Latest Cybersecurity News and Articles


Update: 3CX makes progress in restoring Windows app from state-linked supply chain attack

06 April 2023
The business communications company restored its Windows Electron app, making progress in its ongoing recovery from a recent supply chain attack, CEO Nick Galea said in a forum post on Tuesday.

Vulnerabilities in popular Japanese word processing software could lead to arbitrary code execution, other issues

06 April 2023
Cisco Talos recently discovered four vulnerabilities in Ichitaro, a popular word processing software in Japan produced by JustSystems that could lead to arbitrary code execution.

UK Criminal Records Office's Customer Portal Offline Amid Cybersecurity Incident

06 April 2023
As the name implies, the government agency manages people's criminal record information, running checks as needed on individuals for any convictions, cautions, or ongoing prosecutions.

Supply Chain Attacks and Critical Infrastructure: How CISA Helps Secure a Nation's Crown Jewels

06 April 2023
Critical infrastructure attacks are a preferred target for cyber criminals. Here's why and what's being done to protect them. What is Critical Infrastructure and Why is It Attacked? Critical infrastructure is the physical and digital assets, systems and networks that are vital to national security, the economy, public health, or safety. It can be government- or privately-owned. According to Etay

New OpcJacker Targets Iranian Individuals via Malvertising Lures

06 April 2023
Several fake websites were erected to advertise genuine software and cryptocurrency-related applications only to drop OpcJacker, an info-stealer, stated Trend Micro. The malware is capable of carrying next-stage payloads such as NetSupport RAT and a remote access-focused version with hidden virtual network computing (hVNC).

CISA JCDC Will Focus on Energy Sector

06 April 2023
Public utilities have been put to the test as attacks by bad actors have risen sharply in recent years. Q3 ‘22 saw a record number of attacks on the energy market, a trend that is not expected to slow down.

Android’s April 2023 Updates Patch Critical Remote Code Execution Vulnerabilities

06 April 2023
The security bulletin describes 26 vulnerabilities resolved in the Framework and System components as part of the 2023-04-01 security patch level. Most of these are high-severity flaws causing elevation of privilege (EoP) or information disclosure.

Google will require Android apps to let you delete your account

06 April 2023
According to the new policy, starting in early 2024, Google Play users will have better control over their data since every store listing will display links in the "Data deletion" area, allowing them to ask for their accounts and data to be deleted.

Twitter's recommendation algorithm opens platform to manipulation, bot attacks, researcher finds

06 April 2023
Just three days after Twitter released a portion of its source code online including its recommendation algorithm, a researcher found that attackers could manipulate the software to effectively silence specific accounts on the social media platform.

Telegram now the go-to place for selling phishing tools and services

06 April 2023
A report from Kasperksy notes that phishers sell all types of phishing material and services to interested buyers, including ready-made kits, fake pages, subscriptions to tools, guides, and technical support.

Cyber threats organizations should keep an eye on in 2023

06 April 2023
Two of the currently most threatening malware are Emotet and SocGholish. Android droppers usually come disguised as benign apps, available on third-party app stores or even on Google Play. MacOS malware is not common, but the threat can't be ignored.

Google TAG Warns of North Korean-linked ARCHIPELAGO Cyberattacks

06 April 2023
Attack chains mounted by ARCHIPELAGO involve the use of phishing emails containing malicious links that, when clicked by the recipients, redirect to fake login pages that are designed to harvest credentials.

FBI Cracks Down on Genesis Market: 119 Arrested in Cybercrime Crackdown

06 April 2023
A coordinated international law enforcement operation has dismantled Genesis Market, an illegal online marketplace that specialized in the sale of stolen credentials associated with email, bank accounts, and social media platforms. Coinciding with the infrastructure seizure, the major crackdown, which involved authorities from 17 countries, culminated in 119 arrests and 208 property searches in

How ChatGPT can be poked into emitting malicious code

06 April 2023
An experiment by a Forcepoint staffer does, to some extent, highlight how the code-suggesting unreliable chatbot, built by OpenAI and pushed by Microsoft, could be used to cut some corners in malware development or automate the process.

3CX Supply Chain Attack by Lazarus also Targets Crypto Firms

06 April 2023
Kaspersky attributed the 3CX supply chain attack to the North Korean Lazarus APT group, owing to the deployment of the Gopuram and AppleJeus backdoors used by the threat actor. Attackers deployed Gopuram on machines mostly belonging to cryptocurrency companies in Brazil, Germany, Italy, and France.

UK Discloses Offensive Cyber Capabilities Principles

06 April 2023
The UK government continues to adjust its cyber response to the growing threat posed by nation-state adversaries, in line with its latest National Cyber Strategy (NCS), published in December 2022.

New CryptoClippy Malware Targeting Portuguese Cryptocurrency Users

06 April 2023
The activity leverages SEO poisoning techniques to entice users searching for "WhatsApp web" to rogue domains hosting the malware, Palo Alto Networks Unit 42 said in a new report published today.

Rilide Info-stealer: A Serious Threat to Cryptocurrency Assets

06 April 2023
Trustwave SpiderLabs laids bare a new malware, dubbed Rilide, that can steal cryptocurrency by abusing multiple Chromium-based browsers, such as Google Chrome, Opera, Microsoft Edge, and Brave. Experts recommend remaining vigilant when opening emails from unknown and untrusted sources.

Google Mandates Android Apps to Offer Easy Account Deletion In-App and Online

05 April 2023
Google is enacting a new data deletion policy for Android apps that allow account creation to also offer users with a setting to delete their accounts in an attempt to provide more transparency and control over their data. "For apps that enable app account creation, developers will soon need to provide an option to initiate account and data deletion from within the app and online," Bethel

New Proxyjacking Attack Exploits Log4j for Initial Access

05 April 2023
Researchers at Sysdig highlight that the new Proxyjacking attack, which is much like cryptojacking, is abusing the infamous Log4j vulnerability to gain initial access to victims’ systems. On a broader scale, researchers note that a modest compromise of 100 IPs can enable attackers to make a profit of nearly $1,000 per month.