Latest Cybersecurity News and Articles


BEC Volumes Double on Phishing Surge

17 March 2023
The number of business email compromise (BEC) incidents doubled last year and replaced ransomware as the most prolific cybercrime category, according to Secureworks. Ransomware detections reportedly declined by 57%.

BianLian Ransomware Gang Evolves to Purely Focus on Data Extortion

17 March 2023
The most notable shift observed in BianLian attacks recently is its move away from ransoming encrypted files, and towards data-leak extortion as a means to extract payments from victims.

What is Reverse Tabnabbing and What Can You Do to Stop It?

17 March 2023
Tabnabbing is a phishing method in which attackers take advantage of victims’ unattended browser tabs. With reverse tabnabbing, on the other hand, attackers can actually rewrite the source page after a victim clicks a malicious link.

Cryptocurrency Exchange Fiatusdt Exposed Sensitive Customer KYC Records, Wallet Addresses Online

17 March 2023
The exposed database contained users' sensitive information, including screenshots of "Chat Messages" showing deposits and withdrawal amounts, KYC compliance records, identification images, transaction hashes, and wallet addresses.

Why Security Practitioners Should Understand Their Business

17 March 2023
The sooner security practitioners become proactive in understanding the business side of their organizations, and the industry overall, the better they will be able to do their jobs and build the innovations that change the industry for the better.

Chinese and Russian Hackers Using SILKLOADER Malware to Evade Detection

17 March 2023
SILKLOADER joins other loaders such as KoboldLoader, MagnetLoader, and LithiumLoader that have been recently discovered incorporating Cobalt Strike components. It also shares overlaps with LithiumLoader in that both employ the DLL sideloading method.

THN Webinar: 3 Research-Backed Ways to Secure Your Identity Perimeter

17 March 2023
Think of the typical portrayal of a cyberattack. Bad guy pounding furiously on a keyboard, his eyes peeking out from under a dark hoodie. At long last, his efforts pay off and he hits the right combination of keys. "I'm in!" he shouts in triumph. Clearly, there are many problems with this scenario – and it's not just the hoodie. What's even more inaccurate is that most cyber attackers today do

New GoLang-Based HinataBot Exploiting Router and Server Flaws for DDoS Attacks

17 March 2023
A new Golang-based botnet dubbed HinataBot has been observed to leverage known flaws to compromise routers and servers and use them to stage distributed denial-of-service (DDoS) attacks. "The malware binaries appear to have been named by the malware author after a character from the popular anime series, Naruto, with file name structures such as 'Hinata--,'" Akamai said in a

UK Joins US, Canada, Others in Banning TikTok From Government Devices

17 March 2023
The Chancellor of the Duchy of Lancaster, Oliver Dowden, confirmed the plans to ban TikTok earlier today after Cabinet Office Ministers ordered a security review of the app.

The First-ever Cryptojacking Campaign with Dero Cryptocurrency

17 March 2023
Attackers mining digital assets via others’ infrastructure seem to have found a new boost with Dero cryptocurrency, revealed Crowdstrike. Since February, the operation has reportedly launched attacks against the Kubernetes environment of three U.S.-based servers. Threat actors potentially deployed over 4,000 miner instances during this campaign.

Researchers Uncover Winter Vivern APT's Wave of Global Espionage

17 March 2023
Recently linked campaigns reveal that Winter Vivern has targeted Polish government agencies, the Ukraine Ministry of Foreign Affairs, the Italy Ministry of Foreign Affairs, and individuals within the Indian government.

MKS Instruments hit by class-action litigation following ransomware attack

17 March 2023
MKS Instruments is facing a class action lawsuit in California in connection with a February ransomware attack that forced the company to suspend part of its manufacturing capacity, according to the company’s annual 10-K filing with the SEC.

A New Security Category Addresses Web-borne Threats

17 March 2023
In the modern corporate IT environment, which relies on cloud connectivity, global connections and large volumes of data, the browser is now the most important work interface. The browser connects employees to managed resources, devices to the web, and the on-prem environment to the cloud one. Yet, and probably unsurprisingly, this browser prominence has significantly increased the number of

Baseband RCE flaws in Samsung’s Exynos chipsets expose devices to remote hack

17 March 2023
Researchers at Google’s Project Zero discovered a total of eighteen vulnerabilities. The four most severe of these (CVE-2023-24033 and three other vulnerabilities that have yet to be assigned CVE-IDs) allowed for an Internet-to-baseband RCE attack.

CISA Seeks Public Opinion on Cloud Application Security Guidance

17 March 2023
Titled Secure Cloud Business Applications (SCuBA) Hybrid Identity Solutions Architecture, the document is meant to help federal agencies securely integrate cloud-based solutions with existing on-premises infrastructure.

Lookalike Telegram and WhatsApp Websites Distributing Cryptocurrency Stealing Malware

17 March 2023
Copycat websites for instant messaging apps like Telegram and WhatApp are being used to distribute trojanized versions and infect Android and Windows users with cryptocurrency clipper malware. "All of them are after victims' cryptocurrency funds, with several targeting cryptocurrency wallets," ESET researchers Lukáš Štefanko and Peter Strýček said in a new analysis. While the first instance of

Conti-based ransomware ‘MeowCorp’ gets free decryptor

17 March 2023
Kaspersky researchers analyzed a cache of 258 private keys released by threat actors on a hacking forum. They found them to be associated with a Conti variant they discovered in December 2022. However, it had been circulating since at least August.

Facebook ‘Unlawfully’ Used Dutch Personal Data: Court

17 March 2023
The judgment by the Amsterdam District Court said Facebook Ireland, custodians of Dutch users’ personal details, not only used the data for advertising but also passed it to third parties without properly informing people or the right legal grounds.

Convincing Twitter 'quote tweet' phone scam targets bank customers

17 March 2023
What makes this scam stand out is it preys on customers tweeting to their banks—such as to raise a complaint or request assistance. But these customers instead receive a reply from the scammer, via a quote-tweet, luring them to call a fake helpline.

Meet Data Privacy Mandates With Cybersecurity Frameworks

17 March 2023
Understanding the ongoing changes to data privacy regulations is challenging enough for CISOs and their teams. Implementing the needed changes as they occur only adds complexity and confusion.