Latest Cybersecurity News and Articles


BlazeStealer Malware Discovered in Python Packages on PyPI Targets Developers

08 November 2023
The malware runs a Discord bot and enables the threat actor to harvest a wide range of information, including passwords from web browsers and screenshots, execute arbitrary commands, encrypt files, and deactivate Microsoft Defender on the host.

DHS Launches New Critical Infrastructure Security and Resilience Campaign

08 November 2023
DHS launches Shields Ready, a new campaign promoting security and resilience for critical infrastructure organizations. The post DHS Launches New Critical Infrastructure Security and Resilience Campaign appeared first on SecurityWeek.

Chinese APTs Targeting Cambodian Government

08 November 2023
By monitoring telemetry associated with two prominent Chinese APT groups, researchers observed network connections predominately originating from Cambodia, including inbound connections originating from at least 24 Cambodian government organizations.

Black Friday bargain hunters warned of enhanced online scams after millions lost last year

08 November 2023
Latest Cyber Aware campaign aims to help shoppers protect themselves online in the run up to the festive period.

Japan Aviation Electronics Says Servers Accessed During Cyberattack

08 November 2023
On Monday evening, the maker of electronics and aerospace products replaced its website with a static message indicating some of its servers were accessed by hackers last Thursday.

Offense Intended: How Adversarial Emulation Went From State Secret To Board Bullet Point

08 November 2023
Offensive Security does not focus on discreet attacks, singular actors, or Indicators of compromise, but understands the entirety of both sides of the battlefield. The post Offense Intended: How Adversarial Emulation Went From State Secret To Board Bullet Point appeared first on SecurityWeek.

90% of cybersecurity professionals work on vacation

08 November 2023
Work-life balance compromises continue to be a challenge as a new report shows  a majority of cybersecurity professionals check email, Slack and other forms of work communication even when on vacation.

Hacker Leaks 35 Million Scraped LinkedIn User Records

08 November 2023
The contents of the leaked database on BreachForums, as observed by Hackread.com, include publicly available information from LinkedIn profiles, containing full names and profile bios.

Researchers Uncover Undetectable Crypto Mining Technique on Azure Automation

08 November 2023
Cybersecurity researchers have developed what's the first fully undetectable cloud-based cryptocurrency miner leveraging the Microsoft Azure Automation service without racking up any charges. Cybersecurity company SafeBreach said it discovered three different methods to run the miner, including one that can be executed on a victim's environment without attracting any attention. "While this

WhatsApp Introduces New Privacy Feature to Protect IP Address in Calls

08 November 2023
Meta-owned WhatsApp is officially rolling out a new privacy feature in its messaging service called "Protect IP Address in Calls" that masks users' IP addresses to other parties by relaying the calls through its servers. "Calls are end-to-end encrypted, so even if a call is relayed through WhatsApp servers, WhatsApp cannot listen to your calls," the company said in a statement shared with The

Report: Business see rise in cyber insurance costs and requirements

08 November 2023
A new report reveals that more than 40% of businesses have reported an increased requirement from insurers for cybersecurity tools.

Sumo Logic Urges Users to Change Credentials Due to Security Breach

08 November 2023
Cloud monitoring and SIEM firm Sumo Logic is urging users to rotate credentials following the discovery of a security breach. The post Sumo Logic Urges Users to Change Credentials Due to Security Breach appeared first on SecurityWeek.

Beware, Developers: BlazeStealer Malware Discovered in Python Packages on PyPI

08 November 2023
A new set of malicious Python packages has slithered their way to the Python Package Index (PyPI) repository with the ultimate aim of stealing sensitive information from compromised developer systems. The packages masquerade as seemingly innocuous obfuscation tools, but harbor a piece of malware called BlazeStealer, Checkmarx said in a report shared with The Hacker News. "[BlazeStealer]

Experts Expose Farnetwork's Ransomware-as-a-Service Business Model

08 November 2023
Farnetwork has been linked to the development and management of various ransomware strains, including JSWORM, Nefilim, Karma, Nemty, and their own program based on the Nokoyawa ransomware.

Shared IT Service Provider Says Ransomware Data Breach Affects 267,000 Patients

08 November 2023
The hackers responsible for the attack, known as the DAIXIN Team, have gradually leaked samples of the stolen patient data and expressed interest in selling it to data brokers.

FBI Highlights Emerging Initial Access Methods Used by Ransomware Groups 

08 November 2023
FBI warns that ransomware operators continue to abuse third-party vendors and services as an attack vector. The post FBI Highlights Emerging Initial Access Methods Used by Ransomware Groups  appeared first on SecurityWeek.

Data Breach at Singapore's Marina Bay Sands Affects 665,000 Customers

08 November 2023
According to a statement published by the resort, the incident occurred on October 19-20 and involved unauthorized third-party access to its non-casino customers’ loyalty program membership data.

Guide: How vCISOs, MSPs and MSSPs Can Keep their Customers Safe from Gen AI Risks

08 November 2023
Download the free guide, "It's a Generative AI World: How vCISOs, MSPs and MSSPs Can Keep their Customers Safe from Gen AI Risks." ChatGPT now boasts anywhere from 1.5 to 2 billion visits per month. Countless sales, marketing, HR, IT executive, technical support, operations, finance and other functions are feeding data prompts and queries into generative AI engines. They use these tools to write

Marina Bay Sands Discloses Data Breach Impacting 665k Customers

08 November 2023
Singapore’s Marina Bay Sands luxury resort has disclosed a data breach impacting the information of 665,000 customers.  The post Marina Bay Sands Discloses Data Breach Impacting 665k Customers appeared first on SecurityWeek.

Outdated Cryptographic Protocols Put Vast Amounts of Network Traffic at Risk

08 November 2023
A recent study by Quantum Xchange reveals that a large percentage of network traffic has encryption flaws due to the use of older protocols like TLS 1.0 and SSL v3 and is unencrypted, posing a significant risk to businesses.