Latest Cybersecurity News and Articles


UK expected to ban TikTok from government mobile phones

15 March 2023
UK expected to ban TikTok from government mobile phones Ban on Chinese owned video-sharing app marks U-turn from previous relaxed position Britain is expected to announce a ban on the Chinese owned video-sharing app TikTok on government mobile phones imminently, bringing the UK inline with the US and European Commission and reflecting deteriorating relations with Beijing.The decision marks a sharp reverse from the UK’s previously relaxed position, but some critics and experts said Britain should also extend the ban to cover personal phones used by ministers and officials – and even consider a complete ban. Continue reading...

YoroTrooper Stealing Credentials and Information from Government and Energy Organizations

15 March 2023
A previously undocumented threat actor dubbed YoroTrooper has been targeting government, energy, and international organizations across Europe as part of a cyber espionage campaign that has been active since at least June 2022. "Information stolen from successful compromises include credentials from multiple applications, browser histories and cookies, system information and screenshots," Cisco

New Cryptojacking Operation Targeting Kubernetes Clusters for Dero Mining

15 March 2023
The development marks a notable shift from Monero, which is a prevalent cryptocurrency used in such campaigns. It's suspected it may have to do with the fact that Dero "offers larger rewards and provides the same or better anonymizing features."

Greg Day hired as Cybereason VP and CISO

15 March 2023
Greg Day has been hired by Cybereason as the Vice President and Global Field Chief Information Security Officer (CISO) for the EMEA region.

Cyber-Attacks in the Media Industry Making Headlines

15 March 2023
The media industry is more visible to the public than virtually any other sector. Correspondingly, cyberattacks on media entities, even those that have a relatively minor impact or are unsuccessful, are highly visible to the public.

YoroTrooper Espionage Campaigns Targeting CIS Countries, Embassies, and EU Healthcare Agency

15 March 2023
YoroTrooper’s main tools include Python-based, custom-built, and open-source information stealers, such as the Stink stealer wrapped into executables via the Nuitka framework and PyInstaller.

57% of financial firms at risk of data breach due to mismanaged data

15 March 2023
Research reveals 57% U.K. financial services sector senior executives say their organization is at risk of a data breach because data is mismanaged.

Kali Linux 2023.1 released – and so is Kali Purple!

15 March 2023
OffSec (formerly Offensive Security) released Kali Linux 2023.1, the latest version of its popular penetration testing and digital forensics platform, accompanied by a technical preview of Kali Purple, a “one-stop shop for blue and purple teams.”

UK’s Largest State Boarding School Announces ‘Sophisticated Cyberattack’

15 March 2023
Wymondham is working with the National Cyber Security Centre (NCSC) “to ensure an appropriate response,” and has notified the Department for Education, said Jonathan Taylor, the chief executive of its parent company, Sapientia Education Trust.

Brand Names in Finance, Telecom, Tech Lead Successful Phishing Lures

15 March 2023
According to an analysis by Cloudflare, credential-seeking cyberattackers garnered the most phishing success by impersonating the brands of telecommunications firms, financial institutions, and popular technology companies in 2022.

Security Firm Rubrik Says Hackers Used Fortra GoAnywhere Zero-Day to Steal Internal Data

15 March 2023
Silicon Valley–based data security company Rubrik has come forward as the latest victim of the Fortra GoAnywhere zero-day vulnerability, which has been linked to hacks targeting a hospital chain and a bank.

Ransomware gang exploits now-patched Windows vulnerability

15 March 2023
Criminals are exploiting a Microsoft SmartScreen bug to deliver Magniber ransomware, potentially infecting hundreds of thousands of devices, without raising any security red flags, according to Google's Threat Analysis Group (TAG).

Organizations need to re-examine their approach to BEC protection

15 March 2023
According to a report by IRONSCALES and Osterman Research, 93% of organizations experienced one or more of the BEC attack variants in the previous 12 months, with 62% facing three or more attack variants.

Microsoft fixes Outlook zero-day used by Russian hackers since April 2022

15 March 2023
The vulnerability (CVE-2023-23397) was reported by CERT-UA, and it's a critical Outlook elevation of privilege security flaw exploitable without user interaction in low-complexity attacks.

PlugX Exploits Flaws in Remote Control Software

15 March 2023
Researchers from AhnLab have observed some unidentified threat actors use PlugX to exploit well-known flaws in remote desktop software to get complete control over the infected system. Several other threats, including the Sliver backdoor, Gh0st RAT, and XMRig coinminer, have abused the bugs in previous attacks. To prevent such threats, organizations are suggested to regularly review and update their security posture, and keep all the software updated.

New Cryptojacking Operation Targeting Kubernetes Clusters for Dero Mining

15 March 2023
Cybersecurity researchers have discovered the first-ever illicit cryptocurrency mining campaign used to mint Dero since the start of February 2023. "The novel Dero cryptojacking operation concentrates on locating Kubernetes clusters with anonymous access enabled on a Kubernetes API and listening on non-standard ports accessible from the internet," CrowdStrike said in a new report shared with The

Shift to secure-by-design must start at university level, CISA director says

15 March 2023
The transition to secure-by-design will require a major shift in how technology products are developed, Jen Easterly said, and that will include changes in the code used to develop software.

The Different Methods and Stages of Penetration Testing

15 March 2023
The stakes could not be higher for cyber defenders. With the vast amounts of sensitive information, intellectual property, and financial data at risk, the consequences of a data breach can be devastating. According to a report released by Ponemon institute, the cost of data breaches has reached an all-time high, averaging $4.35 million in 2022. Vulnerabilities in web applications are often the

Microsoft Rolls Out Patches for 80 New Security Flaws — Two Under Active Attack

15 March 2023
Eight of the 80 bugs are rated Critical, 71 are rated Important, and one is rated Moderate in severity. The updates are in addition to 29 flaws the tech giant fixed in its Chromium-based Edge browser in recent weeks.

Tick APT Targeted High-Value Customers of East Asian Data-Loss Prevention Company

15 March 2023
A cyberespionage actor known as Tick has been attributed with high confidence to a compromise of an East Asian data-loss prevention (DLP) company that caters to government and military entities. "The attackers compromised the DLP company's internal update servers to deliver malware inside the software developer's network, and trojanized installers of legitimate tools used by the company, which