Latest Cybersecurity News and Articles
04 April 2023
Security researchers state the malicious JavaScript file existed on eFile.com website for weeks. BleepingComputer has been able to confirm the existence of the malicious JavaScript file in question, at the time.
04 April 2023
The rapid pace of cloud transformation and democratization of data has created a new innovation attack surface, leading to 3 in 4 organizations experiencing a cloud data breach in 2022, according to Laminar.
04 April 2023
Most healthcare provider organizations exposed visitors to higher levels of tracking, through the use of third-party tracking codes on their websites. In doing so, patients are likely to see an increase in targeted health-related advertising.
04 April 2023
Uber has had more of its internal data stolen from a third party that suffered a security breach. This time, the personal info of the app's drivers was swiped by miscreants from the IT systems of law firm Genova Burns.
04 April 2023
Some of the victims affected by the 3CX supply chain attack have also had their systems backdoored with Gopuram malware, with the threat actors specifically targeting cryptocurrency companies with this additional malicious payload.
04 April 2023
According to the IG, “control weaknesses within the ECM system can pose a substantial risk to taxpayer records currently residing in the system. The potential harm includes breach, unauthorized access, and disclosure of taxpayer information.”
04 April 2023
Judges in the Central District of California, the District of Arizona, and the District of Idaho authorized today's action. The DOJ says the next step is to return the stolen cryptocurrency to the victims.
04 April 2023
As advanced threats become more common, layered security that incorporates memory defense is becoming essential. Without it, there is no effective way to stop threats targeting device memory.
04 April 2023
The threat actor known as Arid Viper has been observed using refreshed variants of its malware toolkit in its attacks targeting Palestinian entities since September 2022.
Symantec, which is tracking the group under its insect-themed moniker Mantis, said the adversary is "going to great lengths to maintain a persistent presence on targeted networks."
Also known by the names APT-C-23 and Desert
04 April 2023
Collaboration sits at the essence of SaaS applications. The word, or some form of it, appears in the top two headlines on Google Workspace’s homepage. It can be found six times on Microsoft 365’s homepage, three times on Box, and once on Workday. Visit nearly any SaaS site, and odds are ‘collaboration’ will appear as part of the app’s key selling point.
By sitting on the cloud, content within
04 April 2023
The Chief Digital and Artificial Intelligence Office (CDAO) Directorate for Digital Services (DDS), Craig Martell, unveiled the website last Thursday. It will help DoD organizations, vendors, and researchers understand how to conduct a bug bounty.
04 April 2023
The QNAP vulnerabilities affect the operating systems: QTS, QuTS hero, QuTScloud, and QVP (QVR Pro appliances). These operating system versions have already been updated.
04 April 2023
Britain’s newly created offensive hacking unit, the National Cyber Force, has said it is engaged daily in operations to disrupt terrorist groups, distributors of child sexual abuse material, and military opponents of the UK.
04 April 2023
A new ransomware group with two victims listed on its leak site has been observed making million-dollar ransom demands. The group, called Money Message, has listed an Asian airline, which has revenue close to $1 billion, as one of its victims. Adversaries have shared a screenshot of the accessed file system as proof of the breach.
04 April 2023
To strengthen their cybersecurity posture, companies must spend valuable resources on maintaining or updating systems, hiring and training staff, and implementing security software — resources and options that many don’t have readily available.
04 April 2023
Hackers are adding malicious functionality to WinRAR self-extracting archives that contain harmless decoy files, allowing them to plant backdoors without triggering the security agent on the target system.
04 April 2023
With a small payroll and tight staffing constraints, smaller businesses are unlikely to have a mature security posture that could otherwise deflect social engineering scams.
04 April 2023
Upon realizing that session resumption led to the inability to properly check revocation status, Cloudflare responded by first disabling session resumption for all mTLS connections. This blocked the vulnerability immediately.
04 April 2023
Google’s TAG shared details on zero-day and n-day vulnerabilities affecting Android and iOS devices that are under exploitation by highly-targeted spyware campaigns. It didn’t reveal the spyware vendors involved or identify the number of victims targeted in this campaign. Organizations are suggested to leverage the IOCs shared by Google and other security agencies to strengthen their security posture.
04 April 2023
A Chinese state-sponsored threat group has been linked to a unique malware, dubbed Mélofée, targeting Linux servers. The threat group’s infrastructure overlaps mostly with Winnti. Researchers observed another AlienReverse implant being used during the campaign.