Latest Cybersecurity News and Articles
21 March 2023
The healthcare sector continues to face a significant increase in cybersecurity threats putting patients’ lives and personal data at risk.
21 March 2023
One issue that has been frequently raised in private sector responses to the RFI is the importance of regulatory harmonization of cyber incident reporting timelines issued at different levels of government and by international organizations.
21 March 2023
The discovered packages – which were downloaded 150K times over the past month (before they were removed from the NuGet repository) – contained a “download & execute” type of payload.
21 March 2023
Because security has been prioritized over UX for so long, it was very often added without properly accounting for the impact of security measures on UX. You can’t fix what you can’t measure, see and experience.
21 March 2023
Poorly managed Linux SSH servers are being targeted as part of a new campaign that deploys different variants of malware called ShellBot.
"ShellBot, also known as PerlBot, is a DDoS Bot malware developed in Perl and characteristically uses IRC protocol to communicate with the C&C server," AhnLab Security Emergency response Center (ASEC) said in a report.
ShellBot is installed on servers that
21 March 2023
“Upon receipt of the ransom demand, we immediately started an investigation in collaboration with a leading global third-party cybersecurity firm,” the Italian car maker said.
21 March 2023
H0lyGh0st, Magecart, and a slew of state-sponsored hacker groups are diversifying their tactics and shifting their focus to…
You.
That is, if you're in charge of cybersecurity for a small-to-midsize enterprise (SME).
Why? Bad actors know that SMEs typically have a smaller security budget, less infosec manpower, and possibly weak or missing security controls to protect their data and
21 March 2023
Mandiant researchers tracked 55 zero-day vulnerabilities that they judge were exploited in 2022. Although this count is lower than the record-breaking 81 zero-days exploited in 2021, it still represents almost triple the number from 2020.
21 March 2023
The new keys allow the creation of policies that can limit the use of role credentials to only the location from where they originated, reducing the risk of credential exfiltration.
21 March 2023
Threat groups behind Killnet and Black Basta ransomware are targeting the healthcare sector and other critical infrastructure industries in force, according to Microsoft and the HHS Cybersecurity Coordination Center (HC3).
21 March 2023
As many as 55 zero-day vulnerabilities were exploited in the wild in 2022, with most of the flaws discovered in software from Microsoft, Google, and Apple.
While this figure represents a decrease from the year before, when a staggering 81 zero-days were weaponized, it still represents a significant uptick in recent years of threat actors leveraging unknown security flaws to their advantage.
The
21 March 2023
The Financial Services Information Sharing and Analysis Center (FS-ISAC) said Google Cloud joined its critical providers program, as part of a larger industry effort to bolster supply chain security in the financial services sector.
21 March 2023
On Monday, Google announced that it had flagged several apps made by a Chinese e-commerce giant as malware, alerting users who had them installed, and suspended the company’s official app.
21 March 2023
As business and the world in general grow more complex, the shared responsibility between cloud customers and cloud providers becomes, well, cloudier. This is especially true when it comes to security and compliance.
21 March 2023
CISA initiated the RVWP by notifying 93 organizations identified as running instances of Microsoft Exchange Service with a vulnerability called "ProxyNotShell," widely exploited by ransomware actors.
21 March 2023
Dish Network stated it reinstated the ability of customers of its Boost Mobile brand to access account information as it provided an update on its bid to recover from a cyberattack in February.
21 March 2023
Last month, the Australian government announced plans to fight SMS-based scams by implementing an SMS sender ID registry. Under this system, organizations that want to SMS customers will first have to register their sender ID with a government body.
21 March 2023
Bitcoin ATM maker General Bytes disclosed that unidentified threat actors stole cryptocurrency from hot wallets by exploiting a zero-day security flaw in its software.
"The attacker was able to upload his own java application remotely via the master service interface used by terminals to upload videos and run it using 'batm' user privileges," the company said in an advisory published over the
21 March 2023
ReliaQuest studied a security breach incident by Black Basta ransomware wherein criminals gained entry into the network, and rapidly escalated their privileges, with the use of QBot. The attackers executed the malware via HTML Smuggling, an attack strategy QBot has been observed implementing previously in December 2022.
20 March 2023
New online tools for small organisations to help find and fix any cyber security issues.