Latest Cybersecurity News and Articles


FakeCalls Impersonates Leading Financial Institutions, Targets South Korea

20 March 2023
Check Point Research found FakeCalls, a new Android vishing malware tool, targeting victims in South Korea by impersonating 20 leading financial institutions in the region. It lures victims with a fake loan form that would request users’ personal details and banking details including credit card numbers. To stay protected, experts suggest downloading apps only from official and reliable sources.

Lowe’s Market Exposes Sensitive Data and Credentials via Publicly Accessible Environment File

20 March 2023
Researchers found a publicly accessible environment file (.env) hosted on the Lowe’s Market website. Public access to the file posed a risk to the security of the company’s systems, as it was leaking sensitive data and numerous credentials.

BianLian Ransomware Evolves into Pure Data Exfiltration-Focused Group

20 March 2023
Changing its ransom tactics, the BianLian ransomware group appears to have decided not to encrypt its victims' files, rather only extract data and demand a ransom against that. The ransomware operation surfaced in the wild in July 2022. The ransomware operators, in some of the cases, also referenced the subsections of several laws and statutes that a victim firm can face if its breach news goes public.

Update: Hackers post more stolen Minneapolis Public School data to dark web

20 March 2023
The data dumped online included payroll information, protected health information, home addresses, phone numbers, disciplinary records, student records, pictures, safety plans, union grievances, misconduct complaints, and civil rights investigations.

SEC proposes new cyber rules to secure financial sector

20 March 2023
The new proposed regulations would require broker-dealers to notify customers within 30 days of a data breach, immediately inform the government, and expand the type of customer information protected by data privacy regulations.

New Cyber Platform Lab 1 Decodes Dark Web Data to Uncover Hidden Supply Chain Breaches

20 March 2023
This article has not been generated by ChatGPT.  2022 was the year when inflation hit world economies, except in one corner of the global marketplace – stolen data. Ransomware payments fell by over 40% in 2022 compared to 2021. More organisations chose not to pay ransom demands, according to findings by blockchain firm Chainalysis. Nonetheless, stolen data has value beyond a price tag, and in

Researchers Shed Light on CatB Ransomware's Evasion Techniques

20 March 2023
The threat actors behind the CatB ransomware operation have been observed using a technique called DLL search order hijacking to evade detection and launch the payload. CatB, also referred to as CatB99 and Baxtoy, emerged late last year and is said to be an "evolution or direct rebrand" of another ransomware strain known as Pandora based on code-level similarities. It's worth noting that the use

Ukraine's cyberpolice arrests RAT developer for infecting 10,000 PCs with malware

20 March 2023
"The 25-year-old offender was exposed by employees of the Khmelnychchyna Cybercrime Department together with the regional police investigative department and the SBU regional department," reads the cyberpolice's announcement.

Wawa to pay up to $28.5M in data breach settlement

20 March 2023
Convenience retailer Wawa has committed to pay up to $28.5 million to settle negligence claims stemming from a data breach that occurred in 2019, according to filings made in the U.S District Court, Eastern District of Pennsylvania.

UK: ICO Reprimands Metropolitan Police for Data Snafu

20 March 2023
The UK’s data protection regulator has reprimanded the country’s largest police service for failing to properly maintain records on organized crime groups (OGCs), resulting in inaccurate information being stored on a key database.

Infamous BreachForums Mastermind 'Pompompurin' Arrested in New York

20 March 2023
According to an affidavit filed by the Federal Bureau of Investigation (FBI), the suspect identified himself as Conor Brian Fitzpatrick and admitted to being the owner of the BreachForums website.

Emotet malware now distributed in Microsoft OneNote files to evade defenses

20 March 2023
While Emotet was one of the most distributed malware in the past, over the past year, it would stop and start in spurts, ultimately taking a break towards the end of 2022.

Telerik Vulnerability Abused by Threat Actors - Warns CISA

20 March 2023
Multiple threat groups were found abusing CVE-2023-26360, a high-severity three-year-old bug, in Progress Telerik to infiltrate an unnamed federal entity in the U.S. The successful exploitation of the bug allowed threat actors to remotely execute arbitrary code on an FCEB agency's Microsoft Internet Information Services (IIS) web server.

New Go-Based HinataBot Abuses Old Vulnerabilities for DDoS Attacks

20 March 2023
HinataBot is the latest in the ever-growing list of emerging Go-based threats abusing old vulnerabilities and weak credentials and could launch massive 3.3 Tbps DDoS attacks. The threat actors behind HinataBot were originally distributing Mirai binaries before they began developing their own botnet in mid-January. Organizations are advised to update the firmware of the affected products. 

Emotet Rises Again: Evades Macro Security via OneNote Attachments

20 March 2023
The notorious Emotet malware, in its return after a short hiatus, is now being distributed via Microsoft OneNote email attachments in an attempt to bypass macro-based security restrictions and compromise systems. Emotet, linked to a threat actor tracked as Gold Crestwood, Mummy Spider, or TA542, continues to be a potent and resilient threat despite attempts by law enforcement to take it down. A 

BBC urges staff to delete TikTok from company mobile phones

19 March 2023
BBC urges staff to delete TikTok from company mobile phones Move comes after UK government bans app on government devices over fears of data being accessed by Chinese stateThe BBC has urged its staff to delete the Chinese-own social media app TikTok from corporate mobile phones.Guidance to BBC staff circulated on Sunday said: “We don’t recommend installing TikTok on a BBC corporate device unless there is a justified business reason. If you do not need TikTok for business reasons, TikTok should be deleted.” Continue reading...

Actively Exploited Microsoft Outlook Vulnerability Imperils Microsoft 365 Apps

18 March 2023
Discovered in or around the beginning of March, the Microsoft Outlook vulnerability was found to affect several applications from the Microsoft 365 Apps Enterprise stack, including MS Office 2019, 2016, 2013, and LTSC.

QBot Laying the Foundations for Black Basta Ransomware Activity

18 March 2023
The attacker’s actions had the whiff of a Black Basta affiliate, with Qbot activity widely reported as being a cornerstone of Black Basta intrusions. Black Basta is a splinter group that emerged after the “Conti” ransomware syndicate was quelled.

Hitachi Energy breached by Clop gang through GoAnywhere Zero-Day exploitation

18 March 2023
Hitachi Energy immediately launched an investigation into the incident and disconnected the compromised system. The company reported the data breach to law enforcement agencies and data protection watchdog.

Chinese Hackers Exploit Fortinet Zero-Day Flaw for Cyber Espionage Attack

18 March 2023
The zero-day exploitation of a now-patched medium-security flaw in the Fortinet FortiOS operating system has been linked to a suspected Chinese hacking group. Threat intelligence firm Mandiant, which made the attribution, said the activity cluster is part of a broader campaign designed to deploy backdoors onto Fortinet and VMware solutions and maintain persistent access to victim environments.