Latest Cybersecurity News and Articles


Fake Ransomware Gang Targets U.S. Organizations With Empty Data Leak Threats

03 April 2023
Fake extortionists are piggybacking on data breaches and ransomware incidents, threatening U.S. companies with publishing or selling allegedly stolen data unless they get paid.

Italian Watchdog Bans OpenAI's ChatGPT Over Data Protection Concerns

03 April 2023
The Italian data protection watchdog, Garante per la Protezione dei Dati Personali (aka Garante), has imposed a temporary ban of OpenAI's ChatGPT service in the country, citing data protection concerns. To that end, it has ordered the company to stop processing users' data with immediate effect, stating it intends to investigate the company over whether it's unlawfully processing such data in

"It's The Service Accounts, Stupid": Why Do PAM Deployments Take (almost) Forever To Complete

03 April 2023
Privileged Access Management (PAM) solutions are regarded as the common practice to prevent identity threats to administrative accounts. In theory, the PAM concept makes absolute sense: place admin credentials in a vault, rotate their passwords, and closely monitor their sessions. However, the harsh reality is that the vast majority of PAM projects either become a years-long project, or even

Jefferson County Schools hit with ransomware attack

03 April 2023
Out of an abundance of caution, all network systems have been taken down to investigate thoroughly. These networks will be reconnected once all traces of malware are gone.

UK Regulator Calls for HIV Data Protection Improvement

03 April 2023
The UK’s Information Commissioner’s Office (ICO) has called for “serious improvements” to data protection processes for organizations handling information on HIV sufferers, after reprimanding an NHS body.

New Tactical Octopus Attack Campaign Targets US Entities with Malware Bundled in Tax-Themed Documents

03 April 2023
As the tax deadline on April 15 approaches in the US, threat actors are ramping up tax-related phishing scams to US-based victims to infect systems with stealthy malware.

DISH slapped with multiple lawsuits after ransomware cyber attack

03 April 2023
These class action lawsuits, filed across different states, allege that DISH "overstated" its operational efficiency while having a deficient cybersecurity and IT infrastructure.

TikTok Attorney: China Can’t Get U.S. Data Under Plan

03 April 2023
Under intense scrutiny from Washington that could lead to a potential ban, the top attorney for TikTok and its Chinese parent company ByteDance defended the social media platform’s plan to safeguard U.S. user data from China.

Winter Vivern Launches Attacks Against Government Entities in Europe

03 April 2023
The Winter Vivern APT group was seen abusing a bug in the Zimbra Collaboration software to obtain secrets from the email inboxes of government agencies in European countries. The group uses scanning technologies like Acunetix to find unpatched webmail portals to attack potential victims. The XSS bug, CVE-2022-27926, impacts Zimbra Collaboration version 9.0.0.

Crypto-Stealing OpcJacker Malware Targets Users with Fake VPN Service

03 April 2023
A piece of new information-stealing malware called OpcJacker has been spotted in the wild since the second half of 2022 as part of a malvertising campaign. "OpcJacker's main functions include keylogging, taking screenshots, stealing sensitive data from browsers, loading additional modules, and replacing cryptocurrency addresses in the clipboard for hijacking purposes," Trend Micro researchers

OSC&R open software supply chain attack framework now on GitHub

03 April 2023
OSC&R is an open framework for understanding and evaluating software supply chain security threats. It has received the endorsement of former U.S. NSA Director Admiral Mike Rogers and is now available on GitHub.

Update: North Korean Lazarus Group Linked to 3CX Supply Chain Hack

03 April 2023
Security researchers have uncovered more evidence that the North Korean Lazarus group is responsible for the software supply chain attack on 3CX, a voice and video-calling desktop client used by major multinational companies.

Ukrainian Hackers Trick Russian Military Wives for Personal Info

03 April 2023
The hackers convinced the wife of a serving colonel in the Russian military to participate in a patriotic photoshoot. She then convinced 12 more military wives to join, which allowed them to extract personal and sensitive information.

LockBit claims to leak data stolen from the South Korean National Tax Service

03 April 2023
On March 29, 2023, the ransomware gang announced the hack of the South Korean National Tax Service. It added the South Korean agency to its Tor leak site and announced the release of stolen data by April 1st, 2023 in case the ransom was not paid.

Hook, Line, and Sinker: Phishing Landscape in 2022

03 April 2023
Cofense released a report around the top phishing trends from 2022 and found that attackers largely preferred credential phishing as their primary attack method. The use of malware in these attacks increased by 44%, with Emotet and Qakbot being the most used malware families. Moreover, the total volume of scam URLs increased by 30% between 2021 and 2022.

Mustang Panda Cyberespionage Strikes Over 200 Targets

03 April 2023
Researchers discovered that a series of cyberespionage attacks launched by the subgroups of Earth Preta APT has affected over 200 organizations. While part of these subgroups is focused on stealing intellectual property and business information, others target government and diplomatic entities.

Operation Henhouse: Hundreds of arrests and millions in assets seized in month tackling fraud

01 April 2023
The NCA’s National Economic Crime Centre has led a successful operation working closely with the City of London Police and other policing partners against suspected fraudsters across the UK.

15 million public-facing services vulnerable to CISA KEV flaws

01 April 2023
This massive number is reported by cybersecurity company Rezilion, which conducted large-scale research to identify vulnerable systems exposed to cyberattacks from threat actors, whether state-sponsored or ransomware gangs.

Italy Temporarily Blocks ChatGPT Over Privacy Concerns

01 April 2023
Italy is temporarily blocking the artificial intelligence software ChatGPT in the wake of a data breach as it investigates a possible violation of stringent European Union data protection rules, the government’s privacy watchdog said Friday.

Microsoft Fixes New Azure AD Vulnerability Impacting Bing Search and Major Apps

01 April 2023
Microsoft has patched a misconfiguration issue impacting the Azure Active Directory (AAD) identity and access management service that exposed several "high-impact" applications to unauthorized access. "One of these apps is a content management system (CMS) that powers Bing.com and allowed us to not only modify search results, but also launch high-impact XSS attacks on Bing users," cloud security