Latest Cybersecurity News and Articles


Apparel Giant VF Corporation Reports Cyberattack on First Day of SEC Disclosure Rule

19 December 2023
VF Corporation, one of the largest apparel companies in the world, reported a cyberattack to the U.S. Securities and Exchange Commission (SEC) on the first day of a new cyber incident reporting rule.

What the SEC Weighed in Finalizing the Cyber Disclosure Rules

19 December 2023
The SEC does not aim to manage security but wants better disclosures. The final rule requires the disclosure of material cybersecurity incidents, but does not require specific technical details to avoid providing a roadmap for future attacks.

Insights from the CISA Healthcare and Public Health Sector Risk and Vulnerability Assessment

19 December 2023
The external assessment did not identify any significant vulnerabilities that would allow easy access to the organization's network, but the internal assessment revealed multiple weaknesses that led to domain compromise.

US Regulators Warn of AI Risk to Financial Systems

19 December 2023
The Financial Stability Oversight Council has classified artificial intelligence as an "emerging vulnerability" in the financial system, acknowledging both its potential for innovation and the risks it poses.

xorbot: A Stealthy Botnet Family That Defies Detection

19 December 2023
Xorbot utilizes encryption and decryption algorithms, borrowed from the Mirai source code, to encrypt communication with its command and control server and store sensitive information.

Microsoft is Working on a More Secure Print System for Windows

19 December 2023
Microsoft has introduced Windows Protected Print Mode (WPP) to enhance security and eliminate vulnerabilities in the Windows print system. These changes aim to reduce the attack surface and enhance user safety.

Researchers Disclose Zero-Click Exploit for Microsoft Outlook

19 December 2023
The vulnerabilities, CVE-2023-35384 and CVE-2023-36710, allow an attacker to bypass security measures and execute code on a victim's machine by tricking Outlook into downloading a specially crafted sound file.

Alleged LockBit Operator to Face New Cybercrime Charges in Canada

19 December 2023
A Canadian-Russian man, Mikhail Vasiliev, who is facing extradition to the United States for his alleged involvement in the LockBit ransomware group, is now facing new cybercrime charges in Ontario.

Update: October Cyberattack Leaked Data of 14.7 Million People, Mortgage Giant Mr. Cooper Says

19 December 2023
The accessed data included sensitive details such as names, addresses, phone numbers, Social Security numbers, and bank account numbers of individuals associated with mortgage loans serviced by Mr. Cooper.

8220 Gang Exploiting Oracle WebLogic Server Vulnerability to Spread Malware

19 December 2023
The threat actors associated with the 8220 Gang have been observed exploiting a high-severity flaw in Oracle WebLogic Server to propagate their malware. The security shortcoming is CVE-2020-14883 (CVSS score: 7.2), a remote code execution bug that could be exploited by authenticated attackers to take over susceptible servers. "This vulnerability allows remote authenticated

Double-Extortion Play Ransomware Strikes 300 Organizations Worldwide

19 December 2023
The threat actors behind the Play ransomware are estimated to have impacted approximately 300 entities as of October 2023, according to a new joint cybersecurity advisory from Australia and the U.S. "Play ransomware actors employ a double-extortion model, encrypting systems after exfiltrating data and have impacted a wide range of businesses and critical infrastructure organizations in North

Pro-China Influence Operation Gained YouTube Following, Researchers Find

18 December 2023
The campaign utilizes a network of at least 30 YouTube channels and employs tactics associated with both Russian and Chinese influence operations, including the use of artificially generated voices in videos.

ALPHV Second Most Prominent Ransomware Strain Before Reported Downtime

18 December 2023
ALPHV was the second-most leveraged ransomware strain in North America and Europe between January 2022 and October 2023, just before the reported takedown of the group’s website, according to ZeroFox research.

65% of organizations say ransomware concerns impact risk management

18 December 2023
Enterprise risk management in the financial sector was analyzed in a report where 65% of organizations say ransomware concerns impact risk management.

Microsoft Warns of Storm-0539: The Rising Threat Behind Holiday Gift Card Frauds

18 December 2023
Storm-0539 not only targets gift card-related services for fraud but also collects sensitive information, such as emails and network configurations, for follow-on attacks against the same organizations.

Beware: Experts Reveal New Details on Zero-Click Outlook RCE Exploits

18 December 2023
Technical details have emerged about two now-patched security flaws in Microsoft Windows that could be chained by threat actors to achieve remote code execution on the Outlook email service sans any user interaction. "An attacker on the internet can chain the vulnerabilities together to create a full, zero-click remote code execution (RCE) exploit against Outlook clients," Akamai security

UK National Grid Pulls Chinese Equipment Over Cybersecurity Concerns

18 December 2023
The contract with NR Electric UK, a subsidiary of China's Nari Technology, was terminated without reason given in April, highlighting growing concerns over Chinese involvement in critical infrastructure.

Ubiquiti Fixes Glitch That Exposed Private Video Streams to Other Customers

18 December 2023
The bug was caused by a misconfiguration during an upgrade to Ubiquiti's cloud infrastructure, resulting in 1,216 accounts being improperly associated with another group of 1,177 accounts.

Top 7 Trends Shaping SaaS Security in 2024

18 December 2023
Over the past few years, SaaS has developed into the backbone of corporate IT. Service businesses, such as medical practices, law firms, and financial services firms, are almost entirely SaaS based. Non-service businesses, including manufacturers and retailers, have about 70% of their software in the cloud.  These applications contain a wealth of data, from minimally sensitive general

Rhadamanthys Malware: Swiss Army Knife of Information Stealers Emerges

18 December 2023
The developers of the information stealer malware known as Rhadamanthys are actively iterating on its features, broadening its information-gathering capabilities and also incorporating a plugin system to make it more customizable. This approach not only transforms it into a threat capable of delivering "specific distributor needs," but also makes it more potent, Check Point said&