Latest Cybersecurity News and Articles


UK Government Advises Best Practices for Embedded Device Security

10 July 2024
The cybersecurity arm of the UK government, RITICS, has released a new guide to assist companies in enhancing the security of their operational technology (OT) and industrial control system (ICS) hardware.

Persistent npm Campaign Shipping Trojanized jQuery

10 July 2024
Approximately 68 malicious packages were created between May 26 and June 23, 2024, with deceptive names like cdnjquery and jquertyi. These packages were manually crafted, unlike automated attacks, allowing the threat actor to steal website form data.

Crypto Analysts Expose HuiOne Guarantee's $11 Billion Cybercrime Transactions

10 July 2024
Cryptocurrency analysts have shed light on an online marketplace called HuiOne Guarantee that's widely used by cybercriminals in Southeast Asia, particularly those linked to pig butchering scams. "Merchants on the platform offer technology, data, and money laundering services, and have engaged in transactions totaling at least $11 billion," Elliptic said in a report shared with The Hacker News.

ViperSoftX Malware Disguises as eBooks on Torrents to Spread Stealthy Attacks

10 July 2024
The sophisticated malware known as ViperSoftX has been observed being distributed as eBooks over torrents. "A notable aspect of the current variant of ViperSoftX is that it uses the Common Language Runtime (CLR) to dynamically load and run PowerShell commands, thereby creating a PowerShell environment within AutoIt for operations," Trellix security researchers Mathanraj Thangaraju and Sijo Jacob

Advancing technology puts identities at risk

10 July 2024
Identity and vulnerability management were analyzed in a recent report.

40% of organizations are unprepared for phishing attacks

10 July 2024
Cyber risks, ransomware and cyberattacks were analyzed in a recent report.

Ticketmaster tickets leaked for Taylor Swift concerts and more

10 July 2024
The extortion campaign against Ticketmaster continues with 166,000 Taylor Swift ticket barcodes leaked. 

New OpenSSH Vulnerability Discovered: Potential Remote Code Execution Risk

09 July 2024
Select versions of the OpenSSH secure networking suite are susceptible to a new vulnerability that can trigger remote code execution (RCE). The vulnerability, tracked as CVE-2024-6409 (CVSS score: 7.0), is distinct from CVE-2024-6387 (aka RegreSSHion) and relates to a case of code execution in the privsep child process due to a race condition in signal handling. It only impacts versions 8.7p1

Microsoft Patch Tuesday, July 2024 Edition

09 July 2024
Microsoft Corp. today issued software updates to plug 139 security holes in various flavors of Windows and other Microsoft products. Redmond says attackers are already exploiting at least two of the vulnerabilities in active attacks against Windows users.

Researchers Catch Yemeni Hackers Spying on Middle East Military Phones

09 July 2024
A Yemeni hacking group associated with the Houthi movement has been spying on military personnel in the Middle East by infecting their phones with surveillance software, according to cybersecurity firm Lookout.

CISA and Partner Agencies Join ASD’S ACSC to Release Advisory on APT40, a Chinese State-Sponsored Group

09 July 2024
Cybersecurity agencies from Australia, Canada, Germany, Japan, New Zealand, South Korea, the UK, and the US have warned about APT40, a China-linked cyber espionage group known for quickly exploiting new security bugs after public disclosure.

Nearly 10 billion stolen passwords were leaked on a hacker forum

09 July 2024
Nearly 10 billion unique, plaintext passwords were uploaded to a hacker forum. 

65% of organizations cite data loss as top risk of unauthorized tools

09 July 2024
The security of unauthorized (unapproved by IT) Software as a Service (SaaS) applications were analyzed in a recent report by Next DLP.

RADIUS Protocol Vulnerability Exposes Networks to MitM Attacks

09 July 2024
Cybersecurity researchers have discovered a security vulnerability in the RADIUS network authentication protocol called BlastRADIUS that could be exploited by an attacker to stage Mallory-in-the-middle (MitM) attacks and bypass integrity checks under certain circumstances. "The RADIUS protocol allows certain Access-Request messages to have no integrity or authentication checks," InkBridge

Critical Ghostscript flaw exploited in the wild. Patch it now!

09 July 2024
This vulnerability affects Ghostscript versions ? 10.03.0 and can have a significant impact on web applications and services using Ghostscript for document conversion and previews.

Guide to Operational Security for Election Officials released by CISA

09 July 2024
The CISA has released its Guide to Operational Security for Election Officials. 

Hackers Exploiting Jenkins Script Console for Cryptocurrency Mining Attacks

09 July 2024
Cybersecurity researchers have found that it's possible for attackers to weaponize improperly configured Jenkins Script Console instances to further criminal activities such as cryptocurrency mining. "Misconfigurations such as improperly set up authentication mechanisms expose the '/script' endpoint to attackers," Trend Micro's Shubham Singh and Sunil Bharti said in a technical write-up

Scammers Double-Dip by Offering Prior Victims Help to Recover Stolen Funds

09 July 2024
The scammers identify previous scam victims and pose as trusted entities such as government agencies, cybersecurity firms, or fund recovery services, asking for upfront fees or personal information to supposedly help with the recovery process.

HUMINT: Diving Deep into the Dark Web

09 July 2024
Clear Web vs. Deep Web vs. Dark Web Threat intelligence professionals divide the internet into three main components: Clear Web - Web assets that can be viewed through public search engines, including media, blogs, and other pages and sites. Deep Web - Websites and forums that are unindexed by search engines. For example, webmail, online banking, corporate intranets, walled gardens, etc. Some

Apache Fixed a Source Code Disclosure Flaw in Apache HTTP Server

09 July 2024
This vulnerability, tracked as CVE-2024-39884 and caused by a regression, can lead to unintentional exposure of sensitive data when legacy content-type configurations are used.