Latest Cybersecurity News and Articles


Malware that can do anything and everything is on the rise

15 February 2023
“Swiss Army knife” malware – multi-purpose malware that can perform malicious actions across the cyber-kill chain and evade detection by security controls – is on the rise, according to Picus Security’s analysis of 550,000 real-world malware samples.

16 NPM Packages Posing as Speed Testers Install Crypto Miners Instead

15 February 2023
CheckPoint discovered these packages on January 17, 2023, all uploaded to NPM by a user named "trendava." Following the company's report, NPM removed them the following day.

Namecheap's Services Abused to Obtain Recovery Phrase

15 February 2023
Email inboxes of Namecheap subscribers started to receive phishing messages last week in an attempt to dupe them into disclosing personal data or their crypto wallets' recovery phrases. Scammers impersonated DHL and MetaMask in their campaigns. Namecheap said that their own systems had not been compromised and that the upstream third-party system they employ to send emails was responsible for the campaign.

Royal Mail hackers demanded $79.4 million ransom

15 February 2023
The LockBit hacking group that encrypted Royal Mail data sought a $79.4 million ransom from the company, a demand that the postal group’s board appears to have rebuffed, setting the stage for a potential large-scale leak of company information.

Chinese Hackers Infiltrate South American Diplomatic Networks

15 February 2023
The Chinese state-sponsored threat actor DEV-0147 has been spotted targeting diplomatic entities in South America with the ShadowPad remote access Trojan (RAT), also known as PoisonPlug.

RedEyes Hackers Use New Malware to Steal Data From Windows, Phones

15 February 2023
The APT37 threat group uses a new evasive 'M2RAT' malware and steganography to target individuals for intelligence collection. APT37, aka 'RedEyes' or 'ScarCruft,' is a North Korean cyber espionage hacking group believed to be state-supported.

Lazarus Group Conceals Blockchain Trails with New Custodial-based Mixer

15 February 2023
The North Korean Lazarus APT group has laundered over $100 million in cryptocurrency since October 2022, through a new single crypto mixer, named Sinbad - found blockchain analysts. Last year, the U.S. Treasury's Office of Foreign Assets Control (OFAC) imposed sanctions against these mixing services. Since then, it is suspected that Lazarus has shifted to the new mixer service to launder its funds.

How a man-on-the-side attack works

15 February 2023
Basically, a client sends a request to a server via a compromised data-transfer channel. This channel isn’t controlled by the cybercriminals, but it is “listened to” by them.

Experts Warn of New Evasive 'Beep' Malware That Can Fly Under the Radar

15 February 2023
Cybersecurity researchers have unearthed a new piece of evasive malware dubbed Beep that's designed to fly under the radar and drop additional payloads onto a compromised host.

Breaking Down the Seven Steps of an SQL Injection Kill Chain

15 February 2023
Much like other cyberattacks, malicious actors carry out SQL injection attacks in various stages across the attack life cycle. During an SQL injection attack specifically, attackers use a wide variety of techniques to gain access to their targets.

Microsoft Takes the Wraps off Sophisticated Tactics by Nobelium

15 February 2023
Microsoft researchers released in-depth analyses of the threat ecology of the Russian-affiliated Nobelium group and how it exploited MagicWeb to perform a complex authentication bypass for Active Directory Federated Services (AD FS). Microsoft first spotted MagicWeb in August 2022, when a Microsoft customer fell victim to a post-compromise capability of MagicWeb.

Configuration Issues in SaltStack IT Tool Put Enterprises at Risk

15 February 2023
Researchers have identified a template injection technique against the open-source SaltStack IT configuration and orchestration platform, as well as common misconfiguration issues, which could allow attackers to gain over the organization's network.

Lokibot, AgentTesla Grow in January 2023's Most Wanted Malware List

15 February 2023
Check Point has released its Global Threat Index report for January 2023, which shows AgentTesla returning to the third spot (from the ninth in December 2022) in the January 2023 Most Wanted Malware list.

Philadelphia Orchestra, Kimmel Center websites down after cyberattack cripples ticket sales

15 February 2023
On Friday, the orchestra and the Kimmel Center said ticket sales were affected by a cyberattack, without providing further details. A spokesperson for the Philadelphia Orchestra did not respond to a request for comment.

Report Reveals How US Has 'Not Advanced the Ball' on Top Cyber Risks

15 February 2023
Increasing geopolitical tensions, vulnerabilities in critical infrastructure, and a patchwork of needed regulations are some of the factors contributing to a host of cybersecurity threats facing the public and private sectors in the new year.

Regular Pen Testing Is Key to Resolving Conflict Between SecOps and DevOps

15 February 2023
In an ideal world, security and development teams would be working together in perfect harmony. But we live in a world of competing priorities, where DevOps and security departments often butt heads with each other. Agility and security are often at odds with each other— if a new feature is delivered quickly but contains security vulnerabilities, the SecOps team will need to scramble the release

Experts Warn of 'Beep' - A New Evasive Malware That Can Fly Under the Radar

15 February 2023
Cybersecurity researchers have unearthed a new piece of evasive malware dubbed Beep that's designed to fly under the radar and drop additional payloads onto a compromised host. "It seemed as if the authors of this malware were trying to implement as many anti-debugging and anti-VM (anti-sandbox) techniques as they could find," Minerva Labs researcher Natalie Zargarov said. "One such technique

Top Chinese Android Vendors Ship Pre-Installed Malware in Smartphones

15 February 2023
Android devices manufactured by top firms are being delivered with pre-installed malware in China, revealed researchers from the Universities of Edinburgh and Dublin. The apps were created to covertly exfiltrate user and device data, including system information, geolocation, user profiles, and call histories. Even those who left the country are exposed to surveillance threats.

Microsoft patches three exploited zero-day flaws

15 February 2023
The February 2023 Patch Tuesday is upon us, with Microsoft releasing patches for 75 CVE-numbered vulnerabilities, including three actively exploited zero-day flaws (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823).

Zscaler acquires Canonic Security to accelerate how enterprises address SaaS-native threats

15 February 2023
Zscaler acquires Canonic Security to prevent organizations’ growing risks of SaaS supply chain attacks. Canonic’s solution allows cybersecurity and IT teams to gain visibility and streamline SaaS application governance and enforcement.