about phishing and entertain subscribers with polls like, 'What type

How the Last Big Breach Will Help You Prepare for the Next Cyber Crisis

07 April 2023
Security teams ought to seize on the opportunities of failures of the past to make meaningful change in how we approach incident response, urged Sarah Armstrong-Smith, chief security advisor at Microsoft, during UK Cyber Week 2023.

Researchers Uncover New European Malware-as-a-Service Group

07 April 2023
A crew of English-speaking European teenagers with a variety of skills and a propensity for allusions to Greek and Roman mythology are likely behind an up-and-coming cybercrime group called FusionCore.

Inside Kremlin's Cyber Arsenal: Unveiling the Secrets of Vulkan Files

07 April 2023
Sensitive documents leaked by a whistleblower reveal Moscow-based IT contractor NTC Vulkan's involvement in developing offensive tools for the Russian military, intelligence agencies, and the Russia-linked APT group Sandworm. The leaked documents specifically cover details of three projects, named Scan, Amesit, and Krystal-2B. 

New Generation of Phishing Hides Behind Trusted Services

07 April 2023
With the increasing use of cloud-based office productivity and collaboration tools, attackers can now easily host and share malicious documents, files, and malware on reputable domains.

Medusa Ransomware Claims Attack on Open University of Cyprus

07 April 2023
Today, the Medusa ransomware group posted OUC on its data leak site, giving the institute 14 days to respond to its ransom demands. The hackers asked for $100,000. However, it set the same price for both deleting the data as well as for selling it.

Broad MFA, rapid patching a must to stop cyberattacks, Marsh McLennan finds

07 April 2023
Companies currently implement MFA at many different levels, however, the report shows the technique only works if it is broadly applied, according to Scott Stransky, managing director and head of the Marsh McLennan Cyber Risk Analytics Center.

Cisco Patches Code and Command Execution Vulnerabilities in Several Products

07 April 2023
Cisco this week announced patches for multiple vulnerabilities across its product portfolio, including high-severity issues impacting its Secure Network Analytics and Identity Services Engine (ISE) products.

Data-leak flaw in Qualcomm, HiSilicon-based Wi-Fi AP chips

07 April 2023
Researchers in China and the US have published details of a security shortcoming in the network processing units (NPUs) in Qualcomm and HiSilicon chips found at the heart of various wireless access points (APs).

The Rise of CCTV Hacks in an Evolving Cyber-Threat Landscape

07 April 2023
With access to CCTV footage, cybercriminals can do a lot of damage – from learning a household’s daily schedule to plan burglaries to accessing financial or personal information to steal identities for social engineering attacks or fraud.

Phishing From Legitimate QuickBooks Domain

07 April 2023
In this attack, hackers are sending fake invoices from a legitimate Quickbooks domain. This email comes directly from Quickbooks. It has a QuickBooks email address, meaning it will pass all SPF checks, domain checks, and more.