Latest Cybersecurity News and Articles


RCE Exploit for Wyze Cam v3 Publicly Released, Patch Now

31 October 2023
A security researcher has discovered two vulnerabilities in Wyze Cam v3 firmware and released a proof-of-concept exploit that can be used to gain remote code execution and take over vulnerable devices.

Costco Pharmacy Sends Sensitive Health Data to Third Parties

31 October 2023
The lawsuits claim that Costco's data collection and disclosure practices violate HIPAA, the Federal Trade Act, and federal and state wiretapping and other laws, as well as warnings from government agencies.

Canada Bans WeChat and Kaspersky Apps On Government Devices

31 October 2023
Canada on Monday announced a ban on the use of apps from Tencent and Kaspersky on government mobile devices, citing an "unacceptable level of risk to privacy and security." "The Government of Canada is committed to keeping government information and networks secure," the Canadian government said. "We regularly monitor potential threats and take immediate action to address risks." To that end,

Update: Exploit Released for Critical Cisco IOS XE Flaw, Many Hosts Still Hacked

31 October 2023
Despite patches being available, thousands of Cisco IOS XE devices remain compromised, with major telecommunications and internet providers being particularly affected by such attacks.

Proofpoint to Buy Tessian to Infuse Email Protection With AI

31 October 2023
The acquisition aligns with Proofpoint's vision of securing the human layer in cybersecurity and aims to improve email security, reduce the risk of data breaches, and ease the workload on security teams.

Meta Launches Paid Ad-Free Subscription in Europe to Satisfy Privacy Laws

31 October 2023
Meta on Monday announced plans to offer an ad-free option to access Facebook and Instagram for users in the European Union (EU), European Economic Area (EEA), and Switzerland to comply with "evolving" data protection regulations in the region. The ad-free subscription, which costs €9.99/month on the web or €12.99/month on iOS and Android, is expected to be officially available starting next

SEC Charges SolarWinds and Its CISO With Fraud and Cybersecurity Failures

30 October 2023
The SEC filed charges against SolarWinds and its CISO over misleading investors about its cybersecurity practices and known risks. The post SEC Charges SolarWinds and Its CISO With Fraud and Cybersecurity Failures appeared first on SecurityWeek.

NASCO notifies individuals of a data breach through MOVEit

30 October 2023
NASCO announced a data breach. NASCO utilized MOVEit software, which was accessed in late May and the breach was discovered in mid-July.

FTC says financial institutions must disclose data breaches in 30 days

30 October 2023
The Federal Trade Commission (FTC) has amended the Safeguards Rule requiring non-banking financial institutions to report data breaches.

Remcos RAT Disguises as Payslip to Infect Users

30 October 2023
Researchers uncovered a phishing campaign distributing the Remcos remote access trojan. Cybercriminals disguised the malware as a payslip in a deceptive email. Remcos RAT can perform a range of malicious activities, including keylogging, capturing screenshots, controlling webcams and microphones, and extracting browser histories and passwords.

Canada Bans WeChat and Kaspersky on Government Phones

30 October 2023
The Chief Information Officer of Canada determined that WeChat and Kaspersky applications present an unacceptable level of risk to privacy and security. The post Canada Bans WeChat and Kaspersky on Government Phones appeared first on SecurityWeek.

QR Code-based Phishing Attains 587% Hike, Reports Check Point

30 October 2023
QR code phishing attacks, including quishing and QRLJacking, have seen a dramatic 587% increase from August to September 2023, with threat actors extracting login information from users. This social engineering tactic takes advantage of the trust in QR codes and the routine nature of security updates. The prevalence of quishing is a testament to the ever-evolving nature of cyber threats. 

Huawei, Vivo Phones Tag Google App as TrojanSMS-PA Malware

30 October 2023
Huawei, Honor, and Vivo devices are displaying false security alerts urging the deletion of the Google app due to a supposed TrojanSMS-PA malware, but Google denies that its app triggered the alerts.

Attackers Can Use Modified Wikipedia Pages to Mount Redirection Attacks on Slack

30 October 2023
The Wiki-Slack attack relies on crafting a legitimate footnote in a Wikipedia article and exploiting Slack's rendering of the shared page's preview to generate a hidden malicious link.

Pro-Hamas Hacktivists Targeting Israeli Entities with Wiper Malware

30 October 2023
A pro-Hamas hacktivist group has been observed using a new Linux-based wiper malware dubbed BiBi-Linux Wiper, targeting Israeli entities amidst the ongoing Israeli-Hamas war. "This malware is an x64 ELF executable, lacking obfuscation or protective measures," Security Joes said in a new report published today. "It allows attackers to specify target folders and can potentially destroy an entire

Toronto Public Library Facing Disruptions Due to Cyberattack

30 October 2023
The organization has confirmed that it is a cybersecurity incident, and while there is no evidence of compromised personal information, it may take several days to fully restore normal operations.

45% of Americans avoid accessing sensitive information on public Wi-Fi

30 October 2023
According to a public Wi-Fi security survey by NordVPN, almost 70% of U.S. respondents prefer mobile internet for public online activities.

IoT Security Threats Highlight the Need for Zero Trust Principles

30 October 2023
The manufacturing sector is particularly vulnerable to IoT malware attacks, experiencing an average of 6,000 attacks per week according to Zscaler, which can disrupt critical OT processes and pose long-term challenges for security teams.

White House Issues Sweeping Executive Order to Secure AI

30 October 2023
The order directs the National Institute of Standards and Technology to establish new standards for red-team testing and the Department of Health and Human Services to create a safety program for AI in healthcare.

Florida SIM Swapper Sentenced to Prison for Cryptocurrency Theft

30 October 2023
A 20-year-old Floridian was sentenced to prison for his role in a hacking scheme that led to the theft of $1 million in cryptocurrency. The post Florida SIM Swapper Sentenced to Prison for Cryptocurrency Theft appeared first on SecurityWeek.