Latest Cybersecurity News and Articles


10% of organizations have a formal AI policy in place

25 October 2023
Security leaders were surveyed by ISACA on generative AI uses and policies within the workplace, finding 10% of organizations have a formal policy.

Over 9,500 Bank of Canton Customers May Have had Personal Information Exposed Due to Vendor Breach

25 October 2023
The breach was caused by a vulnerability in Fiserv's MOVEit managed file transfer application. Fiserv has patched the vulnerability, and the bank is monitoring for unusual activity.

VMware Releases Patch for Critical vCenter Server RCE Vulnerability

25 October 2023
VMware has released security updates to address a critical vulnerability in their vCenter Server software. The flaw, known as CVE-2023-34048, allows for remote code execution and is of critical severity (CVSS score: 9.8).

Cl0p named 'nastiest' malware of 2023

25 October 2023
Malware threat actors in 2023 were ranked in a report by OpenText Cybersecurity, finding that the list was topped by four new ransomware groups.

Kazakhstan-Associated Yorotrooper Disguises Origin of Attacks as Azerbaijan

25 October 2023
The threat actor attempts to disguise their origin by hosting infrastructure in Azerbaijan and using the Azerbaijani language in their operations, despite not being fluent in Azerbaijani.

Ukrainian Cyber Officials Warn of Surge in SmokeLoader Attacks on Financial, Government Entities

25 October 2023
Smokeloader malware is a highly complex tool that can perform various malicious functions, such as stealing credentials and executing DDoS attacks, with prices ranging from $400 to $1,650 depending on the package.

CoinFlip Data Breach Exposes Personal Information of Over 36,000 Customers

25 October 2023
The breach, which occurred on August 7, 2023, was discovered a day later and the cybercriminals were removed from CoinFlip's systems with the assistance of their IT team.

Mandiant Intelligence Chief Raises Alarm Over China’s ‘Volt Typhoon’ Hackers in US Critical Infrastructure

25 October 2023
Mandiant's Chief analyst urges critical infrastructure defenders to work on finding and removing traces of Volt Typhoon, a Chinese government-backed hacking team caught in a series of eyebrow-raising attacks against targets in Guam and the United States. The post Mandiant Intelligence Chief Raises Alarm Over China’s ‘Volt Typhoon’ Hackers in US Critical Infrastructure appeared first on SecurityWeek.

Hackers Earn $400k on First Day at Pwn2Own Toronto 2023

25 October 2023
NAS devices, printers, IP cameras, speakers, and mobile phones were hacked on the first day at Pwn2Own Toronto 2023. The post Hackers Earn $400k on First Day at Pwn2Own Toronto 2023 appeared first on SecurityWeek.

Russian Hackers Caught Exploiting Roundcube Webmail Zero-Day

25 October 2023
Russian APT Winter Vivern exploits a zero-day in the Roundcube webmail server in attacks targeting European governments. The post Russian Hackers Caught Exploiting Roundcube Webmail Zero-Day appeared first on SecurityWeek.

Winter Vivern Exploits Zero-Day Vulnerability in Roundcube Webmail Servers

25 October 2023
The vulnerability, assigned CVE-2023-5631, allowed attackers to execute arbitrary JavaScript code in the context of a Roundcube user's browser window through a specially crafted email.

New England Biolabs Exposes Sensitive Data via Environment Files

25 October 2023
The two exposed environment files contained sensitive information such as database credentials, SMTP server login details, and payment processing information, according to Cybernews researchers.

Bracing for AI-Enabled Ransomware and Cyber Extortion Attacks

25 October 2023
Ransomware groups are likely to leverage AI-enabled tools, such as chatbots and voice cloning, to enhance their social engineering tactics and technical skills, posing a greater threat to public and private organizations.

Connecting the wars: Intel analysis of Israel-Hamas and Russia-Ukraine

25 October 2023
In Episode 17 of the Cybersecurity & Geopolitical Discussion from Security magazine, Ian Thornton-Trump, Philip Ingram and Lisa Forte analyze the Russia-Ukraine and Israel-Hamas wars.

CISA Working on Updated National Cyber Incident Response Plan

25 October 2023
The updated plan will involve collaboration with industry stakeholders, government agencies, and critical infrastructure organizations, recognizing the private sector's role as the first responder to many cyber incidents.

New Project Analyzes and Catalogs Vendor Support for Secure PLC Coding

25 October 2023
A new project aims to make it easier for PLC programmers to implement secure coding practices by cataloging useful files and functions from each vendor. The post New Project Analyzes and Catalogs Vendor Support for Secure PLC Coding appeared first on SecurityWeek.

Accenture Expands Cybersecurity Services Capabilities in Latin America With Acquisition of MNEMO Mexico

25 October 2023
MNEMO Mexico's expertise in advanced cyber defense, generative AI-powered cyber intelligence, and a 24/7 security operations center will enhance Accenture's capabilities in helping organizations build cyber-resilient businesses.

Keyfactor Earns $1.3B Valuation After Sale of Minority Stake

25 October 2023
With the investment from Sixth Street Growth, Keyfactor aims to continue its trajectory of hypergrowth, leveraging their experience, financial prowess, and strategic network to empower the company in the next chapter of its development.

Censys Banks $75M for Attack Surface Management Technology

25 October 2023
Michigan startup raises $75 million in new funding as venture capital investors bet big on attack surface management technologies. The post Censys Banks $75M for Attack Surface Management Technology appeared first on SecurityWeek.

Cybercriminals Run Malicious Ads via Facebook

25 October 2023
Criminals are hijacking business accounts on Facebook and running their own advertising campaigns, causing financial damage and reputational harm to legitimate account holders.