Latest Cybersecurity News and Articles


Hamas Likely Cooperates With Hackers to Stay Online

23 October 2023
The infrastructure of the Al-Qassam Brigades website has been moved between different providers to keep it online amidst Israeli airstrikes and constant attacks from hackers.

Europol: ‘Key Target’ in Ragnar Locker Ransomware Operation Arrested in Paris

23 October 2023
Law enforcement agencies from 11 countries collaborated to arrest a key member of the Ragnar Locker ransomware group, leading to the takedown of their infrastructure and data leak website.

Cyber Venture Capital Funding on Pace to Hit Four-Year Low

23 October 2023
Venture capital investments in cybersecurity firms have decreased, with $1.9 billion raised in the third quarter, a 30% drop from the previous year, according to new data released by Crunchbase.

Okta Says Hackers Breached its Support System and Viewed Customer Files

23 October 2023
Hackers gained access to Okta's customer support management system, allowing them to view private customer information, including sensitive data such as cookies and session tokens.

Exploitation of Cisco IOS XE vulnerabilities affecting UK organisations

23 October 2023
Organisations are encouraged to take action to mitigate vulnerabilities affecting Cisco IOS XE (CVE-2023-20198 and CVE-2023-20273) and follow the latest vendor advice.

Quasar RAT Leverages DLL Side-Loading to Fly Under the Radar

23 October 2023
The open-source remote access trojan known as Quasar RAT has been observed leveraging DLL side-loading to fly under the radar and stealthily siphon data from compromised Windows hosts. "This technique capitalizes on the inherent trust these files command within the Windows environment," Uptycs researchers Tejaswini Sandapolla and Karthickkumar Kathiresan said in a report published last week,

Harmonic Lands $7M Funding to Secure Generative AI Deployments

23 October 2023
The company aims to provide businesses with a comprehensive understanding of AI adoption within their enterprises, offering risk assessments for all AI applications and identifying compliance, security, and privacy issues.

Update: War Crimes Tribunal Says September Cyberattack was an Act of Espionage

23 October 2023
The attack is seen as an attempt to undermine the Court's mandate. Dutch law enforcement authorities are currently investigating the incident, but it is unclear if any information was stolen.

Exploitation of Cisco IOS XE vulnerabilities affecting UK organisations

22 October 2023
Organisations are encouraged to take action to mitigate vulnerabilities affecting Cisco IOS XE (CVE-2023-20198 and CVE-2023-20273) and follow the latest vendor advice.

Europol Dismantles Ragnar Locker Ransomware Infrastructure, Nabs Key Developer

21 October 2023
Europol on Friday announced the takedown of the infrastructure associated with Ragnar Locker ransomware, alongside the arrest of a "key target" in France. "In an action carried out between 16 and 20 October, searches were conducted in Czechia, Spain, and Latvia," the agency said. "The main perpetrator, suspected of being a developer of the Ragnar group, has been brought in front of the examining

Okta's Support System Breach Exposes Customer Data to Unidentified Threat Actors

21 October 2023
Identity services provider Okta on Friday disclosed a new security incident that allowed unidentified threat actors to leverage stolen credentials to access its support case management system. "The threat actor was able to view files uploaded by certain Okta customers as part of recent support cases," David Bradbury, Okta's chief security officer, said. "It should be noted that the Okta

Cisco Zero-Day Exploited to Implant Malicious Lua Backdoor on Thousands of Devices

21 October 2023
The vulnerability, tracked as CVE-2023-20273, allows for privilege escalation through the Web UI. It has been used alongside another vulnerability, CVE-2023-20198, in an exploit chain to deploy a malicious implant.

Critical RCE Flaws Found in Solarwinds Access Audit Solution

21 October 2023
The vulnerabilities, which have been patched in version 2023.2.1, could be exploited by remote unauthenticated attackers to execute arbitrary code in the context of SYSTEM without authentication.

Business-Oriented Threat Involving ‘Several Types of Malware All at Once’ Remains Active

21 October 2023
The campaign involves various types of malware, including cryptominers and keyloggers, and primarily targets enterprises that provide business-to-business (B2B) products and services.

FBI: Thousands of Remote IT Workers Sent Wages to North Korea to Help Fund Weapons Program

21 October 2023
The workers used false identities to secure remote IT jobs and funneled their earnings to North Korea, while also infiltrating and stealing information from the companies they worked for.

Cisco Zero-Day Exploited to Implant Malicious Lua Backdoor on Thousands of Devices

20 October 2023
Cisco has warned of a new zero-day flaw in IOS XE that has been actively exploited by an unknown threat actor to deploy a malicious Lua-based implant on susceptible devices. Tracked as CVE-2023-20273 (CVSS score: 7.2), the issue relates to a privilege escalation flaw in the web UI feature and is said to have been used alongside CVE-2023-20198 as part of an exploit chain. "The attacker first

23andMe announce data breach

20 October 2023
23andMe announced that customer profile information was accessed without user consent, including DNA Relatives profiles for individual accounts.

Okta Support System Hacked, Sensitive Customer Data Stolen

20 October 2023
Okta warns that hackers broke into its support case management system and stole sensitive data that can be used to impersonate valid users. The post Okta Support System Hacked, Sensitive Customer Data Stolen appeared first on SecurityWeek.

48% of organizations predict cyberattack recovery to take weeks

20 October 2023
According to a cloud adoption report, 72% of respondents are using generative AI and 74% leveraging public cloud AI and analytics services.

Hackers Stole Access Tokens from Okta’s Support Unit

20 October 2023
Okta, a company that provides identity tools like multi-factor authentication and single sign-on to thousands of businesses, has suffered a security breach involving a compromise of its customer support unit, KrebsOnSecurity has learned. Okta says the incident affected a "very small number" of customers, however it appears the hackers responsible had access to Okta's support platform for at least two weeks before the company fully contained the intrusion.