Latest Cybersecurity News and Articles


Opal Security, Which Helps Companies Manage Access and Identities, Raises $22M

11 December 2023
Identity management solution provider Opal Security has managed to raise $22 million in a Series B round to expand its team and develop new AI-powered tools for identity and access risk remediation.

Apache Fixed Critical RCE Flaw CVE-2023-50164 in Struts 2

11 December 2023
The Apache Software Foundation has released security updates to address a critical file upload vulnerability in the Struts 2 framework, which could allow for remote code execution.

Red Roof announces data breach

11 December 2023
Red Roof confirmed that the organization experienced a data breach in late September of 2023. The breach did not involve any Red Roof guest data.

GULOADER Adds New Anti-Analysis Tactic to Arsenal

11 December 2023
Researchers have identified new techniques employed by the GuLoader malware to enhance its evasion capabilities and make analysis more challenging. The highly evasive shellcode downloader malware was found leveraging Vectored Exception Handler (VEH) capability. Organizations can leverage the latest YARA rules from Elastic Security to detect malware.

Report: Privilege Elevation Exploits Used in Over 50% Of Insider Attacks

11 December 2023
Insider threats, including both malicious attacks and unintentional risks, are on the rise, with privilege escalation exploits being a significant component of unauthorized activity.

Researchers Unmask Sandman APT's Hidden Link to China-Based KEYPLUG Backdoor

11 December 2023
Tactical and targeting overlaps have been discovered between the enigmatic advanced persistent threat (APT) called Sandman and a China-based threat cluster that's known to use a backdoor known as KEYPLUG. The assessment comes jointly from SentinelOne, PwC, and the Microsoft Threat Intelligence team based on the fact that the adversary's Lua-based malware LuaDream and KEYPLUG have been

Lack of encryption the primary reason for sensitive data loss

11 December 2023
New study reveals that organizations appear to struggle in their ability to assess and remediate data encryption risks and policy violations.

CISA and ENISA Signed a Working Arrangement to Enhance Cooperation

11 December 2023
The collaboration aims to strengthen cybersecurity, safeguard critical infrastructure, and reinforce the resilience of digital products in the face of increasing cyber threats.

Lazarus Group Using Log4j Exploits to Deploy Remote Access Trojans

11 December 2023
The Lazarus Group, a North Korea-linked threat actor, has been conducting a global campaign called Operation Blacksmith. They are exploiting security flaws in Log4j to deploy remote access trojans (RATs) on compromised hosts.

UK Sanctions Nine Linked to Cyber Trafficking in Southeast Asia

11 December 2023
The United Kingdom has imposed sanctions on individuals and entities involved in Southeast Asia's online scamming industry, targeting both human traffickers and companies connected to scam operations.

Lazarus Group Using Log4j Exploits to Deploy Remote Access Trojans

11 December 2023
The notorious North Korea-linked threat actor known as the Lazarus Group has been attributed to a new global campaign that involves the opportunistic exploitation of security flaws in Log4j to deploy previously undocumented remote access trojans (RATs) on compromised hosts. Cisco Talos is tracking the activity under the name Operation Blacksmith, noting the use of three DLang-based

Researcher Discovered a New Lock Screen Bypass Bug for Android 14 and 13

11 December 2023
The vulnerability allows threat actors physical access to a device, exposing sensitive data in users' Google accounts. Google has been aware of this issue for at least six months but has not yet addressed it, according to researcher Jose Rodriguez.

Aim for a Modern Data Security Approach

11 December 2023
Organizations must shift their data security approach to safeguard sensitive workloads from the moment they enter the data pipeline, rather than relying on securing data only in the cloud data warehouse.

FBI Explains How Companies can Delay SEC Cyber Incident Disclosures

11 December 2023
Companies are advised to establish a relationship with their local FBI field office and contact them soon after a cyber incident is discovered to assist with the FBI's review and determine if a disclosure delay is necessary.

Playbook: Your First 100 Days as a vCISO - 5 Steps to Success

11 December 2023
In an increasingly digital world, no organization is spared from cyber threats. Yet, not every organization has the luxury of hiring a full-time, in-house CISO. This gap in cybersecurity leadership is where you, as a vCISO, come in. You are the person who will establish, develop, and solidify the organization's cybersecurity infrastructure, blending strategic guidance with actionable

Love for Sports Could Lead to Poor Password Practices

11 December 2023
As per a recent study by Bitwarden, approximately one-third of Americans use sports-related terms in their passwords, with professional sports teams being twice as likely to inspire these passwords compared to college sports teams.

Researchers Unveil GuLoader Malware's Latest Anti-Analysis Techniques

11 December 2023
The malware is typically spread through phishing campaigns, and its creators have continuously improved its ability to bypass security features. One recent change involves an enhancement to its Vectored Exception Handling (VEH) capability.

Webinar — Psychology of Social Engineering: Decoding the Mind of a Cyber Attacker

11 December 2023
In the ever-evolving cybersecurity landscape, one method stands out for its chilling effectiveness – social engineering. But why does it work so well? The answer lies in the intricate dance between the attacker's mind and human psychology. Our upcoming webinar, "Think Like a Hacker, Defend Like a Pro," highlights this alarming trend. We delve deep into social engineering, exploring its

Log4j Vulnerability Still Haunts the Security Community

11 December 2023
According to a report from Veracode, two years after the disclosure of a critical vulnerability in Apache Log4j, nearly 2 in 5 applications are still using vulnerable versions, highlighting the persistence of security risks in software development.

Data Breaches Fallout Reach New Heights as the Number of Exposed Records Soars

11 December 2023
According to an Apple-commissioned study conducted by a professor at MIT, ransomware attacks have seen a steep rise, with a nearly 70% increase in such attacks in the first nine months of 2023, primarily targeting organizations with sensitive data.