Latest Cybersecurity News and Articles
17 March 2023
To protect themselves from significant losses, cybercriminals use regulatory mechanisms, such as escrow services (aka middlemen, intermediaries, or guarantors), and arbitration.
17 March 2023
The top three ransomware gangs linked to attacks targeting critical infrastructure last year, based on the number of attacks, were Lockbit (149), ALPHV/BlackCat (114), and Hive (87).
17 March 2023
A new hacker group, named YoroTrooper, was found targeting European nations and organizations in a cyberespionage campaign that started in June 2022. The attack begins with phishing emails with malicious shortcut files (LNK), along with legitimate PDF documents related to national development strategy, used as decoys.
17 March 2023
The advanced persistent threat known as Winter Vivern has been linked to campaigns targeting government officials in India, Lithuania, Slovakia, and the Vatican since 2021.
The activity targeted Polish government agencies, the Ukraine Ministry of Foreign Affairs, the Italy Ministry of Foreign Affairs, and individuals within the Indian government, SentinelOne said in a report shared with The
17 March 2023
Google is calling attention to a set of severe security flaws in Samsung's Exynos chips, some of which could be exploited remotely to completely compromise a phone without requiring any user interaction.
The 18 zero-day vulnerabilities affect a wide range of Android smartphones from Samsung, Vivo, Google, wearables using the Exynos W920 chipset, and vehicles equipped with the Exynos Auto T5123
16 March 2023

The US says the extremely popular video-sharing app ‘screams’ of national security concerns and considers a countrywide banTikTok is once again fending off claims that its Chinese parent company, ByteDance, would share user data from its popular video-sharing app with the Chinese government, or push propaganda and misinformation on its behalf.China’s foreign ministry on Wednesday accused the US itself of spreading disinformation about TikTok’s potential security risks following a report in the Wall Street Journal that the committee on foreign investment in the US – part of the treasury department – was threatening a US ban on the app unless its Chinese owners divest their stake. Continue reading...
16 March 2023
Check Point Research laid bare tech details of the dotRunpeX injector that delivers a range of known malware families such as AgentTesla,AsyncRat, AveMaria/WarzoneRAT, BitRAT, Formbook, and more. The first-stage loaders are primarily delivered via phishing emails that contain malicious attachments in the form of .iso, .img, .zip, or .7z files.
16 March 2023
CloudSEK witnessed a 200-300% month-on-month surge in AI-generated YouTube videos about software cracks containing malicious links to a variety of stealer malware such as Raccoon, RedLine, and Vidar. To make the videos appear at the top of the results, threat actors employ SEO poisoning techniques.
16 March 2023

Letter argues that Chinese-owned video-sharing app could be in breach of UK lawA cross-party group of MPs and peers have asked the information commissioner to investigate whether the Chinese-owned TikTok’s handling of personal information is in breach of UK law.The letter from the Inter-Parliamentary Alliance on China (IPAC) argues that TikTok cannot be compliant with data protection rules – and comes just hours after the UK announced a ban on the popular video-sharing app appearing on ministers’ and officials’ government-owned phones. Continue reading...
16 March 2023
Cybersecurity researcher Luca Mella shared technical insights on the Makop ransomware that attains persistence through dedicated .NET tools. To access victim networks, the gang makes use of internet-facing bugs and exposed remote administrative services. The operators began to work for their criminal enterprise in 2020 using a variant of the Phobos ransomware.
16 March 2023
Ontinue, the managed detection and response division of Open Systems, announced Gareth Lindahl-Wise as its new Chief Information Security Officer.
16 March 2023
Mozilla announced this week the release of Firefox 111, which patches over a dozen vulnerabilities, including potentially serious issues. Of the 13 CVEs, seven have been assigned a ‘high’ severity rating.
16 March 2023
With a focus on working toward closing the gender gap in cybersecurity, CISA and Girl Scouts of the USA formalize collaboration efforts.
16 March 2023
The importance of attribution depends on the organization involved and whether it can see an investigation through. With investigations taking lots of time and resources, it shouldn’t be an organization’s priority in the event of a breach.
16 March 2023
The two hackers, belonging to the "ViLE" crime group, allegedly broke into a federal law enforcement database. They also used a compromised Bangladeshi police officer's email to fraudulently request user data from a social media company.
16 March 2023
A study by Hoxhunt sampling 53,000 email users in more than 100 countries found that professional red teamers generated a click rate of 4.2%, while ChatGPT-generated emails induced just a 2.9% click rate.
16 March 2023
According to the alert, both the unnamed nation-backed hacking group and the criminal group dubbed XE Group exploited known vulnerabilities in Progress Telerik software located in the unnamed government agency’s Microsoft IIS web server.
16 March 2023
By virtue of Chrome's market share, if Google makes this change for Chrome, that makes it a de facto standard that every commercial public certificate authority would have to follow.
16 March 2023

Move is latest escalation by lawmakers over fears user data could be passed on to China’s governmentThe Biden administration has threatened to ban TikTok in the US unless the social media company’s Chinese owners divest their stakes in it, according to news reports on Wednesday.The move, first reported by the Wall Street Journal, is the most dramatic in a series of escalations by US officials and legislators, driven by fears that US user data held by the company could be passed on to China’s government. It also comes amid a global backlash to the popular video-based app over concerns about the potential for Chinese spying, with countries including the UK, Canada and Australia recently moving to ban the app from government phones. Continue reading...
16 March 2023
Threat activity clusters affiliated with the Chinese and Russian cybercriminal ecosystems have been observed using a new piece of malware that's designed to load Cobalt Strike onto infected machines.
Dubbed SILKLOADER by Finnish cybersecurity company WithSecure, the malware leverages DLL side-loading techniques to deliver commercial adversary simulation software.
The development comes as