Latest Cybersecurity News and Articles


Key Aerospace Player Safran Group Leaks Sensitive Data

15 March 2023
The Cybernews research team recently discovered that the French-based multinational aviation company, the eighth largest aerospace supplier worldwide, was leaking sensitive data due to a misconfiguration of its systems.

Criminals already targeting nervous CVB customers

15 March 2023
According to various researchers and security firms, threat actors are already out hunting for SVB-exposed prey through both passive and active phishing scams, including similar fake domains and business email compromise (BEC) attacks.

Microsoft Patch Tuesday, March 2023 Edition

15 March 2023
Microsoft on Tuesday released updates to quash at least 74 security bugs in its Windows operating systems and software. Two of those flaws are already being actively attacked, including an especially severe weakness in Microsoft Outlook that can be exploited without any user interaction.

ISO27001 Updates: Change is afoot

15 March 2023
The standard hasn't had a significant update since 2013. There were some minor amendments in 2017, but largely these were structural or grammatical updates. In 2022, things have changed dramatically, but also in very subtle ways.

Ring Denies Falling Victim to Ransomware Attack

15 March 2023
On Monday, the cybergang behind the Alphv ransomware added an entry to their leaks site claiming they breached Ring and threatening to release data supposedly stolen from the company.

Rishi Sunak hints at TikTok ban from UK government devices

15 March 2023
Rishi Sunak has indicated that the UK could follow the US and Canada in banning TikTok from government devices, saying he will take “whatever steps are necessary” to protect Britain’s security.

UK expected to ban TikTok from government mobile phones

15 March 2023
UK expected to ban TikTok from government mobile phones Ban on Chinese owned video-sharing app marks U-turn from previous relaxed position Britain is expected to announce a ban on the Chinese owned video-sharing app TikTok on government mobile phones imminently, bringing the UK inline with the US and European Commission and reflecting deteriorating relations with Beijing.The decision marks a sharp reverse from the UK’s previously relaxed position, but some critics and experts said Britain should also extend the ban to cover personal phones used by ministers and officials – and even consider a complete ban. Continue reading...

YoroTrooper Stealing Credentials and Information from Government and Energy Organizations

15 March 2023
A previously undocumented threat actor dubbed YoroTrooper has been targeting government, energy, and international organizations across Europe as part of a cyber espionage campaign that has been active since at least June 2022. "Information stolen from successful compromises include credentials from multiple applications, browser histories and cookies, system information and screenshots," Cisco

New Cryptojacking Operation Targeting Kubernetes Clusters for Dero Mining

15 March 2023
The development marks a notable shift from Monero, which is a prevalent cryptocurrency used in such campaigns. It's suspected it may have to do with the fact that Dero "offers larger rewards and provides the same or better anonymizing features."

Greg Day hired as Cybereason VP and CISO

15 March 2023
Greg Day has been hired by Cybereason as the Vice President and Global Field Chief Information Security Officer (CISO) for the EMEA region.

Cyber-Attacks in the Media Industry Making Headlines

15 March 2023
The media industry is more visible to the public than virtually any other sector. Correspondingly, cyberattacks on media entities, even those that have a relatively minor impact or are unsuccessful, are highly visible to the public.

YoroTrooper Espionage Campaigns Targeting CIS Countries, Embassies, and EU Healthcare Agency

15 March 2023
YoroTrooper’s main tools include Python-based, custom-built, and open-source information stealers, such as the Stink stealer wrapped into executables via the Nuitka framework and PyInstaller.

57% of financial firms at risk of data breach due to mismanaged data

15 March 2023
Research reveals 57% U.K. financial services sector senior executives say their organization is at risk of a data breach because data is mismanaged.

Kali Linux 2023.1 released – and so is Kali Purple!

15 March 2023
OffSec (formerly Offensive Security) released Kali Linux 2023.1, the latest version of its popular penetration testing and digital forensics platform, accompanied by a technical preview of Kali Purple, a “one-stop shop for blue and purple teams.”

UK’s Largest State Boarding School Announces ‘Sophisticated Cyberattack’

15 March 2023
Wymondham is working with the National Cyber Security Centre (NCSC) “to ensure an appropriate response,” and has notified the Department for Education, said Jonathan Taylor, the chief executive of its parent company, Sapientia Education Trust.

Brand Names in Finance, Telecom, Tech Lead Successful Phishing Lures

15 March 2023
According to an analysis by Cloudflare, credential-seeking cyberattackers garnered the most phishing success by impersonating the brands of telecommunications firms, financial institutions, and popular technology companies in 2022.

Security Firm Rubrik Says Hackers Used Fortra GoAnywhere Zero-Day to Steal Internal Data

15 March 2023
Silicon Valley–based data security company Rubrik has come forward as the latest victim of the Fortra GoAnywhere zero-day vulnerability, which has been linked to hacks targeting a hospital chain and a bank.

Ransomware gang exploits now-patched Windows vulnerability

15 March 2023
Criminals are exploiting a Microsoft SmartScreen bug to deliver Magniber ransomware, potentially infecting hundreds of thousands of devices, without raising any security red flags, according to Google's Threat Analysis Group (TAG).

Organizations need to re-examine their approach to BEC protection

15 March 2023
According to a report by IRONSCALES and Osterman Research, 93% of organizations experienced one or more of the BEC attack variants in the previous 12 months, with 62% facing three or more attack variants.

Microsoft fixes Outlook zero-day used by Russian hackers since April 2022

15 March 2023
The vulnerability (CVE-2023-23397) was reported by CERT-UA, and it's a critical Outlook elevation of privilege security flaw exploitable without user interaction in low-complexity attacks.