Latest Cybersecurity News and Articles
08 March 2023
TSA has issued a new cybersecurity amendment. as part of the Department of Homeland Security’s efforts to increase cybersecurity resilience.
08 March 2023
Researchers at Trellix Advanced Research Center have detected various campaigns that use OneNote documents to distribute Qakbot and other malware such as AsyncRAT, Icedid, and XWorm.
08 March 2023
It uses spear-phishing emails for initial access, carrying malicious documents with government-themed lures. It further deploys the RoyalRoad RTF kit, allowing attackers to exploit older vulnerabilities for further infection.
08 March 2023
Morphisec researchers have been tracking this info-stealer since November 2022. This campaign uses lures and loading tactics similar to another info-stealer named S1deload, however, the final payload delivered is different.
08 March 2023
The attack occurred on February 17, causing technical difficulties for the facility. The care institution announced the breach via its website and attributed the problem to a group that had gained unauthorized access to its network.
08 March 2023

Move comes as White House backs bill that could give it power to ban Chinese-owned app nationwideTikTok has announced a data security regime for protecting user information across Europe, as political pressure increases in the US to ban the social video app.The plan, known as Project Clover, involves user data being stored on servers in Ireland and Norway at an annual cost of €1.2bn (£1.1bn), while any data transfers outside Europe will be vetted by a third-party IT company. Continue reading...
08 March 2023
The attack in February forced the Israel Institute of Technology (Technion) to postpone exams and shut down its IT systems. The incident followed what Israeli defense officials said were dozens of attempted Iranian cyberattacks over the past year.
08 March 2023
Analysis in 2021 by The Citizen Lab concluded that TikTok collects types of data similar to what other social media platforms collect - and also said that "the general privacy standards for social platforms is not a high bar."
08 March 2023
The RESTRICT Act was introduced to Congress to address the potential threat of technology from foreign adversaries to improve national cybersecurity.
08 March 2023
The North Korea-linked Lazarus Group has been observed weaponizing flaws in an undisclosed software to breach a financial business entity in South Korea twice within a span of a year.
08 March 2023
A pair of severe security vulnerabilities have been disclosed in the Jenkins open source automation server that could lead to code execution on targeted systems.
The flaws, tracked as CVE-2023-27898 and CVE-2023-27905, impact the Jenkins server and Update Center, and have been collectively christened CorePlague by cloud security firm Aqua. All versions of Jenkins versions prior to 2.319.2 are
08 March 2023
A spokesperson for the school told The Record that they did not know if the attack was ransomware, and claimed they “do not have evidence of any personal data being compromised.” On Tuesday, the school confirmed it would not open for the day.
08 March 2023
A total of 24 of the addressed security defects were reported by external researchers. These include eight high-severity flaws, 11 medium-severity bugs, and five low-severity issues.
08 March 2023
A severe vulnerability in the Toyota Customer 360 customer relationship management (CRM) platform allowed a security researcher to access the personal information of the car maker’s customers in Mexico.
08 March 2023
The exploited vulnerability, tracked as CVE-2022-27228, affects the ‘Polls, Votes’ module of the Bitrix Site Manager application. The security hole allows a remote, unauthenticated attacker to execute arbitrary code.
08 March 2023
For the 113th International Women’s Day, Security Magazine is sharing stories and suggestions from women in security leadership positions.
08 March 2023
The February 9 attack disrupted operations at several member companies, including Delaware Life Insurance; Delaware Life Insurance Company of New York; Clear Spring Life and Annuity; Clear Spring Property and Casualty; and Clear Spring Health.
08 March 2023
The NIST strengthened its cybersecurity efforts on Tuesday by renewing its partnerships with the state of Maryland and Montgomery County that underpin the National Cybersecurity Center of Excellence (NCCoE).
08 March 2023
Shikha Kothari, Principal Security Advisor at Eden Data, shares strategies for cybersecurity leaders to create supportive work environments for women.
08 March 2023
The new Sharp Panda campaign uses spear-phishing emails with malicious DOCX file attachments that deploy the RoyalRoad RTF kit to attempt to exploit older vulnerabilities to drop malware on the host.