Latest Cybersecurity News and Articles


Chrome 119 Patches 15 Vulnerabilities

01 November 2023
Chrome 119 is rolling out to Linux, macOS, and Windows users with patches for 15 vulnerabilities. The post Chrome 119 Patches 15 Vulnerabilities appeared first on SecurityWeek.

FBI ‘Keeping a Close Eye’ on Iranian Hackers as Israel-Hamas War Intensifies

01 November 2023
The FBI Director Christopher Wray warned that cyberattacks against the US by Iran and non-state actors could escalate if the conflict intensifies. He stated that Iran has a history of targeting American interests and critical infrastructure.

World's Largest Hardware Retail Cooperative Hit by Cyberattack

01 November 2023
Ace Hardware is currently experiencing a cyberattack that has disrupted its IT systems. While in-store payment systems and credit card processing are unaffected, online services such as placing orders are currently unavailable.

Cryptojackers Use IAM Credential Within Five Minutes of Discovery

01 November 2023
EleKtra-Leak, an ongoing cryptojacking campaign, exploits exposed IAM credentials on GitHub to mine Monero. The attackers are said to have used each stolen credential within five minutes of its discovery. The payloads are delivered via a Google Drive URL, another widely used application, to evade detection. It is recommended to audit the GitHub repository cloning events for any suspicious operations and secure the exposed keys.

MITRE Releases ATT&CK v14 With Improvements to Detections, ICS, Mobile 

01 November 2023
MITRE announces the release of ATT&CK v14, which brings enhancements related to detections, ICS, and mobile. The post MITRE Releases ATT&CK v14 With Improvements to Detections, ICS, Mobile  appeared first on SecurityWeek.

Report: Cyberattacks Cause Revenue Losses in 42% Of Small Businesses

01 November 2023
Employee and consumer data continue to be the most affected categories in data breaches, leading to negative impacts such as lost revenue, customer trust, and employee turnover.

Pro-Ukrainian Hacker Groups Claim to Breach Russia's National Card Payment System

01 November 2023
The targeted system, Mir, is a homegrown alternative to international payment brands and has seen increased usage in Russia following the country's invasion of Ukraine and the departure of international payment services.

DPI: Still Effective for the Modern SOC?

01 November 2023
There has been an ongoing debate in the security industry over the last decade or so about whether or not deep packet inspection (DPI) is dead. The post DPI: Still Effective for the Modern SOC? appeared first on SecurityWeek.

Hands on Review: LayerX's Enterprise Browser Security Extension

01 November 2023
The browser has become the main work interface in modern enterprises. It’s where employees create and interact with data, and how they access organizational and external SaaS and web apps. As a result, the browser is extensively targeted by adversaries. They seek to steal the data it stores and use it for malicious access to organizational SaaS apps or the hosting machine. Additionally,

Companies Scramble to Integrate Immediate Recovery Into Ransomware Plans

01 November 2023
Over one-third of companies lack a comprehensive ransomware strategy, highlighting the need for a holistic approach that prioritizes both prevention and recovery, according to a survey by Zerto.

WiHD Video Torrent Community Leak Exposes Details of All Torrent Users

01 November 2023
Private torrent trackers like WiHD, known for their exclusivity, can still suffer from data breaches, highlighting the importance of robust security measures in protecting user data.

Malicious NuGet Packages Abuse MSBuild Integrations for Code Execution

01 November 2023
Threat actors are constantly publishing malicious NuGet packages to automatically execute code on developers’ machines. The post Malicious NuGet Packages Abuse MSBuild Integrations for Code Execution appeared first on SecurityWeek.

Iranian Cyber Espionage Group Targets Financial and Government Sectors in Middle East

01 November 2023
A threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been observed waging a sophisticated cyber espionage campaign targeting financial, government, military, and telecommunications sectors in the Middle East for at least a year. Israeli cybersecurity firm Check Point, which discovered the campaign alongside Sygnia, is tracking the actor under the name Scarred

The Dangers of Dual Ransomware Attacks

01 November 2023
Recovery efforts should prioritize patching vulnerabilities, removing malicious artifacts, and strengthening protective and detective controls to enhance cyber resilience and reduce the risk of follow-up attacks.

Update: F5 Warns of Active Attacks Exploiting BIG-IP Vulnerability

01 November 2023
F5 has issued a warning about active exploitation of a critical security flaw in its BIG-IP software. The vulnerability, known as CVE-2023-46747, allows attackers to execute arbitrary system commands.

Cutting-Edge AI Raises Fears About Risks to Humanity. Are Tech and Political Leaders Doing Enough?

01 November 2023
Many people are raising the alarm about AI’s as-yet-unknown dangers and calling for safeguards to protect people from its existential threats. The post Cutting-Edge AI Raises Fears About Risks to Humanity. Are Tech and Political Leaders Doing Enough? appeared first on SecurityWeek.

SIEM and Log Management Provider Graylog Raises $39 Million

01 November 2023
Graylog secured $39 million in funding to accelerate product development and scale its go-to-market operations. The post SIEM and Log Management Provider Graylog Raises $39 Million appeared first on SecurityWeek.

TA571 Delivers Forked IcedID Loader Variant

01 November 2023
The use of the Forked IcedID variant, which removes banking functionality and focuses on payload delivery, highlights a shift in malware tactics toward prioritizing ransomware delivery.

Former British Cyberespionage Agency Employee Gets Life in Prison for Stabbing an American Spy

01 November 2023
Former British cyberespionage agency employee was sentenced in a London court for attempted murder, will have to serve at least 13 years in prison. The post Former British Cyberespionage Agency Employee Gets Life in Prison for Stabbing an American Spy appeared first on SecurityWeek.

North Korean Hackers Tageting Crypto Experts with KANDYKORN macOS Malware

01 November 2023
State-sponsored threat actors from the Democratic People's Republic of Korea (DPRK) have been found targeting blockchain engineers of an unnamed crypto exchange platform via Discord with a novel macOS malware dubbed KANDYKORN. Elastic Security Labs said the activity, traced back to April 2023, exhibits overlaps with the infamous adversarial collective Lazarus Group, citing an analysis of the