Latest Cybersecurity News and Articles
17 February 2023
The discovery was made by Cybernews, who found an open ElasticSearch instance containing 22 million log entries referencing usernames, including individual users and business accounts.
17 February 2023
Entities in Armenia have come under a cyber attack using an updated version of a backdoor called OxtaRAT that allows remote access and desktop surveillance.
"The tool capabilities include searching for and exfiltrating files from the infected machine, recording the video from the web camera and desktop, remotely controlling the compromised machine with TightVNC, installing a web shell,
17 February 2023
Minerva Labs discovered a brand-new piece of stealthy malware known as Beep. Through this, malware authors were attempting to use as many anti-debugging and anti-VM (anti-sandbox) strategies as they could uncover. Beep is meant to evade detection and extract and launch additional payloads—via a technique called process hollowing—on a compromised system.
17 February 2023
Inglis, who spent 28 years at the NSA, including as a top deputy of the spy agency, has reportedly recommended that the White House nominate Kemba Walden as the new National Cyber Director.
17 February 2023
WIP26 is characterized by the abuse of public Cloud infrastructure – Microsoft 365 Mail, Microsoft Azure, Google Firebase, and Dropbox – for malware delivery, data exfiltration, and C2 purposes.
17 February 2023
Group-IB researchers have identified two malicious campaigns from 2020 and 2021, respectively, carried out by SideWinder APT that were designed to steal cryptocurrency. The researchers found two new home-grown tools used by SideWinder APT during the campaign: SideWinder.RAT.b and SideWinder.StealerPy. Given the groups’s financial backing and target list, researchers anticipate this threat to keep evolving and expanding.
17 February 2023
Norwegian authorities announced on Thursday that they had recovered $5.9 million of cryptocurrency stolen in the Axie Infinity hack – an incident widely held to have been perpetrated by the Lazarus Group, which has links to North Korea.
17 February 2023
The attackers use the same commercial online services that sales and marketing teams rely on to identify prospects and personalize communications. They also use Google Translate to translate their malicious emails into multiple languages.
17 February 2023
Recent guidance from the US Cyber Security and Infrastructure Security Agency (CISA) recognizes the need for organizations to continually validate defenses against the latest adversary tactics, techniques, and procedures (TTPs).
17 February 2023
The users receive an SMS with information on the status of a fictional package, presumably ordered from outside of the country. Also, they are informed of the fact that the delivery has failed due to the customs fee not being paid.
17 February 2023
This Red Team framework is designed to be capable of being highly evasive and undetectable by security products, as demonstrated also by many shellcodes we intercepted through hunting activities with zero detection rate on VirusTotal platform.
17 February 2023
Since January 2022, Trend Micro has been observing Earth Yako as it targets researchers in academic institutions and think tanks in Japan. They also observed a small number of attacks that appear to have targeted organizations in Taiwan.
17 February 2023
Hogwarts Legacy, the much-anticipated Harry Potter video game, has finally landed on gaming platforms. As with all games like this, it comes with a steep price tag, so it's no surprise to see websites peddling cracked versions of the game for free.
17 February 2023
A new variant of the notorious Mirai botnet has been found leveraging several security vulnerabilities to propagate itself to Linux and IoT devices.
Observed during the second half of 2022, the new version has been dubbed V3G4 by Palo Alto Networks Unit 42, which identified three different campaigns likely conducted by the same threat actor.
"Once the vulnerable devices are compromised, they
17 February 2023
Mozilla this week announced the release of Firefox 110 and Firefox ESR 102.8 with patches for 10 high-severity vulnerabilities. The two browser versions also arrived with patches for several medium- and low-severity vulnerabilities.
17 February 2023
Microsoft attributed the Chinese cyberespionage group DEV-0147 to a wave of attacks targeting diplomatic entities in South America. The group is also using the ShadowPad backdoor to maintain persistence. Experts suspect that the group uses phishing and exploits unpatched applications as initial attack vectors.
17 February 2023
Security researcher Yerodin Richards has found an authenticated remote code execution (RCE) vulnerability in Arris routers. This is the type of router that ISPs typically provide in loan for customers’ telephony and internet access.
17 February 2023
The obvious threat is users’ credentials, which are often reused on different sites and, when compromised, can be utilized to either blackmail the victim or become sold on the dark web for other purposes.
17 February 2023
The CISA added actively exploited flaws in Cacti, Microsoft Office, Windows, and iOS to its Known Exploited Vulnerabilities Catalog. Experts recommend also private organizations review the Catalog and address the vulnerabilities in their systems.
17 February 2023
Cisco has rolled out security updates to address a critical flaw reported in the ClamAV open source antivirus engine that could lead to remote code execution on susceptible devices.
Tracked as CVE-2023-20032 (CVSS score: 9.8), the issue relates to a case of remote code execution residing in the HFS+ file parser component.
The flaw affects versions 1.0.0 and earlier, 0.105.1 and earlier, and