Latest Cybersecurity News and Articles


NPM Trojan Bypasses UAC, Installs AnyDesk with "Oscompatible" Package

19 January 2024
In a recent incident, a malicious package called "oscompatible" was uploaded to the npm registry. The package was found to contain a sophisticated remote access trojan for Windows machines.

CISA Warns Against New Androxgh0st Malware Attacks

19 January 2024
The CISA and the FBI issued a joint warning about the Androxgh0st malware botnet, indicating that threat actors are building a botnet network to extract cloud credentials. Threat actors were also observed using stolen AWS credentials to create new users and user policies on a vulnerable website. The agencies have released IOCs associated with the Androxgh0st malware operation and recommended mitigations.

Preventing Data Loss: Backup and Recovery Strategies for Exchange Server Administrators

19 January 2024
In the current digital landscape, data has emerged as a crucial asset for organizations, akin to currency. It’s the lifeblood of any organization in today's interconnected and digital world. Thus, safeguarding the data is of paramount importance. Its importance is magnified in on-premises Exchange Server environments where vital business communication and emails are stored and managed.  In

Kansas State University Cyberattack Disrupts IT Network and Services

19 January 2024
Kansas State University is managing a cybersecurity incident that has disrupted various network systems, including VPN, email services, and video platforms, impacting the educational continuity for its 20,000 students and 1,400 academic personnel.

Ransomware Attacks Leave Small Business Owners Feeling Suicidal, Report Says

19 January 2024
The stress caused by ransomware attacks can lead to burnout and sickness among IT teams, potentially resulting in personnel leaving their jobs or being absent on sick leave.

U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM Vulnerability

19 January 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical flaw in Ivanti Endpoint Manager Mobile and MobileIron Core to its list of actively exploited vulnerabilities.

Remcos Rat Propagates via Webhards

19 January 2024
The Remcos RAT is being distributed in South Korea through webhards, leveraging adult-themed games as a disguise. In this tactic, users are deceived into opening files posing as adult games. This campaign emphasizes the need for heightened vigilance when downloading files from the internet.

JPMorgan Ups Cyber Defenses as Scam Attacks Rise

19 January 2024
Mary Callahan Erdoes, head of the bank’s asset and wealth management division, highlighted a significant rise in cybercrime, with a 65% increase in fraud losses for U.S. financial institutions from 2022 to 2023.

Oleria Raises $33M Series A to Usher in New Era of Adaptive and Autonomous Identity Security

19 January 2024
Oleria, a company specializing in adaptive and autonomous identity security solutions, has secured $33.1 million in Series A funding, led by Evolution Equity Partners with participation from Salesforce Ventures, Tapestry VC, and Zscaler.

Russian State Hackers Deploying Malware in Espionage Attacks Around Europe

19 January 2024
Russian state hackers from Center 18, a unit within Russia’s Federal Security Service (FSB), have been using sophisticated tactics to deploy backdoors on the devices of targets in NATO countries and Ukraine.

Wealthy Countries Boast Superior Cyber Defenses

19 January 2024
A report by SecurityScorecard revealed that wealthier regions have better cybersecurity defenses and lower cyber risk compared to poorer regions. The study found that organizations in regions with lower GDP are more likely to suffer data breaches.

Update: Cyberattack on Ukraine’s Largest Telecom Provider Will Cost It About $100 Million

19 January 2024
The attack on Kyivstar, believed to have been carried out by Sandworm APT, aimed to cause a destructive impact, deliver a psychological blow, and gather intelligence, marking a significant incident in the ongoing cyberwar between Ukraine and Russia.

Npm Trojan Bypasses UAC, Installs AnyDesk with "Oscompatible" Package

19 January 2024
A malicious package uploaded to the npm registry has been found deploying a sophisticated remote access trojan on compromised Windows machines. The package, named "oscompatible," was published on January 9, 2024, attracting a total of 380 downloads before it was taken down. oscompatible included a "few strange binaries," according to software supply chain security firm Phylum, including a single

An Analysis of the DarkGate AutoIt Loader

19 January 2024
The malware employs tactics such as lateral movement via PSEXEC, malicious download and execution, proxy setup, and RDP configuration to exfiltrate data and establish command and control communications.

U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM Vulnerability

18 January 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a now-patched critical flaw impacting Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core to its Known Exploited Vulnerabilities (KEV) catalog, stating it's being actively exploited in the wild. The vulnerability in question is CVE-2023-35082 (CVSS score: 9.8), an authentication bypass

Malicious Extortion Bot Targets Publicly Exposed PostgreSQL and MySQL Databases

18 January 2024
The bot gains access to the databases, deletes all tables and databases, and leaves a ransom note demanding payment for data recovery. However, the bot only saves a small portion of the data, even if the ransom is paid.

TA866 Returns with a Large Email Campaign

18 January 2024
The new campaign by TA866 involved a large volume of emails with attached PDFs containing OneDrive URLs that initiated a multi-step infection chain leading to malware payload.

New Docker Malware Steals CPU for Crypto & Drives Fake Website Traffic

18 January 2024
Vulnerable Docker services are being targeted by a novel campaign in which the threat actors are deploying XMRig cryptocurrency miner as well as the 9Hits Viewer software as part of a multi-pronged monetization strategy. "This is the first documented case of malware deploying the 9Hits application as a payload," cloud security firm Cado said, adding the development is a sign that adversaries are

Malware Exploiting 9Hits, Turns Docker Servers into Crypto Miners

18 January 2024
Attackers are using off-the-shelf images from Dockerhub to spread malware, with the 9Hits app visiting various websites and the XMRig miner disabled from visiting crypto-related sites to prevent analysis.

TensorFlow CI/CD Flaw Exposed Supply Chain to Poisoning Attacks

18 January 2024
Continuous integration and delivery misconfigurations in TensorFlow could have been exploited for supply chain attacks, allowing malicious code injection and compromise of GitHub and PyPi releases.