Latest Cybersecurity News and Articles


Kubescape 3.0 Elevates Open-Source Kubernetes Security

08 November 2023
The platform provides comprehensive visibility into the security posture of all images in a cluster, prioritizing remediation efforts and highlighting high-risk workloads.

Visa Launches Cybersecurity Training Program

08 November 2023
Visa has launched a payments learning program to address the shortage of skilled cybersecurity professionals and create a diverse talent pipeline in response to the White House's call for more pathways in cybersecurity.

Dropper Service Bypassing Android Security Restrictions to Install Malware

08 November 2023
ThreatFabric warns of a dropper service bypassing recent Android security restrictions to install spyware and banking trojans. The post Dropper Service Bypassing Android Security Restrictions to Install Malware appeared first on SecurityWeek.

Update: Dallas County Reviewing Data Leaked by Ransomware Gang

08 November 2023
The gang has posted allegedly stolen data and threatened to release more if there is no reaction. The county is investigating the incident and working with law enforcement and cybersecurity experts.

Webinar: Kickstarting Your SaaS Security Strategy & Program

08 November 2023
SaaS applications make up 70% of total company software usage, and as businesses increase their reliance on SaaS apps, they also increase their reliance on those applications being secure. These SaaS apps store an incredibly large volume of data so safeguarding the organization's SaaS app stack and data within is paramount. Yet, the path to implementing an effective SaaS security program is not 

New BlueNoroff Malware Variant Targets Cryptocurrency Exchanges

08 November 2023
The malware is believed to be a late stage in a multi-stage attack delivered via social engineering, targeting companies in the cryptocurrency industry or those closely associated with it.

Experts Expose Farnetwork's Ransomware-as-a-Service Business Model

08 November 2023
Cybersecurity researchers have unmasked a prolific threat actor known as farnetwork, who has been linked to five different ransomware-as-a-service (RaaS) programs over the past four years in various capacities. Singapore-headquartered Group-IB, which attempted to infiltrate a private RaaS program that uses the Nokoyawa ransomware strain, said it underwent a "job interview" process with the

How to build future security leaders

08 November 2023
What challenges do aspiring cybersecurity leaders face? Answer this question and more with George Gerchow, Chief Security Officer at Sumo Logic.

Financial sector prepares for new payment security guidelines

08 November 2023
Financial institutions work to improve payment data security.

Fraud attacks on financial industry call centers rising

07 November 2023
A new survey found that fraud attacks on call centers are on the rise, based on growth from 2021 to 2022, with financial industry respondents noting an even more acute increase.

Pro-Palestinian Hackers Group ‘Soldiers of Solomon’ Disrupted the Production Cycle of the Largest Israeli Flour Production Plant

07 November 2023
This attack on the flour plant is part of a series of cyber attacks by the group on Israeli organizations, including a successful attack on the Ashalim Power Station and taking control of military servers and systems.

Update: Ransomware Gang Leaks Data Allegedly Stolen From Canadian Hospitals

07 November 2023
Five Canadian hospitals have confirmed that patient and employee data stolen in a ransomware attack has been leaked online, impacting millions of patient visits and employee information.

New GootLoader Malware Variant Evades Detection and Spreads Rapidly

07 November 2023
GootBot is designed to connect to compromised WordPress sites for command and control, making use of unique hard-coded C2 servers for each sample, posing a challenge for detection and prevention.

Critical Vulnerabilities Expose Veeam ONE Software to Code Execution

07 November 2023
Veeam Software has rolled out patches to cover code execution vulnerabilities in its Veeam ONE IT monitoring product. The post Critical Vulnerabilities Expose Veeam ONE Software to Code Execution appeared first on SecurityWeek.

37 Vulnerabilities Patched in Android With November 2023 Security Updates

07 November 2023
The November 2023 Android security update addresses high-severity vulnerabilities in the System component, with additional fixes for Arm, MediaTek, and Qualcomm components.

Data Brokers Expose Sensitive US Military Member Info to Foreign Threat Actors: Study

07 November 2023
Foreign threat actors can easily obtain sensitive information on US military members from data brokers, a Duke University study shows. The post Data Brokers Expose Sensitive US Military Member Info to Foreign Threat Actors: Study appeared first on SecurityWeek.

Online Store Zhefengle Exposed Millions of Chinese Citizen IDs

07 November 2023
The database contained over 3.3 million orders from 2015 to 2020, many of which included uploaded copies of customers' government-issued identity cards. The vulnerability was addressed after a security researcher notified the store owners.

Microsoft Will Roll Out MFA-Enforcing Policies for Admin Portal Access

07 November 2023
These policies will also require MFA for per-user MFA users for all cloud apps and for high-risk sign-ins. The policies will be gradually added to eligible Microsoft tenants, and administrators will have 90 days to review and enable them.

New Jupyter Infostealer Version Emerges with Sophisticated Stealth Tactics

07 November 2023
The Jupyter Infostealer malware has resurfaced with new techniques, including PowerShell command modifications and the use of signed certificates, to establish a persistent presence on compromised systems.

Report: SIM Box Fraud to Drive 700% Surge in Roaming Scams

07 November 2023
SIM box fraud is a type of “interconnected bypass” scam, where threat actors intercept international calls and route them to a local device known as a SIM box. This device then routes the connection back into the network as a local call.