Latest Cybersecurity News and Articles


The US Is Sending Money to Countries Devastated by Cyberattacks

31 March 2023
Almost a year after the crisis began, a senior White House official told reporters today that the United States plans to provide $25 million in cybersecurity assistance to help Costa Rica strengthen its digital infrastructure.

Xloader's Newest Variant Brings Upgraded Code Obfuscation Capabilities

31 March 2023
In early 2020, Formbook was rebranded as Xloader, and the operators behind it moved to a malware-as-a-service (MaaS) business model, renting C2 infrastructure to customers.

Winter Vivern APT Targets European Government Entities with Zimbra Vulnerability

31 March 2023
The advanced persistent threat (APT) actor known as Winter Vivern is now targeting officials in Europe and the U.S. as part of an ongoing cyber espionage campaign. "TA473 since at least February 2023 has continuously leveraged an unpatched Zimbra vulnerability in publicly facing webmail portals that allows them to gain access to the email mailboxes of government entities in Europe," Proofpoint 

Ransomware attacks skyrocket as threat actors double down on U.S., global attacks

31 March 2023
New studies by NCC Group and Barracuda Networks show threat actors are increasing ransomware exploits, with consumer goods and services receiving the brunt of attacks and a large percentage of victims being hit multiple times.

Chinese RedGolf Group Targeting Windows and Linux Systems with KEYPLUG Backdoor

31 March 2023
To defend against RedGolf attacks, organizations are recommended to apply patches regularly, monitor access to external facing network devices, track and block identified C2 infrastructure, and configure IDS/IPS to monitor for malware detections.

Ukrainian cyberpolice busts fraud gang that stole $4.3 million

31 March 2023
The crime group created over 100 fake "phishing" sites targeting users in France, Spain, Poland, the Czech Republic, Portugal, and other European countries, enticing them with products below market prices.

Debt Buyer NCB Management Services Notifies 500,000 People Impacted by Data Breach

31 March 2023
Exposed personal information, the company says, includes names, addresses, phone numbers, email addresses, birth dates, driver’s license numbers, Social Security numbers, and employment positions.

Biden Administration addresses potential commercial spyware risks

31 March 2023
An executive order was signed by President Biden prohibiting the use of commercial spyware that pose risks to national security or human rights. 

Volume of HTTPS Phishing Sites Surges 56% Annually

31 March 2023
It appears that domain registrars and certificate-issuing authorities are becoming less effective at preventing fraudsters from obtaining and using legitimate certificates to enhance their phishing success rates.

Millions Affected by Dutch People Affected by Data Breach at Customer Survey Software Provider

31 March 2023
The data breach at Nebu has affected Nederlandse Spoorwegen (NS), VodafoneZiggo, ArboNed, Heineken, International Film Festival Rotterdam, the Dutch Golf Federation, CZ (insurance firm), Trevvel, and the Dutch Rental Commission (Huurcommissie).

Cyber Police of Ukraine Busted Phishing Gang Responsible for $4.33 Million Scam

31 March 2023
The Cyber Police of Ukraine, in collaboration with law enforcement officials from Czechia, has arrested several members of a cybercriminal gang that set up phishing sites to target European users. Two of the apprehended affiliates are believed to be organizers, with 10 others detained in other territories across the European Union. The suspects are alleged to have created more than 100 phishing

Cisco Buys Startup Lightspin to Address Cloud Security Risks

31 March 2023
The San Jose, California-based networking giant said its proposed buy of Lightspin will allow clients to identify and address key cloud security risks without the hassle of extensive configuration requirements.

Deep Dive Into 6 Key Steps to Accelerate Your Incident Response

31 March 2023
Organizations rely on Incident response to ensure they are immediately aware of security incidents, allowing for quick action to minimize damage. They also aim to avoid follow on attacks or future related incidents. The SANS Institute provides research and education on information security. In the upcoming webinar, we’ll outline, in detail, six components of a SANS incident response plan,

Students’ Bank Accounts Hacked Because of Ticketing Software Breach

31 March 2023
Almost a month after attending a concert at Cornell University featuring the Beach Bunny band on January 28, several Ithaca College students’ credit and debit card information was breached and varying amounts of money were stolen.

Anti-Bot Software Firm DataDome Banks $42M Financing

31 March 2023
DataDome has raised a total of $81 million in VC funding since launching in 2015 with software to help businesses deal with bots and online fraud activity. The company said the new funding would be used on market expansion and R&D activities.

CISA orders agencies to patch bugs exploited to drop spyware

31 March 2023
The flaws in question were abused as part of several exploit chains in two separate highly-targeted campaigns targeting Android and iOS users, as Google's Threat Analysis Group (TAG) recently revealed.

Hackers Claim to Dox Russian 'War Criminal,' Convince His Wife to Do 'Patriotic Photoshoot'

31 March 2023
The hackers said they were able to enter the colonel’s military accounts and found information about his subordinates, the movement of troops, and documents related to Russian military equipment.

3CX Supply Chain Attack — Here's What We Know So Far

31 March 2023
Enterprise communications software maker 3CX on Thursday confirmed that multiple versions of its desktop app for Windows and macOS are affected by a supply chain attack. The version numbers include 18.12.407 and 18.12.416 for Windows and 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 for macOS. The company said it's engaging the services of Google-owned Mandiant to review the incident. In the

APT group Winter Vivern exploits Zimbra webmail flaw to target government entities

31 March 2023
An APT group known in the security industry as Winter Vivern has been exploiting a vulnerability in the Zimbra Collaboration software to gain access to mailboxes from government agencies in several European countries.

FDA Protects Medical Devices Against Cyber-Threats With New Measures

31 March 2023
According to a guidance document published earlier today, applicants seeking approval for new medical devices must submit a plan designed to “monitor, identify and address” possible cybersecurity issues associated with them.