Latest Cybersecurity News and Articles


Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players' Systems

13 February 2023
An unknown threat actor created malicious game modes for the Dota 2 multiplayer online battle arena (MOBA) video game that could have been exploited to establish backdoor access to players' systems. The modes exploited a high-severity flaw in the V8 JavaScript engine tracked as CVE-2021-38003 (CVSS score: 8.8), which was exploited as a zero-day and addressed by Google in October 2021. "Since V8

Education Department reminds colleges of deadline for following cybersecurity rules

13 February 2023
Higher-education institutions that handle federal financial aid data have until early June to comply with federal rules for protecting privacy and personal information, the Education Department noted this week.

Chinese Tonto Team Hackers' Second Attempt to Target Cybersecurity Firm Group-IB Fails

13 February 2023
The Singapore-headquartered firm said that it detected and blocked malicious phishing emails originating from the group targeting its employees. It's also the second attack aimed at Group-IB, the first of which took place in March 2021.

Pepsi Bottling Ventures Suffers Data Breach After Malware Attack

13 February 2023
Pepsi Bottling Ventures LLC suffered a data breach caused by a network intrusion that resulted in the installation of information-stealing malware and the extraction of data from its IT systems.

From Huawei to TikTok, Chinese tech giants face scrutiny amid spying concerns

13 February 2023
With Chinese tech giants triggering national security concerns -- amid Beijing-backed bad actors capable of orchestrating massive cyberattacks worldwide -- the outcome of the constant tussle could shape the world's tech landscape for years to come.

Indian Social Media App Slick Exposed Childrens' User Data

13 February 2023
Due to a misconfiguration, anyone familiar with the database’s IP address could access the database, which contained entries of over 153,000 users at the time it was secured.

Four ways cyber leaders can take a page from football playbooks

13 February 2023
Football reminds us of the important elements that drive effective people-centric cybersecurity. With a growing threat landscape, organizations must stay proactive: they must continuously upskill teams and individuals across the entire organization.

DHL, MetaMask Phishing Emails Target Namecheap Customers

13 February 2023
A surge of phishing emails impersonating DHL and MetaMask started hitting inboxes of Namecheap customers last week, attempting to trick recipients into sharing personal information or sharing their crypto wallet’s secret recovery phrase.

Russian Government evaluates the immunity to hackers acting in the interests of Russia

13 February 2023
Russian media reported that Alexander Khinshtein, the head of the Duma committee on information policy, announced that the Russian government is evaluating to avoid punishing hackers acting in the interests of Moscow.

Ransomware Targets Technion University, Protests Tech Layoffs and Israel

13 February 2023
A ransom note from the new 'DarkBit' ransomware group was left on the university's systems, where the attackers demanded 80 Bitcoin or roughly US$ 1,745,200 to release the decryptor to the university.

OilRig Targets More Middle East Government Entities

13 February 2023
OilRig APT evolved its methods to bypass security protections by adding a new backdoor to its arsenal to support its long-running espionage campaign against government organizations in the Middle East. 

Siemens Drives Rise in ICS Vulnerabilities Discovered in 2022: Report

13 February 2023
Not only do many of the security holes discovered in 2022 impact Siemens products, the German industrial giant is also responsible for self-reporting the highest number of vulnerabilities, far more than other vendors, according to a SynSaber report.

Researchers Uncover Obfuscated Malicious Code in PyPI Python Packages

13 February 2023
Four different rogue packages in the Python Package Index (PyPI) have been found to carry out a number of malicious actions, including dropping malware, deleting the netstat utility, and manipulating the SSH authorized_keys file.

NIST Picks Ascon Algorithms to Protect Data on IoT, Small Electronic Devices

13 February 2023
The National Institute of Standards and Technology (NIST) has selected a group of cryptographic algorithms called Ascon as the lightweight cryptography standard to protect data flowing through IoT devices.

As V-Day nears: Romance scams cost victims $1.3B last year

13 February 2023
Romance scams cost victims at least $1.3 billion in 2022, according to the US Federal Trade Commission's latest numbers. Almost 70,000 people reported these crimes last year, and the median reported loss was $4,400.

Military Organizations in Pakistan Targeted With Sophisticated Espionage Tool

13 February 2023
Tracked as NewsPenguin, the adversary has been observed sending phishing emails that use the upcoming Pakistan International Maritime Expo & Conference (PIMEC-2023) as bait and which carry weaponized documents to deliver an advanced espionage tool.

Honeypot-Factory: The Use of Deception in ICS/OT Environments

13 February 2023
There have been a number of reports of attacks on industrial control systems (ICS) in the past few years. Looking a bit closer, most of the attacks seem to have spilt over from traditional IT. That's to be expected, as production systems are commonly connected to ordinary corporate networks at this point. Though our data does not indicate at this point that a lot of threat actors specifically

Australia Defence Dept removed all its CCP-linked cameras

13 February 2023
Australia's Defence Department removed all Chinese-manufactured surveillance cameras after an audit detailed the number of Hikvision and Dahua devices installed in various government facilities.

Experts published a list of proxy IPs used by the pro-Russia group Killnet

13 February 2023
Researchers from SecurityScorecard published a list of proxy IPs used by the pro-Russia group Killnet with the intent to interfere with its operation and block its attacks.

CISA adds Fortra MFT, TerraMaster NAS, Intel driver Flaws, to its Known Exploited Vulnerabilities Catalog

13 February 2023
The CISA added actively exploited flaws in Fortra MFT, Intel driver, and TerraMaster NAS, respectively tracked as CVE-2023-0669, CVE-2015-2291, and CVE-2022-24990, to its Known Exploited Vulnerabilities Catalog.