Latest Cybersecurity News and Articles


Ransomware Groups Continue to Increase Their Operational Tempo

30 October 2023
According to GuidePoint Security, ransomware activity continued to surge in Q3 of 2023. There was a 15% increase in ransomware activity compared to Q2, with 10 new emerging groups tracked during this quarter.

OT Cyberattacks Proliferating Despite Growing Cybersecurity Spend

30 October 2023
The complexity of OT environments, the convergence of IT and OT, insider attacks, and supply chain vulnerabilities contribute to the lack of success in defending against these attacks.

CISOs Struggling to Understand Value of Security Controls Data

30 October 2023
Many chief information security officers (CISOs) are facing challenges when it comes to the purpose and value of security controls data in supporting critical business decisions, according to a report by Panaseer.

CISA Targets Software Identification in Push to Boost Supply Chain Security

30 October 2023
The request for comment aims to establish uniform parameters for tracking critical information such as known vulnerabilities and approved software, enhancing software security.

Three New Security Flaws Discovered in NGINX Ingress Controller for Kubernetes

30 October 2023
The vulnerabilities, tracked as CVE-2022-4886, CVE-2023-5043, and CVE-2023-5044, include path sanitization bypass, annotation injection for arbitrary command execution, and code injection via the permanent-redirect annotation.

New Hunters International Ransomware Possible Rebrand of Hive

30 October 2023
Though it shares strong similarities, Hunters International denies being the same group as Hive, claiming to have purchased the source code from them, and focuses on stealing data rather than encryption.

Urgent: New Security Flaws Discovered in NGINX Ingress Controller for Kubernetes

30 October 2023
Three unpatched high-severity security flaws have been disclosed in the NGINX Ingress controller for Kubernetes that could be weaponized by a threat actor to steal secret credentials from the cluster. The vulnerabilities are as follows -  CVE-2022-4886 (CVSS score: 8.8) - Ingress-nginx path sanitization can be bypassed to obtain the credentials of the ingress-nginx controller CVE-2023-5043 (

Hackers Using MSIX App Packages to Infect Windows PCs with GHOSTPULSE Maware

30 October 2023
A new cyber attack campaign has been observed using spurious MSIX Windows app package files for popular software such as Google Chrome, Microsoft Edge, Brave, Grammarly, and Cisco Webex to distribute a novel malware loader dubbed GHOSTPULSE. "MSIX is a Windows app package format that developers can leverage to package, distribute, and install their applications to Windows users," Elastic

Researchers Uncover Wiretapping of XMPP-Based Instant Messaging Service

28 October 2023
New findings have shed light on what's said to be a lawful attempt to covertly intercept traffic originating from jabber[.]ru (aka xmpp[.]ru), an XMPP-based instant messaging service, via servers hosted on Hetzner and Linode (a subsidiary of Akamai) in Germany. "The attacker has issued several new TLS certificates using Let's Encrypt service which were used to hijack encrypted STARTTLS

CCleaner Says Hackers Stole Users’ Personal Data During MOVEit Mass-Hack

28 October 2023
The hackers exploited a vulnerability in the MOVEit file transfer tool, used by CCleaner, to access sensitive data. The stolen information includes names, contact details, and product purchase information. Less than 2% of users were affected.

Update: Kansas Court System Down Nearly Two Weeks in ‘Security Incident’ That Has Hallmarks of Ransomware

28 October 2023
The outage has hindered electronic filings, payment processing, case management, public access to records, and applications for various legal services, leading to delays and a reliance on paper-based processes.

LockBit Ransomware Gang Claims to Have Stolen Data From Boeing

28 October 2023
The LockBit group has a history of listing companies as victims, even if it was actually a vendor to the compromised company, so further investigation is needed to confirm the extent of the breach.

Stanford University Investigating Cyberattack After Akira Ransomware Claims

28 October 2023
Stanford University is currently investigating a cybersecurity incident within its Department of Public Safety after a ransomware gang claimed to have attacked the school. The Akira ransomware gang has claimed to have stolen 430 GB of data.

Daily malware activity doubled year over year for small businesses

27 October 2023
Small business cybersecurity was analyzed in a recent Comcast report, finding that daily malware activity in 2023 roughly doubled since 2022.

CISA: Agencies Seeing Steep Decrease in Known Exploited Vulnerabilities on Federal Networks

27 October 2023
Federal civilian agencies have remediated over 7 million Known Exploited Vulnerabilities findings this year, resulting in a 72% decrease in the percentage of vulnerabilities exposed for 45 or more days.

North Korean Lazarus Group Targets Software Vendor Using Known Flaws

27 October 2023
The group compromised a software vendor by exploiting known security flaws in another popular software. They deployed malware such as SIGNBT and LPEClient to gain control over the victims' systems.

UK: NCSC Rolls Out Protective DNS Service for Schools

27 October 2023
The U.K NCSC's PDNS for Schools service will be rolled out for free over the next year, and it will provide metrics about network health and support for resolving issues.

Stripedfly Malware Framework Infects One Million Windows, Linux Hosts

27 October 2023
StripedFly features TOR-based traffic concealing mechanisms, automated updating, worm-like spreading capabilities, and an EternalBlue SMBv1 exploit created before the flaw was disclosed.

US Senator Quizzes 23andMe Over Credential-Stuffing Hack

27 October 2023
Genetics testing firm 23andMe is facing multiple class action lawsuits and congressional scrutiny following a credential-stuffing hacking incident that exposed sensitive customer data.

California City Warns of Data Breach After Attack Claim by NoEscape Ransomware

27 October 2023
The breach, which occurred from August 12 to September 26, involved the theft of personal information such as names, Social Security numbers, driver's license numbers, medical information, and health insurance policy numbers.