Latest Cybersecurity News and Articles


North Korean Hackers Tageting Crypto Experts with KANDYKORN macOS Malware

01 November 2023
State-sponsored threat actors from the Democratic People's Republic of Korea (DPRK) have been found targeting blockchain engineers of an unnamed crypto exchange platform via Discord with a novel macOS malware dubbed KANDYKORN. Elastic Security Labs said the activity, traced back to April 2023, exhibits overlaps with the infamous adversarial collective Lazarus Group, citing an analysis of the

Top-Level Domain .US Harbors Prolific Malicious Link Shortening Service

01 November 2023
The .US domain has been plagued by phishing activity and illicit content, with thousands of malicious link shortener domains registered, despite regulations aimed at verifying the identity and location of registrants.

Palo Alto Networks to Acquire Cloud Security Start-Up Dig Security

01 November 2023
The acquisition will integrate Dig's capabilities into Palo Alto's Prisma Cloud platform. Financial details were not disclosed, but reports suggest the deal is valued at $400 million.

Turla APT Uses Fresh Variant of Kazuar Backdoor to Target Ukrainian Defense Sector

01 November 2023
The latest variant of Kazuar features significant improvements in code structure and functionality, including comprehensive system profiling, credential theft, an extended set of commands, and enhanced task automation.

Applying ATT&CK Methodology to Hardware and Firmware

01 November 2023
The rise of hardware- and firmware-related attacks and supply chain threats has fundamentally changed the cybersecurity landscape, requiring a deeper understanding of these areas in the context of the MITRE ATT&CK framework.

Iranian Threat Group Scarred Manticore Snoops on Entities From Albania to the Middle East

01 November 2023
The campaign, which targets high-profile organizations in the Middle East, has been using the LIONTAIL malware framework installed on Windows servers. LIONTAIL uses Windows HTTP stack driver HTTP.sys to load memory-resident payloads.

Turla Updates Kazuar Backdoor with Advanced Anti-Analysis to Evade Detection

01 November 2023
The Russia-linked hacking crew known as Turla has been observed using an updated version of a known second-stage backdoor referred to as Kazuar. The new findings come from Palo Alto Networks Unit 42, which is tracking the adversary under its constellation-themed moniker Pensive Ursa. "As the code of the upgraded revision of Kazuar reveals, the authors put special emphasis on Kazuar's ability to

Alert: F5 Warns of Active Attacks Exploiting BIG-IP Vulnerability

01 November 2023
F5 is warning of active abuse of a critical security flaw in BIG-IP less than a week after its public disclosure that could result in the execution of arbitrary system commands as part of an exploit chain. Tracked as CVE-2023-46747 (CVSS score: 9.8), the vulnerability allows an unauthenticated attacker with network access to the BIG-IP system through the management port to achieve code execution

Over half of CISOs measure security program maturity monthly

31 October 2023
Chief Information Security Officers (CISOs) were surveyed on their security programs and risk management strategies, including attack response times.

Cybersecurity Leaders Spooked by SEC Lawsuit Against SolarWinds CISO

31 October 2023
The SEC's lawsuit against the CISO of SolarWinds is leaving CISOs across the industry spooked and reevaluating their roles. The post Cybersecurity Leaders Spooked by SEC Lawsuit Against SolarWinds CISO appeared first on SecurityWeek.

API open authentication vulnerabilities discovered by researchers

31 October 2023
API security vulnerabilities in open authentication (OAuth), including user account information, were recently discovered by Salt Security.

Palo Alto Networks to Acquire Cloud Security Start-Up Dig Security

31 October 2023
Palo Alto Networks has entered into a definitive agreement to acquire Dig Security, a provider of Data Security Posture Management (DSPM) technology. The post Palo Alto Networks to Acquire Cloud Security Start-Up Dig Security appeared first on SecurityWeek.

Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability

31 October 2023
Atlassian warns that a critical vulnerability in Confluence Data Center and Server could lead to significant data loss if exploited. The post Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability appeared first on SecurityWeek.

Largest Indian Data Leak Involving 815 Million People’s COVID Test Data on Sale; Samples Verified

31 October 2023
The personal data of nearly 815 million citizens of India, including names, phone numbers, addresses, passport information, and Aadhaar card details, has been found for sale on the dark web.

Malicious NuGet Packages Exploit Loophole in MSBuild Integrations

31 October 2023
Cybersecurity firm ReversingLabs has discovered a coordinated and ongoing malicious campaign on the NuGet package manager. The campaign involves the publishing of hundreds of malicious packages since August.

Florida SIM Swapper Sentenced to Prison for Cryptocurrency Theft

31 October 2023
The perpetrator and his co-conspirators targeted dozens of victims, gaining access to their cryptocurrency accounts by hijacking their phone numbers and initiating password resets.

Arid Viper Disguising Mobile Spyware as Updates for Non-Malicious Android Applications

31 October 2023
The malware used by Arid Viper shares similarities with a non-malicious dating app called Skipped, indicating a possible connection between the APT group and the app's developers.

IAM Credentials in Public GitHub Repositories Harvested in Minutes

31 October 2023
A threat actor is reportedly harvesting IAM credentials from public GitHub repositories within five minutes of exposure. The post IAM Credentials in Public GitHub Repositories Harvested in Minutes appeared first on SecurityWeek.

Russia to Launch its Own Version of Virustotal Due to US Snooping Fears

31 October 2023
The Russian government is developing its own malware scanning platform, Multiscanner, due to concerns that the U.S. government could access data from the popular VirusTotal service.

Attackers Exploiting Critical F5 BIG-IP Vulnerability

31 October 2023
Exploitation of a critical vulnerability (CVE-2023-46747) in F5’s  BIG-IP product started less than five days after public disclosure and PoC exploit code was published. The post Attackers Exploiting Critical F5 BIG-IP Vulnerability appeared first on SecurityWeek.