Latest Cybersecurity News and Articles
09 February 2023
Federal regulators hit multistate hospital system Banner Health with a $1.25 million HIPAA fine in the wake of a 2016 hacking breach that affected nearly 3 million individuals.
09 February 2023
Automobile retailer Arnold Clark, in an update to customers, now reports that ransomware-wielding attackers who hit it over the holidays didn't just lock its systems; they also stole data.
09 February 2023
The first of the two vulnerabilities is CVE-2022-21587 (CVSS score: 9.8), a critical issue impacting versions 12.2.3 to 12.2.11 of the Oracle Web Applications Desktop Integrator product.
09 February 2023
A New Prilex PoS malware variant has been observed blocking NFC-enabled contactless credit card transactions and forcing users to insert credit cards for transactions. In fact, an attacker can configure the malware to capture card data only if it is a Black/Infinite or Corporate card. Retailers are suggested to use the right security solution in place in PoS modules to stop malicious code from tampering with the transactions.
09 February 2023
XSS Hunter is a popular open source tool for identifying cross-site scripting (XSS) bugs in websites. An online version was previously maintained by its creator Mandatory (Matthew Bryant).
09 February 2023
Operators of the LockBit ransomware rolled out a new version of their malware, dubbed LockBit Green. It is the modified version of the ESXI ransomware variant and is created to launch attacks against cloud-based services. Moreover, researchers highlighted that the new LockBit variant has a significant overlap with the Conti(v3) ransomware, whose source code was leaked last year.
09 February 2023
The loaders, dubbed MalVirt, are implemented in .NET and use virtualization through the legitimate KoiVM virtualizing protector for .NET applications, according to threat researchers with SentinelOne's SentinelLabs.
09 February 2023
The Iranian nation-state hacking group known as OilRig has continued to target government organizations in the Middle East as part of a cyber espionage campaign that leverages a new backdoor to exfiltrate data.
"The campaign abuses legitimate but compromised email accounts to send stolen data to external mail accounts controlled by the attackers," Trend Micro researchers Mohamed Fahmy, Sherif
09 February 2023
Cybersecurity is quickly becoming one of the most significant growth drivers for Managed Service Providers (MSPs). That's the main insight from a recent study from Lumu: in North America, more than 80% of MSPs cite cybersecurity as a primary growth driver of their business. Service providers have a huge opportunity to expand their business and win new customers by developing their cybersecurity
09 February 2023
A former employee of Ubiquiti pleaded guilty on Thursday in a Manhattan federal courtroom on charges related to perpetrating an audacious insider attack on his employer, in which he accessed a trove of confidential data before demanding a ransom.
09 February 2023
TgToxic has been targeting Android mobile users in Taiwan, Thailand, and Indonesia since July 2022. The malware steals users’ credentials and assets such as cryptocurrency from digital wallets, as well as money from bank and finance apps.
09 February 2023
Business email compromise (BEC) has become one of the most popular methods of financially motivated hacking. And over the past year, one group, in particular, has demonstrated just how quick, easy, and lucrative it really is.
09 February 2023
HPE noted a use-after-free vulnerability in its OneView infrastructure management platform that allows remote attackers to execute arbitrary code on targeted systems, leak data, or create conditions ripe for a DoS attack.
09 February 2023
Launched in 2016, OSS-Fuzz is meant to help identify vulnerabilities in open-source software through continuous fuzzing, with a declared goal of making common software infrastructure more secure.
09 February 2023
Chaim Mazal has been named Chief Security Officer (CSO) at Gigamon and will take on a variety of responsibilities including IT and global security.
09 February 2023
Despite its enormous potential, information security experts have raised concerns over the possible use of ChatGPT by threat actors to launch attacks, including malware development and convincing social engineering scams.
09 February 2023
According to security researchers at Avanan, threat actors have been exploiting ClickFunnels' ability to create pages with malicious links and ultimately conduct credential-harvesting attacks.
09 February 2023
Gurucul report results indicate insider threats are a top concern at organizations of all kinds with over half experiencing a threat in 2022.
09 February 2023
Two new security weaknesses discovered in several electric vehicle (EV) charging systems could be exploited to remotely shut down charging stations and even expose them to data and energy theft.
The findings, which come from Israel-based SaiFlow, once again demonstrate the potential risks facing the EV charging infrastructure.
The issues have been identified in version 1.6J of the Open Charge
09 February 2023
In a continuing sign that threat actors are adapting well to a post-macro world, it has emerged that the use of Microsoft OneNote documents to deliver malware via phishing attacks is on the rise.
Some of the notable malware families that are being distributed using this method include AsyncRAT, RedLine Stealer, Agent Tesla, DOUBLEBACK, Quasar RAT, XWorm, Qakbot, BATLOADER, and FormBook.