Latest Cybersecurity News and Articles


EU Cyber Resilience Act May Cause Bottlenecks, Companies Say

10 November 2023
Concerns have been raised about the provision in the act that requires software developers to report vulnerabilities within 24 hours, as it may overwhelm cyber agencies and pose security risks.

1.3 Million Maine Residents Impacted by MOVEit Hack

10 November 2023
The State of Maine says the personal information of 1.3 million individuals was compromised in the MOVEit attack. The post 1.3 Million Maine Residents Impacted by MOVEit Hack appeared first on SecurityWeek.

Kyocera AVX Says Ransomware Attack Impacted 39,000 Individuals

10 November 2023
The LockBit ransomware gang claimed responsibility for the breach and leaked stolen data, including passport scans and financial documents, potentially exposing proprietary designs and patented information.

Ransomware Attack on China’s Biggest Bank Disrupts Treasury Market Trades, Reports Say

10 November 2023
A ransomware attack on China’s biggest bank, the Industrial and Commercial Bank of China Financial Services, disrupts Treasury market trades. The post Ransomware Attack on China’s Biggest Bank Disrupts Treasury Market Trades, Reports Say appeared first on SecurityWeek.

SentinelOne to Acquire Cybersecurity Consulting Firm Krebs Stamos Group

10 November 2023
Cybersecurity company SentinelOne is acquiring advisory firm Krebs Stamos Group to create a new entity called PinnacleOne Strategic Advisory Group, with Christopher Krebs and Alex Stamos taking on key positions.

NATO Allies Express Support for Collective Response to Cyberattacks

10 November 2023
Germany's National Security Strategy envisions the establishment of a dedicated entity for offensive cyber operations, although it rejects the use of hack-backs as a means of cyber defense.

Threat Actors Leverage File-Sharing Service and Reverse Proxies for Credential Harvesting

10 November 2023
The use of a reverse proxy in this phishing campaign allows the attackers to bypass multi-factor authentication (MFA) and gain access to victims' Microsoft 365 accounts, leading to further distribution of phishing emails.

MGM Resorts Anticipates No Further Disruptions From September Cyberattack

10 November 2023
MGM Resorts is investing $40 million in IT upgrades next year and is facing multiple class-action lawsuits and potential financial losses from legal proceedings related to the attack.

Predator AI ChatGPT Integration Poses Risk to Cloud Services

10 November 2023
The hacking tool is distributed through Telegram channels linked to hacking communities and focuses on facilitating web application attacks on commonly used technologies.

WhatsApp Introduces New Privacy Feature to Protect IP Address in Calls

10 November 2023
The privacy feature builds upon previous measures such as "Silence Unknown Callers" to protect users from unwanted contact and minimize the risk of zero-click attacks and spyware.

Ransomed.vc Gang Claims to Shut Down After Six Affiliates Allegedly Arrested

10 November 2023
The group initially threatened victims with European data breach fines but later offered to sell the entire operation, including domain names, breached company access, and databases.

GitHub Enhances Security Capabilities With AI

10 November 2023
GitHub is leveraging AI to enhance its secret scanning program, allowing code maintainers to create custom patterns for detecting organization-specific secrets and improving scanning accuracy.

The New 80/20 Rule for SecOps: Customize Where it Matters, Automate the Rest

10 November 2023
There is a seemingly never-ending quest to find the right security tools that offer the right capabilities for your organization. SOC teams tend to spend about a third of their day on events that don’t pose any threat to their organization, and this has accelerated the adoption of automated solutions to take the place of (or augment) inefficient and cumbersome SIEMs. With an estimated 80% of

Alert: 'Effluence' Backdoor Persists Despite Patching Atlassian Confluence Servers

10 November 2023
Cybersecurity researchers have discovered a stealthy backdoor named Effluence that's deployed following the successful exploitation of a recently disclosed security flaw in Atlassian Confluence Data Center and Server. "The malware acts as a persistent backdoor and is not remediated by applying patches to Confluence," Aon's Stroz Friedberg Incident Response Services said in an analysis published

UK Shoppers Lost Over $13 Million to Fraud Last Festive Season

10 November 2023
While AI tools make fraud campaigns more convincing, users can still protect themselves by being cautious of phishing emails, recognizing warning signs, and following online shopping guidance provided by the NCSC.

Risk Ledger Raises $7.65 Million for Supply Chain Security Solution

10 November 2023
The London-based company offers a collaborative platform that helps organizations identify and mitigate supply chain security risks in real time. The funding will be used to advance product development and deepen partnerships in key industries.

NY AG Hits Radiology Group With $450K Fine in SonicWall Hack

10 November 2023
The breach was a result of the group failing to apply a firmware patch to fix a zero-day vulnerability in their SonicWall firewall, highlighting the importance of promptly updating and securing computer hardware and systems.

FBI Highlights Emerging Initial Access Methods Used by Ransomware Groups

10 November 2023
Organizations should implement security measures such as regular backups, vendor security reviews, strong user account security, and network monitoring to mitigate the risk of ransomware attacks.

Iran-Linked Imperial Kitten Cyber Group Targeting Middle East's Tech Sectors

10 November 2023
A group with links to Iran targeted transportation, logistics, and technology sectors in the Middle East, including Israel, in October 2023 amid a surge in Iranian cyber activity since the onset of the Israel-Hamas war. The attacks have been attributed by CrowdStrike to a threat actor it tracks under the name Imperial Kitten, and which is also known as Crimson Sandstorm (previously Curium),

Russian State-Owned Sberbank Hit by 1 Million RPS DDoS Attack

10 November 2023
The attack generated one million requests per second (RPS), four times larger than any previous attack on the bank. Sberbank believes that new, highly skilled hackers are targeting major Russian resources.