Latest Cybersecurity News and Articles
17 March 2023
Copycat websites for instant messaging apps like Telegram and WhatApp are being used to distribute trojanized versions and infect Android and Windows users with cryptocurrency clipper malware.
"All of them are after victims' cryptocurrency funds, with several targeting cryptocurrency wallets," ESET researchers Lukáš Štefanko and Peter Strýček said in a new analysis.
While the first instance of
17 March 2023
Kaspersky researchers analyzed a cache of 258 private keys released by threat actors on a hacking forum. They found them to be associated with a Conti variant they discovered in December 2022. However, it had been circulating since at least August.
17 March 2023
The judgment by the Amsterdam District Court said Facebook Ireland, custodians of Dutch users’ personal details, not only used the data for advertising but also passed it to third parties without properly informing people or the right legal grounds.
17 March 2023
What makes this scam stand out is it preys on customers tweeting to their banks—such as to raise a complaint or request assistance. But these customers instead receive a reply from the scammer, via a quote-tweet, luring them to call a fake helpline.
17 March 2023
Understanding the ongoing changes to data privacy regulations is challenging enough for CISOs and their teams. Implementing the needed changes as they occur only adds complexity and confusion.
17 March 2023
To protect themselves from significant losses, cybercriminals use regulatory mechanisms, such as escrow services (aka middlemen, intermediaries, or guarantors), and arbitration.
17 March 2023
The top three ransomware gangs linked to attacks targeting critical infrastructure last year, based on the number of attacks, were Lockbit (149), ALPHV/BlackCat (114), and Hive (87).
17 March 2023
A new hacker group, named YoroTrooper, was found targeting European nations and organizations in a cyberespionage campaign that started in June 2022. The attack begins with phishing emails with malicious shortcut files (LNK), along with legitimate PDF documents related to national development strategy, used as decoys.
17 March 2023
The advanced persistent threat known as Winter Vivern has been linked to campaigns targeting government officials in India, Lithuania, Slovakia, and the Vatican since 2021.
The activity targeted Polish government agencies, the Ukraine Ministry of Foreign Affairs, the Italy Ministry of Foreign Affairs, and individuals within the Indian government, SentinelOne said in a report shared with The
17 March 2023
Google is calling attention to a set of severe security flaws in Samsung's Exynos chips, some of which could be exploited remotely to completely compromise a phone without requiring any user interaction.
The 18 zero-day vulnerabilities affect a wide range of Android smartphones from Samsung, Vivo, Google, wearables using the Exynos W920 chipset, and vehicles equipped with the Exynos Auto T5123
16 March 2023

The US says the extremely popular video-sharing app ‘screams’ of national security concerns and considers a countrywide banTikTok is once again fending off claims that its Chinese parent company, ByteDance, would share user data from its popular video-sharing app with the Chinese government, or push propaganda and misinformation on its behalf.China’s foreign ministry on Wednesday accused the US itself of spreading disinformation about TikTok’s potential security risks following a report in the Wall Street Journal that the committee on foreign investment in the US – part of the treasury department – was threatening a US ban on the app unless its Chinese owners divest their stake. Continue reading...
16 March 2023
Check Point Research laid bare tech details of the dotRunpeX injector that delivers a range of known malware families such as AgentTesla,AsyncRat, AveMaria/WarzoneRAT, BitRAT, Formbook, and more. The first-stage loaders are primarily delivered via phishing emails that contain malicious attachments in the form of .iso, .img, .zip, or .7z files.
16 March 2023
CloudSEK witnessed a 200-300% month-on-month surge in AI-generated YouTube videos about software cracks containing malicious links to a variety of stealer malware such as Raccoon, RedLine, and Vidar. To make the videos appear at the top of the results, threat actors employ SEO poisoning techniques.
16 March 2023

Letter argues that Chinese-owned video-sharing app could be in breach of UK lawA cross-party group of MPs and peers have asked the information commissioner to investigate whether the Chinese-owned TikTok’s handling of personal information is in breach of UK law.The letter from the Inter-Parliamentary Alliance on China (IPAC) argues that TikTok cannot be compliant with data protection rules – and comes just hours after the UK announced a ban on the popular video-sharing app appearing on ministers’ and officials’ government-owned phones. Continue reading...
16 March 2023
Cybersecurity researcher Luca Mella shared technical insights on the Makop ransomware that attains persistence through dedicated .NET tools. To access victim networks, the gang makes use of internet-facing bugs and exposed remote administrative services. The operators began to work for their criminal enterprise in 2020 using a variant of the Phobos ransomware.
16 March 2023
Ontinue, the managed detection and response division of Open Systems, announced Gareth Lindahl-Wise as its new Chief Information Security Officer.
16 March 2023
Mozilla announced this week the release of Firefox 111, which patches over a dozen vulnerabilities, including potentially serious issues. Of the 13 CVEs, seven have been assigned a ‘high’ severity rating.
16 March 2023
With a focus on working toward closing the gender gap in cybersecurity, CISA and Girl Scouts of the USA formalize collaboration efforts.
16 March 2023
The importance of attribution depends on the organization involved and whether it can see an investigation through. With investigations taking lots of time and resources, it shouldn’t be an organization’s priority in the event of a breach.
16 March 2023
The two hackers, belonging to the "ViLE" crime group, allegedly broke into a federal law enforcement database. They also used a compromised Bangladeshi police officer's email to fraudulently request user data from a social media company.