Latest Cybersecurity News and Articles
13 March 2023
Researchers have made a significant breakthrough in secure communication by developing an algorithm that conceals sensitive information so effectively that it is impossible to detect anything hidden.
13 March 2023
According to cybersecurity company eSentire, the malicious ads are used to spoof a wide range of legitimate apps and services such as Adobe, OpenAPI's ChatGPT, Spotify, Tableau, and Zoom.
13 March 2023
Passwords are still the weakest link in an organization’s network, as proven by the analysis of over 800 million breached passwords, according to a study by Specops Software.
13 March 2023
A fake ChatGPT-branded Chrome browser extension has been found to come with capabilities to hijack Facebook accounts and create rogue admin accounts, highlighting one of the different methods cyber criminals are using to distribute malware.
"By hijacking high-profile Facebook business accounts, the threat actor creates an elite army of Facebook bots and a malicious paid media apparatus," Guardio
13 March 2023
The National Institute of Standards and Technology (NIST) is one of the standard-bearers in global cybersecurity. The U.S.-based institute’s cybersecurity framework helps organizations of all sizes understand, manage, and reduce their cyber-risk levels and better protect their data. Its importance in the fight against cyberattacks can’t be overstated.
While NIST hasn’t directly developed
13 March 2023
Dark Pink, also called Saaiwc, was first profiled by Group-IB earlier this year, describing its use of custom tools such as TelePowerBot and KamiKakaBot to run arbitrary commands and exfiltrate sensitive information.
13 March 2023
Threat actors have been increasingly observed using AI-generated YouTube Videos to spread a variety of stealer malware such as Raccoon, RedLine, and Vidar.
"The videos lure users by pretending to be tutorials on how to download cracked versions of software such as Photoshop, Premiere Pro, Autodesk 3ds Max, AutoCAD, and other products that are licensed products available only to paid users,"
13 March 2023
Given the increase in virtual and hybrid work, government employees’ increasing reliance on out-of-office technologies presents new challenges when it comes to cyber resilience.
13 March 2023
Researchers at the School of Cyber Security at Korea University, Seoul, have presented a new covert channel attack named CASPER can leak data from air-gapped computers to a nearby smartphone at a rate of 20bits/sec.
13 March 2023
Mandiant reports that since June 2022, the North Korean cyberespionage organization UNC2970 has been focusing on media and tech firms in the United States and Europe. Crims specifically targets security researchers of an enterprise using a job recruitment theme. Organizations are suggested to leverage the available IOCs and deploy actionable and context-rich threat intelligence-sharing solutions to detect and contain such incidents.
13 March 2023
"Last year, 4,518 data breaches were reported," researchers from Flashpoint said in a new report. "Threat actors exposed or stole 22.62 billion credentials and personal records, ranging from account and financial information to emails and SSNs."
13 March 2023
Tracked as CVE-2020-5741, this security flaw allows threat actors with admin privileges to execute arbitrary Python code remotely in low-complexity attacks that don't require user interaction.
13 March 2023
IC3 reported that BEC—in which attackers trick businesses into making bogus payments or intercept legitimate payments—resulted in nearly $2.4 billion worth of losses in 2021 and $2.7 billion in 2022.
13 March 2023
Cerebral has revealed it shared the private health information, including mental health assessments, of more than 3.1 million patients in the United States with advertisers and social media giants like Facebook, Google, and TikTok.
13 March 2023
Mandiant says the particular group has previously targeted tech firms, media groups, and entities in the defense industry. Its latest campaign shows it has evolved its targeting scope and adapted its capabilities.
13 March 2023
The database contained gigabytes of personal information, including email addresses, phone numbers, addresses, details of university achievements and scores, and resumes containing detailed work histories and employment details.
13 March 2023
The organizations impacted by the incident include many entities, such as charities, foundations, non-profits, and universities worldwide, from the U.S., Canada, the U.K., and the Netherlands.
13 March 2023
The Chinese-owned video-sharing app will be temporarily prohibited from devices owned or paid for by Belgium's federal government for at least six months, according to a post on Alexander de Croo's website.
13 March 2023
More than a dozen security flaws have been disclosed in E11, a smart intercom product made by Chinese company Akuvox.
"The vulnerabilities could allow attackers to execute code remotely in order to activate and control the device's camera and microphone, steal video and images, or gain a network foothold," Claroty security researcher Vera Mens said in a technical write-up.
Akuvox E11 is
13 March 2023
The Dark Pink advanced persistent threat (APT) actor has been linked to a fresh set of attacks targeting government and military entities in Southeast Asian countries with a malware called KamiKakaBot.
Dark Pink, also called Saaiwc, was first profiled by Group-IB earlier this year, describing its use of custom tools such as TelePowerBot and KamiKakaBot to run arbitrary commands and exfiltrate