Latest Cybersecurity News and Articles
13 December 2023
The OLVX marketplace operates on the clear web and has gained popularity in recent months. It offers various products and services, including phish kits, remote desktop connections, cPanel credentials, webshells, and stolen data.
13 December 2023
The threat actors behind the BazaCall call back phishing attacks have been observed leveraging Google Forms to lend the scheme a veneer of credibility.
The method is an "attempt to elevate the perceived authenticity of the initial malicious emails," cybersecurity firm Abnormal Security said in a report published today.
BazaCall (aka BazarCall), which was first
13 December 2023
The effects of a November ransomware attack against Oceanside, California’s Tri-City Medical Center were contained more than two weeks ago, but now those behind the cyber incident are publishing stolen data on the dark web.
13 December 2023
Brent Arnold, a partner practicing in Gowling WLG's Advocacy department, discusses the challenges the security industry faces with more and more convincing deepfakes making the rounds.
13 December 2023
Sophos has backported the patch for CVE-2022-3236 to end-of-life (EOL) firewall firmware versions due to ongoing attacks exploiting the vulnerability. The code injection vulnerability is being actively exploited by threat actors to target South Asia.
13 December 2023
New research reveals that 90% of the world’s leading energy companies experienced a third-party data breach in the past 12 months.
13 December 2023
The FCC has updated its rules to require carriers to better verify customers' identities before making any changes to their accounts. The agency also emphasized the importance of quickly notifying customers of any account changes.
13 December 2023
ESET Research has discovered a cluster of malicious Python packages in PyPI, the official Python package repository. These packages target both Windows and Linux systems and deliver a custom backdoor.
13 December 2023
A congressional review found that major pharmacy chains do not require a warrant before sharing customers' records with law enforcement, raising concerns about the privacy of Americans' pharmaceutical information.
13 December 2023
The exposed information included donor names, addresses, payment methods, and even sensitive data about children associated with the organizations, posing a potential risk for phishing attacks and fraudulent donation requests.
13 December 2023
Google is highlighting the role played by Clang sanitizers in hardening the security of the cellular baseband in the Android operating system and preventing specific kinds of vulnerabilities.
This comprises Integer Overflow Sanitizer (IntSan) and BoundsSanitizer (BoundSan), both of which are part of UndefinedBehaviorSanitizer (UBSan), a tool designed to catch various kinds of
13 December 2023
The UK's Ministry of Defence has been fined £350,000 ($440,000) by the ICO for failing to protect the personal information of Afghans who worked with the British government and sought relocation after the Taliban took control of Afghanistan.
13 December 2023
The leaked data included personal information such as email addresses, phone numbers, and bank details. It also included driver information such as driving license numbers and work permit numbers.
13 December 2023
Malware analysis encompasses a broad range of activities, including examining the malware's network traffic. To be effective at it, it's crucial to understand the common challenges and how to overcome them. Here are three prevalent issues you may encounter and the tools you'll need to address them.
Decrypting HTTPS traffic
Hypertext Transfer Protocol Secure (HTTPS), the protocol for secure
13 December 2023
The attack on Russia's tax system has reportedly paralyzed the Federal Tax Service, with the internet connection between its central office and regional branches being disrupted, potentially causing long-term damage.
13 December 2023
The Lazarus APT group, in Operation Blacksmith, exploits the Log4Shell vulnerability to deploy new malware threats, focusing on global manufacturing, agricultural, and physical security sectors. The campaign is believed to have been active since March. Organizations are suggested to engage with threat intel sharing platforms to stay ahead of the curve in protecting systems.
13 December 2023
As a result of the investigation, disciplinary action has been taken against 15 Air National Guard leaders, including the removal of commanders, and the USAF has implemented reforms to strengthen classified data access standards.
13 December 2023
The Ukrainian telecom operator Kyivstar was targeted in a cyberattack, causing internet and mobile communications to go offline, potentially linked to Russian state hackers.
13 December 2023
Microsoft has warned that adversaries are using OAuth applications as an automation tool to deploy virtual machines (VMs) for cryptocurrency mining and launch phishing attacks.
"Threat actors compromise user accounts to create, modify, and grant high privileges to OAuth applications that they can misuse to hide malicious activity," the Microsoft Threat Intelligence team said in an
13 December 2023
A parliamentary committee warned that a coordinated attack could cause severe damage to public services and criticized the Home Office for not prioritizing the issue. They also call for more funding for the NCA and the NCSC.