Latest Cybersecurity News and Articles


Customized Phishing with Geotargeting Tools

14 February 2023
Hackers are sending tailored phishing messages to their intended targets by language and location via geotargeting tool known as Geo Targetly, according to Avanan. The threat actors have been following the spray-and-pray technique that ensures they can target a massive number of individuals in one go. As phishing attacks keep evolving, organizations and individuals should take their security game to the next level. 

Researchers Uncover More Than 700 Malicious Open Source Packages

14 February 2023
In January, cybersecurity company Sonatype said it found 691 malicious npm packages and 49 malicious PyPI components containing crypto-miners, remote access Trojans (RATs), and more.

CISA Warns About Ransomware Attacks Against Healthcare

14 February 2023
A new joint advisory warns of North Korean hackers that are involved in ongoing ransomware attacks against healthcare systems in South Korea and the U.S. According to the advisory, the modus operandi of the attacks includes North Korean hackers acquiring and purchasing infrastructure to conceal their identities. The cybersecurity agencies have shared a list of recommendations and mitigation measures to stay safe.

Massive HTTP DDoS Attack Hits Record High of 71 Million Requests Per Second

14 February 2023
"The majority of attacks peaked in the ballpark of 50-70 million requests per second (RPS) with the largest exceeding 71 million," Cloudflare said, calling it a "hyper-volumetric" DDoS attack.

Python Developers Beware: Clipper Malware Found in 450+ PyPI Packages!

14 February 2023
Malicious actors have published more than 451 unique Python packages on the official Python Package Index (PyPI) repository in an attempt to infect developer systems with clipper malware. Software supply chain security company Phylum, which spotted the libraries, said the ongoing activity is a follow-up to a campaign that was initially disclosed in November 2022. The initial vector entails using

Pig Butchering Scams Are Evolving Fast

14 February 2023
New findings from researchers at the security firm Sophos show how pig butchering scammers are tweaking and refining their strategies to try to ensnare more unsuspecting victims.

All but Florida, South Dakota apply for federal cyber grants allocated by infrastructure bill

14 February 2023
As part of the $1.2 trillion infrastructure spending deal signed into law last year, $1 billion was allocated to state and local governments to upgrade their cybersecurity defenses.

Lazarus hackers use new mixer to hide $100 million in stolen crypto

14 February 2023
North Korean hackers have found a way around U.S.-imposed sanctions to launder the cryptocurrency proceeds from their heists, according to evidence discovered by blockchain analysts.

A CISOs Practical Guide to Storage and Backup Ransomware Resiliency

14 February 2023
One thing is clear. The "business value" of data continues to grow, making it an organization's primary piece of intellectual property. From a cyber risk perspective, attacks on data are the most prominent threat to organizations.  Regulators, cyber insurance firms, and auditors are paying much closer attention to the integrity, resilience, and recoverability of organization data – as well as

Companies often operate in dark with little applied threat intelligence

14 February 2023
Almost 4 in 5 organizations are making cybersecurity decisions without any insight into the attackers they are facing off with, according to a report from Mandiant, a unit of Google Cloud.

New Wave of Zero-Day Attacks Hits PyPI Repository

14 February 2023
Fortinet uncovered a wave of zero-day attacks targeting PyPI packages by a cybercriminal group dubbed Core1337. It has published five packages to the public repository - all designed to launch different types of attacks. All the malicious packages have similar code in the setup.py file, the only major difference between them is the webhook URL. Developers are suggested to stay extra cautious when downloading PyPI packages.

Apple fixes the first zero-day in iPhones and Macs this year

14 February 2023
Apple has released emergency security updates to address a new actively exploited zero-day vulnerability, tracked as CVE-2023-23529, that impacts iOS, iPadOS, and macOS. The flaw is a type confusion issue in WebKit.

Chinese Hackers Targeting South American Diplomatic Entities with ShadowPad

14 February 2023
Microsoft on Monday attributed a China-based cyber espionage actor to a set of attacks targeting diplomatic entities in South America. The tech giant's Security Intelligence team is tracking the cluster under the emerging moniker DEV-0147, describing the activity as an "expansion of the group's data exfiltration operations that traditionally targeted government agencies and think tanks in Asia

Spain, U.S. dismantle phishing gang that stole $5 million in a year

14 February 2023
The cybercrime gang specializes in online scams, employing social engineering, phishing, and smishing to collect sensitive victim details and then use that information to commit financial fraud.

MoneyGram Fraud Victims Get $115m in Compensation

14 February 2023
Nearly 40,000 consumers will be handed their share of the funds, which were forfeited by MoneyGram in 2018 as part of a deferred prosecution agreement (DPA). That action was led by the FTC and the Department of Justice (DoJ).

Valve waited 15 months to patch high-severity flaw. A hacker pounced

14 February 2023
Researchers have unearthed four game modes that could successfully exploit a critical vulnerability that remained unpatched in the popular Dota 2 video game for 15 months after a fix had become available.

Cl0p Exploits GoAnywhere MFT Servers; Impacts Over 130 Orgs

14 February 2023
The Clop ransomware group claimed to have successfully infected more than 130 organizations by abusing the zero-day in Fortra’s GoAnywhere MFT secure file transfer solution. The bug, tracked as CVE-2023-0669, is an RCE issue. The company immediately issued a patch and urged organizations using the software to immediately apply it. Hackers, who failed to share proof, said they did it in just ten days.

Hackers took their Middle Class Tax Refunds and now victims are getting a tax bill

14 February 2023
Many Californians are reporting that scammers drained their inflation relief debit cards before they could use the money. What's worse? They're now finding out they may have to pay income taxes on the money they never received.

Coincover raises $30M to help protect digital assets from hacks and human error

14 February 2023
Coincover, a digital asset protection company, has raised $30 million in funding led by Foundation Capital to protect people and their digital assets from hacks or human error, David Janczewski, CEO and co-founder, shared with TechCrunch.

Tor Network Hit By a Series of Ongoing DDoS Attacks

14 February 2023
The Tor Project’s Executive Director, Isabela Dias Fernandes, reported on Tuesday that the network has been targeted by a wave of DDoS attacks for at least the past seven months.