Latest Cybersecurity News and Articles
10 November 2023
A group with links to Iran targeted transportation, logistics, and technology sectors in the Middle East, including Israel, in October 2023 amid a surge in Iranian cyber activity since the onset of the Israel-Hamas war.
The attacks have been attributed by CrowdStrike to a threat actor it tracks under the name Imperial Kitten, and which is also known as Crimson Sandstorm (previously Curium),
10 November 2023
The attack generated one million requests per second (RPS), four times larger than any previous attack on the bank. Sberbank believes that new, highly skilled hackers are targeting major Russian resources.
10 November 2023
Urdu-speaking readers of a regional news website that caters to the Gilgit-Baltistan region have likely emerged as a target of a watering hole attack designed to deliver a previously undocumented Android spyware dubbed Kamran.
The campaign, ESET has discovered, leverages Hunza News (urdu.hunzanews[.]net), which, when opened on a mobile device, prompts visitors of the Urdu version to install its
09 November 2023
Cloud adoption and cybersecurity spending for small and medium businesses (SMBs) was analyzed in a recent report by DigitalOcean Holdings.
09 November 2023
The threat actor known as Lace Tempest has been linked to the exploitation of a zero-day flaw in SysAid IT support software in limited attacks, according to new findings from Microsoft.
Lace Tempest, which is known for distributing the Cl0p ransomware, has in the past leveraged zero-day flaws in MOVEit Transfer and PaperCut servers.
The issue, tracked as CVE-2023-47246, concerns a path traversal
09 November 2023
A medical company has been fined $450,000 by the New York AG over a data breach that may have involved exploitation of a SonicWall vulnerability.
The post Medical Company Fined $450,000 by New York AG Over Data Breach appeared first on SecurityWeek.
09 November 2023
The Russia-linked hacker group Anonymous Sudan claimed responsibility for the DDoS attacks, targeting OpenAI due to its support for Israel and alleged bias in ChatGPT against Palestine.
09 November 2023
The Washington, DC startup is building a threat-informed defense platform that helps organizations automate detection and response work.
The post Tidal Cyber Raises $5 Million for Threat-Informed Defense Platform appeared first on SecurityWeek.
09 November 2023
As organizations increasingly use QR codes, it seems QR code phishing AKA "quishing" is also on the rise with a 51% increase in September.
09 November 2023
The breach exposed sensitive patient data, including names, birthdates, addresses, medical information, and potentially Social Security numbers, emphasizing the risk of identity theft and healthcare fraud.
09 November 2023
A report found that 70% of developers and 52% of chief information security officers view software supply chain security as a top priority.
09 November 2023
A new malvertising campaign has been observed wherein threat actors are copying a legitimate Windows news portal to promote a malicious installer for the popular processor tool CPU-Z. Based on the infrastructure, domain names, and cloaking templates used, researchers believe the incident is part of a larger malvertising campaign targeting other utilities such as Notepad++, Citrix, and VNC Viewer.
09 November 2023
A new set of malicious Python packages has been discovered on the Python Package Index (PyPI) repository. These packages masquerade as harmless obfuscation tools but contain a malware called BlazeStealer. The campaign started in January 2023 and includes eight packages. Developers must stay alert and thoroughly assess the reliability and safety of packages before incorporating them into their work.
09 November 2023
Checkmarx uncovers a malicious campaign targeting Python developers with malware that takes over their systems.
The post ‘BlazeStealer’ Malware Delivered to Python Developers Looking for Obfuscation Tools appeared first on SecurityWeek.
09 November 2023
The attack was not driven by military necessity but rather aimed to increase the psychological toll of the war, showcasing Russia's focus on disrupting and degrading military readiness through cyber means.
09 November 2023
ChatGPT and its API have experienced a major outage due to a DDoS attack apparently launched by Anonymous Sudan.
The post Major ChatGPT Outage Caused by DDoS Attack appeared first on SecurityWeek.
09 November 2023
A new malvertising campaign has been found to employ fake sites that masquerade as legitimate Windows news portal to propagate a malicious installer for a popular system profiling tool called CPU-Z.
"This incident is a part of a larger malvertising campaign that targets other utilities like Notepad++, Citrix, and VNC Viewer as seen in its infrastructure (domain names) and cloaking templates used
09 November 2023
The vulnerability, tracked as CVE-2023-47246, allows for arbitrary code execution and has been exploited by a threat actor known as Lace Tempest, who is associated with the deployment of Cl0p ransomware.
09 November 2023
The U.S. is still the first most breached country in Q3 2023 despite a decrease in breach count, according to a recent report.
09 November 2023
The vulnerability allows an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a DoS attack with a significant amplification factor, making it a serious threat to network and server security.