Latest Cybersecurity News and Articles
29 March 2023
As seen with past attacks from this group, these most recent attacks do not seem to be originating from a single botnet, and the attack methods and sources seem to vary, suggesting the involvement of multiple individual threat actors.
29 March 2023
The report also found that 80% of attacks happened over authenticated APIs, making it a widespread problem for all. Given that it is one of the easiest types of attack to execute, it is no surprise that attackers are increasingly taking this route.
29 March 2023
A new report reveals a turbulent year in the threat actor community as Russia’s invasion of Ukraine disrupted the operations of top ransomware groups.
29 March 2023
ENISA says the three dominant threats to the transportation sector are ransomware (38 percent), data-related threats (30 percent), and malware (17 percent). However, each subgroup has reported experiencing other attack types than ransomware.
29 March 2023
In this blog, researchers have shared details about two distinct campaigns that used various 0-day exploits against Android, iOS, and Chrome and were both limited and highly targeted.
29 March 2023
Mélofée's features are no different from other backdoors of its kind, enabling it to contact a remote server and receive instructions that allow it to carry out file operations, create sockets, launch a shell, and execute arbitrary commands.
29 March 2023
The ransomware attack hit Technion on February 12, forcing the university to block all communication networks. DarkBit originally demanded 80 bitcoins as ransom from the university.
29 March 2023
Powered by OpenAI’s GPT-4 generative AI and Microsoft’s security-specific model, Security Copilot looks like a simple prompt box like any other chatbot. You can ask “what are all the security incidents in my enterprise?”
29 March 2023
A number of zero-day vulnerabilities that were addressed last year were exploited by commercial spyware vendors to target Android and iOS devices, Google's Threat Analysis Group (TAG) has revealed.
The two distinct campaigns were both limited and highly targeted, taking advantage of the patch gap between the release of a fix and when it was actually deployed on the targeted devices.
"These
29 March 2023
The company did not reveal the spyware vendors involved but said one of the campaigns used a link directing targets to a landing page identical to one Google revealed in November 2022 from Spanish spyware firm Variston IT.
29 March 2023
Euler Finance was hacked on March 13, 2023, and around $197 million worth of cryptocurrency was stolen, including $135.8 million stETH, $33.8 million USDC, $18.5 million WBTC, and $8.7 million DAI.
29 March 2023
Tracked as CVE-2022-47986, the vulnerability makes it possible for unauthenticated threat actors to remotely execute malicious code by sending specially crafted calls to an outdated programming interface.
29 March 2023
An unknown Chinese state-sponsored hacking group has been linked to a novel piece of malware aimed at Linux servers.
French cybersecurity firm ExaTrack, which found three samples of the previously documented malicious software that date back to early 2022, dubbed it Mélofée.
One of the artifacts is designed to drop a kernel-mode rootkit that's based on an open source project referred to as
29 March 2023
The protocol is good for cybercriminals in that it lets attackers cut back on phishing webpage hosting costs and its distributed nature makes it near impossible to delete files.
29 March 2023
Proofpoint analysts uncovered variants of the IcedID banking Trojan—Lite, and Forked—that focus on additional payload and bot delivery, respectively. According to experts, the initial developers of Emotet and IcedID operators have worked together on the Lite version. Meanwhile, the new threat group TA581 was observed using the Forked version. All in all, at least three threat actors exploited the new variants of IcedID.
29 March 2023
Successful digital skimming attacks are often the result of misconfigurations or lack of security controls within a merchant’s environment, which threat actors exploit to deploy the malicious skimming code.
29 March 2023
The emergence of smart mobility services and applications has led to a sharp increase in the use of APIs in the automotive industry. However, this increased reliance on APIs has also made them one of the most common attack vectors. According to Gartner, APIs account for 90% of the web application attack surface areas.
With no surprise, similar trends are emerging also in the smart mobility
29 March 2023
Malware analysis is an essential part of security researcher's work. But working with malicious samples can be dangerous — it requires specialized tools to record their activity, and a secure environment to prevent unintended damage.
However, manual lab setup and configuration can prove to be a laborious and time-consuming process.
In this article, we'll look at 4 ways to create a reverse
29 March 2023
The company exposed credentials to the Salesforce Marketing Cloud, a provider of digital marketing automation and analytics software and services. Cybernews has reached out to the car manufacturer, and the dataset has been secured.
29 March 2023
Threat actors target OT and IoT devices because they are the most difficult to patch. Researchers also said botnets have expanded their capabilities, targeting internet of things (IoT) devices to conduct lateral movement in enterprise networks.