Latest Cybersecurity News and Articles
31 March 2023
Almost a year after the crisis began, a senior White House official told reporters today that the United States plans to provide $25 million in cybersecurity assistance to help Costa Rica strengthen its digital infrastructure.
31 March 2023
In early 2020, Formbook was rebranded as Xloader, and the operators behind it moved to a malware-as-a-service (MaaS) business model, renting C2 infrastructure to customers.
31 March 2023
The advanced persistent threat (APT) actor known as Winter Vivern is now targeting officials in Europe and the U.S. as part of an ongoing cyber espionage campaign.
"TA473 since at least February 2023 has continuously leveraged an unpatched Zimbra vulnerability in publicly facing webmail portals that allows them to gain access to the email mailboxes of government entities in Europe," Proofpoint
31 March 2023
New studies by NCC Group and Barracuda Networks show threat actors are increasing ransomware exploits, with consumer goods and services receiving the brunt of attacks and a large percentage of victims being hit multiple times.
31 March 2023
To defend against RedGolf attacks, organizations are recommended to apply patches regularly, monitor access to external facing network devices, track and block identified C2 infrastructure, and configure IDS/IPS to monitor for malware detections.
31 March 2023
The crime group created over 100 fake "phishing" sites targeting users in France, Spain, Poland, the Czech Republic, Portugal, and other European countries, enticing them with products below market prices.
31 March 2023
Exposed personal information, the company says, includes names, addresses, phone numbers, email addresses, birth dates, driver’s license numbers, Social Security numbers, and employment positions.
31 March 2023
An executive order was signed by President Biden prohibiting the use of commercial spyware that pose risks to national security or human rights.
31 March 2023
It appears that domain registrars and certificate-issuing authorities are becoming less effective at preventing fraudsters from obtaining and using legitimate certificates to enhance their phishing success rates.
31 March 2023
The data breach at Nebu has affected Nederlandse Spoorwegen (NS), VodafoneZiggo, ArboNed, Heineken, International Film Festival Rotterdam, the Dutch Golf Federation, CZ (insurance firm), Trevvel, and the Dutch Rental Commission (Huurcommissie).
31 March 2023
The Cyber Police of Ukraine, in collaboration with law enforcement officials from Czechia, has arrested several members of a cybercriminal gang that set up phishing sites to target European users.
Two of the apprehended affiliates are believed to be organizers, with 10 others detained in other territories across the European Union.
The suspects are alleged to have created more than 100 phishing
31 March 2023
The San Jose, California-based networking giant said its proposed buy of Lightspin will allow clients to identify and address key cloud security risks without the hassle of extensive configuration requirements.
31 March 2023
Organizations rely on Incident response to ensure they are immediately aware of security incidents, allowing for quick action to minimize damage. They also aim to avoid follow on attacks or future related incidents.
The SANS Institute provides research and education on information security. In the upcoming webinar, we’ll outline, in detail, six components of a SANS incident response plan,
31 March 2023
Almost a month after attending a concert at Cornell University featuring the Beach Bunny band on January 28, several Ithaca College students’ credit and debit card information was breached and varying amounts of money were stolen.
31 March 2023
DataDome has raised a total of $81 million in VC funding since launching in 2015 with software to help businesses deal with bots and online fraud activity. The company said the new funding would be used on market expansion and R&D activities.
31 March 2023
The flaws in question were abused as part of several exploit chains in two separate highly-targeted campaigns targeting Android and iOS users, as Google's Threat Analysis Group (TAG) recently revealed.
31 March 2023
The hackers said they were able to enter the colonel’s military accounts and found information about his subordinates, the movement of troops, and documents related to Russian military equipment.
31 March 2023
Enterprise communications software maker 3CX on Thursday confirmed that multiple versions of its desktop app for Windows and macOS are affected by a supply chain attack.
The version numbers include 18.12.407 and 18.12.416 for Windows and 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 for macOS.
The company said it's engaging the services of Google-owned Mandiant to review the incident. In the
31 March 2023
An APT group known in the security industry as Winter Vivern has been exploiting a vulnerability in the Zimbra Collaboration software to gain access to mailboxes from government agencies in several European countries.
31 March 2023
According to a guidance document published earlier today, applicants seeking approval for new medical devices must submit a plan designed to “monitor, identify and address” possible cybersecurity issues associated with them.