Latest Cybersecurity News and Articles


When Partial Protection is Zero Protection: The MFA Blind Spots No One Talks About

10 March 2023
Multi-factor Authentication (MFA) has long ago become a standard security practice. With a wide consensus on its ability to fend off more than 99% percent of account takeover attacks, it's no wonder why security architects regard it as a must-have in their environments. However, what seems to be less known are the inherent coverage limitations of traditional MFA solutions. While compatible with

Yoti Receives £10M Investment from Lloyds Banking Group

10 March 2023
The UK-based digital identity company, led by CEO Robin Tombs, intends to use the funds to develop its technology that protects customers’ identities and personal data online.

Known Threat Now Targeting Linux Enterprise Networks Across Media and Entertainment Sector

10 March 2023
In recent weeks, SentinelLabs observed novel Linux versions of IceFire ransomware being deployed within the enterprise network intrusions of several media and entertainment sector organizations worldwide.

AT&T Alerts 9 Million Customers of Data Breach After Vendor Hack

10 March 2023
"Customer Proprietary Network Information from some wireless accounts was exposed, such as the number of lines on an account or wireless rate plan," AT&T told BleepingComputer.

Vendor Faces Lawsuit in Wake of an Apparent 'Royal' Attack

10 March 2023
A healthcare revenue cycle management software vendor is facing a proposed class action lawsuit in the aftermath of a December 2022 data exfiltration attack affecting nearly 251,000 patients.

Update: CHS to Notify One Million in Breach Linked to Software Flaw

10 March 2023
CHS has been working "diligently" to determine an accurate number of individuals affected by the Fortra Incident, both overall and for the state of Maine, the report to the attorney general says.

FBI and international cops catch a NetWire RAT

10 March 2023
"By removing the NetWire RAT, the FBI has impacted the criminal cyber ecosystem," Donald Alway, the assistant director in charge of the FBI's Los Angeles field office, declared in a statement.

Canadian military says ransomware attack on contractor didn’t touch defense systems

10 March 2023
Black & McDonald did not respond to repeated requests for comment, but a spokesperson for Canada’s Department of National Defence told The Record that it was aware of a ransomware attack on the company.

Xenomorph Android Banking Trojan Returns with a New and More Powerful Variant

10 March 2023
A new variant of the Android banking trojan named Xenomorph has surfaced in the wild, the latest findings from ThreatFabric reveal. Named "Xenomorph 3rd generation" by the Hadoken Security Group, the threat actor behind the operation, the updated version comes with new features that allow it to perform financial fraud in a seamless manner. "This new version of the malware adds many new

Vulnerability Exposes Cisco Enterprise Routers to Disruptive Attacks

10 March 2023
Tracked as CVE-2023-20049 (CVSS score of 8.6), the vulnerability impacts the bidirectional forwarding detection (BFD) hardware offload feature for the platform and can be exploited remotely, without authentication.

Data protection vendor Acronis admits to data leak

10 March 2023
The CISO of Swiss cybersecurity firm Acronis has acknowledged a breach of the company’s systems but stated the incident only impacted a single customer and that all other data remains safe.

Dozens of Exploited Vulnerabilities Missing From CISA ‘Must Patch’ List

10 March 2023
Of the vulnerabilities that VulnCheck believes have been exploited in attacks but have not been added to CISA’s KEV catalog, 64% are related to botnets, followed by threat actors (12%) and ransomware (10%) — the rest are unattributed.

Virginia city claimed to be attacked by BianLian ransomware

10 March 2023
BianLian noted in a post on its data leak site that it was able to exfiltrate 350GB worth of data from Waynesboro's network, including file server data and public relations documents, as well as internal police station file server files.

North Korean UNC2970 Hackers Expands Operations with New Malware Families

10 March 2023
A North Korean espionage group tracked as UNC2970 has been observed employing previously undocumented malware families as part of a spear-phishing campaign targeting U.S. and European media and technology organizations since June 2022. Google-owned Mandiant said the threat cluster shares "multiple overlaps" with a long-running operation dubbed "Dream Job" that employs job recruitment lures in

OneNote Used as New Distribution Channel for Qakbot Malware

09 March 2023
Researchers observed a notable spike in emails utilizing malicious OneNote attachments, especially to drop Qakbot or QBot. Operators have apparently reorganized its infrastructure to target specific regions and industries.

Who’s Behind the NetWire Remote Access Trojan?

09 March 2023
A Croatian national has been arrested for allegedly operating NetWire, a Remote Access Trojan (RAT) marketed on cybercrime forums since 2012 as a stealthy way to spy on infected systems and siphon passwords. The arrest coincided with a seizure of the NetWire sales website by the U.S. Federal Bureau of Investigation (FBI). While the defendant in this case hasn’t yet been named publicly, the NetWire website has been leaking information about the likely true identity and location of its owner for the past 11 years.

EPA stresses the need for improved water cybersecurity

09 March 2023
The EPA is stressing the need to improve the cybersecurity of drinking water systems to better defend critical infrastructure from cyberattacks.

Beware! AI Generates a Truly Polymorphic Malware BlackMamba

09 March 2023
A BlackMamba proof-of-concept attack was demonstrated by researchers. The technology on which ChatGPT is built, the large language model (LLM), was used to create a polymorphic keylogger functionality on the fly. The malware was tested against a renowned EDR system and resulted in absolutely no alerts or detections.

Iran-linked hackers used fake Atlantic Council-affiliated persona to target human rights researchers

09 March 2023
It’s not clear if this particular persona’s efforts resulted in any successful phishing attacks. The Twitter account, created in October 2022, remains active. An Instagram account associated with the name is unavailable.

Researchers Uncover Email Threats From Exotic Lily

09 March 2023
Exotic Lily is an initial access broker who specializes in gathering credentials from high-value targets through employee impersonation, deep open-source intelligence (OSINT), and by creating convincing malicious documents.