Latest Cybersecurity News and Articles
27 March 2023
On March 16, 2022, about a month after the FBI took down a popular online forum for buying and selling stolen data known as RaidForums, another criminal marketplace quickly sprung up to take its place.
27 March 2023
American university researchers have developed a novel attack called "Near-Ultrasound Inaudible Trojan" (NUIT) that can launch silent attacks against devices powered by voice assistants, like smartphones, smart speakers, and other IoTs.
27 March 2023
Susan Ferensic has been named as the assistant director of the Weapons of Mass Destruction Directorate (WMDD) at FBI Headquarters.
27 March 2023
Azure network defenders can use the tool to export and review sign-in audit logs and activity alerts from a range of Azure and Microsoft Defender environments to pinpoint signs of suspicious activity.
27 March 2023
The attack has not resulted in the breach of any data and court operations are continuing as usual statewide, state Supreme Court Chief Justice Annette Ziegler said in a statement.
27 March 2023
Cyble Research and Intelligence Labs uncovered a new Malware-as-a-Service (MaaS) platform called Cinoshi. Its arsenal includes a stealer, botnet, clipper, and cryptominer. The stealer collects cards, cookies, and credentials from popular browsers including Chromium, Edge, and Gecko. In addition to paid services, the platform also offers a web panel to control malicious activities for free.
27 March 2023
A hospital was hit by a cyberattack - but the full extent of the breach is still unknown. Walsall Healthcare NHS Trust has urged people to "remain vigilant around any suspicious activity" in the wake of the incident.
27 March 2023
"The City and its Information Systems Department (IS) are working with law enforcement to investigate as well as technical specialists experienced in cyber recovery services to restore services as quickly as possible," said city officials.
27 March 2023
The losses for victims range between $2,500 and $500,000, which the syndicate laundered using a massive network of 180 bank accounts, many of which were opened in South African banks using stolen identities.
27 March 2023
Researchers at Cleafy uncovered a new Android banking trojan being tracked as Nexus. The malware has appeared on multiple hacking forums with the same name and is promoted via a Malware-as-a-Service (MaaS) subscription. Though the malware appears to be at a nascent stage, researchers confirmed several active campaigns using it already. It can perform account takeover attacks against apps of 450 banking portals and cryptocurrency services.
27 March 2023
The attack was disclosed on March 19, and threat actors had access to customer and employee information. The agency is going to notify impacted customers and employees via breach notification letters.
27 March 2023
Security experts found a malicious package, named onyxproxy, using leveraged Unicode support in Python to obfuscate an info-stealing malware. They said that the threat actor merely copy-pasted the code from various places and intermixed it with malicious code. The package onyxproxy was published on the platform on March 15 and it amassed 183 downloads before its removal on March 22.
27 March 2023
Upon starting, the ransomware creates a randomized 64-character long lowercase ASCII string. The randomization ensures the key is unique each time the sample is executed, and therefore it is unique on each targeted machine.
27 March 2023
Single sign-on (SSO) is an authentication method that allows users to authenticate their identity for multiple applications with just one set of credentials. From a security standpoint, SSO is the gold standard. It ensures access without forcing users to remember multiple passwords and can be further secured with MFA. Furthermore, an estimated 61% of attacks stem from stolen credentials. By
27 March 2023
OpenAI on Friday disclosed that a bug in the Redis open-source library was responsible for the exposure of other users' personal information and chat titles in the upstart's ChatGPT service earlier this week.
27 March 2023
A new information-stealing malware has set its sights on Apple's macOS operating system to siphon sensitive information from compromised devices.
Dubbed MacStealer, it's the latest example of a threat that uses Telegram as a command-and-control (C2) platform to exfiltrate data. It primarily affects devices running macOS versions Catalina and later running on M1 and M2 CPUs.
"MacStealer has the
27 March 2023
The hacker claimed to have stolen close to 1 million user records, including names, dates of birth, passwords stored in plaintext, and about 415,000 unique email addresses, which iD Tech did not dispute when TechCrunch reached by email.
27 March 2023
In a new campaign, the Perl-based DDoS bot malware ShellBot (also known as PerlBot), which was previously used in assaults alongside CoinMiner, targets poorly maintained Linux SSH servers. Threat actors use three new malware variants - LiGhT's Modded perlbot v2, DDoS PBot v2.0, and PowerBots (C) GohacK. Administrators are suggested to implement strong password policies.
27 March 2023
Microsoft has released an out-of-band update to address a privacy-defeating flaw in its screenshot editing tool for Windows 10 and Windows 11.
The issue, dubbed aCropalypse, could enable malicious actors to recover edited portions of screenshots, potentially revealing sensitive information that may have been cropped out.
Tracked as CVE-2023-28303, the vulnerability is rated 3.3 on the CVSS
27 March 2023
Researchers from Mitiga discovered that the IAM system saves Okta user passwords to audit logs if a user accidentally types them in the "username" field when logging in, thereby allowing threat actors with access to a company system to harvest them.