Latest Cybersecurity News and Articles


In Other News: Energy Services Firm Hacked, Tech CEO Gets Prison Time, X Glitch Leads to CIA Channel Hijack

20 October 2023
Summary of notable cybersecurity news stories that may be top headlines, but are important for the week of October 16, 2023. The post In Other News: Energy Services Firm Hacked, Tech CEO Gets Prison Time, X Glitch Leads to CIA Channel Hijack appeared first on SecurityWeek.

India Targets Microsoft, Amazon Tech Support Scammers in Nationwide Crackdown

20 October 2023
India's Central Bureau of Investigation (CBI) conducted raids at 76 locations across the country as part of Operation Chakra-II, targeting cybercrime operations involved in tech support scams and cryptocurrency fraud.

Exploited SSH Servers Offered in the Dark web as Proxy Pools

20 October 2023
Researchers at Aqua Nautilus have uncovered a threat to SSH in cloud environments. Attackers are using SSH tunneling to exploit SSH servers and gain access to organizations' networks.

CISA, NSA, FBI, MS-ISAC Publish Guide on Preventing Phishing Intrusions

20 October 2023
The guide categorizes phishing into two common tactics: obtaining login credentials and deploying malware, and provides details on techniques used by malicious actors, such as impersonation and spoofing, to carry out these attacks.

Almost 42,000 Cisco IOS XE Devices Exploited, No Patch Available

20 October 2023
Security researchers have discovered tens of thousands of exploited devices with a backdoor installed due to a critical zero-day vulnerability in Cisco IOS XE software's web user interface.

CISA Launches New Phase of Secure by Design to Push Global Industry on Software Security

20 October 2023
CISA plans to issue a request for information to address Secure by Design engineering and is urging software manufacturers to demonstrate evidence of security incorporation through artifacts.

Philippine Military Ordered to Stop Using Artificial Intelligence Apps Due to Security Risks

20 October 2023
The Philippine defense chief ordered the 163,000-member military to stop using applications that harness AI to generate personal portraits, saying they could pose security risks. The post Philippine Military Ordered to Stop Using Artificial Intelligence Apps Due to Security Risks appeared first on SecurityWeek.

Vietnamese Hackers Hit Digital Marketers With Info-stealer Malware

20 October 2023
Vietnamese cybercrime groups are targeting the digital marketing sectors in the United Kingdom, United States, and India with various malware strains, including the DarkGate information stealer.

Viking Line in Crisis as Cyberattack Paralyzes Shipping Industry Across Europe

20 October 2023
The Viking Line cyberattack, believed to be a DDoS attack, caused major disruptions to shipping company websites and emphasizes the urgent need for robust cybersecurity measures in the industry.

Over 200 million malicious emails were detected in Q3 2023

20 October 2023
According to an email security report, 233.9 million malicious emails were detected in Q3 2023. 150,000 emails displayed previously unknown behaviors.

Tampered OpenCart Authentication Aids Credit Card Skimming Attack

20 October 2023
Using outdated software is the main reason for website compromise. In one case, an e-commerce store running on an old version of OpenCart led to credit card theft and fraud.

Authorities Seize Control of RagnarLocker Ransomware Dark Web Site

20 October 2023
The RagnarLocker ransomware group’s dark web leak site has been seized in a coordinated law enforcement operation. The post Authorities Seize Control of RagnarLocker Ransomware Dark Web Site appeared first on SecurityWeek.

Spec Secures $15M Series A Funding, Accelerating Innovation in Fraud Defense

20 October 2023
Cybersecurity firm Spec has successfully closed a $15M Series A funding round led by SignalFire, with participation from Legion Capital and Rally Ventures, enabling the company to advance its platform and expand its threat labs.

Fraud Detection Firm Spec Raises $15 Million

20 October 2023
Silicon Valley fraud detection startup attracts $15 million in new financing from SignalFire, Legion Capital and Rally Ventures. The post Fraud Detection Firm Spec Raises $15 Million appeared first on SecurityWeek.

SMBs Seek Help as Cyber Threats Reach an All-Time High

20 October 2023
Cultivating a strong cybersecurity culture and empowering employees to make informed security decisions is crucial for SMBs to protect themselves and gain customer trust.

Play Ransomware Threatens to Reveal Stolen Data From Associated Wholesale Grocers

20 October 2023
The Play ransomware group has threatened Associated Wholesale Grocers (AWG) with a cyberattack, stating their intention to release sensitive data stolen from the firm on October 22, 2023.

Malvertisers Using Google Ads to Target Users Searching for Popular Software

20 October 2023
Details have emerged about a malvertising campaign that leverages Google Ads to direct users searching for popular software to fictitious landing pages and distribute next-stage payloads. Malwarebytes, which discovered the activity, said it's "unique in its way to fingerprint users and distribute time sensitive payloads." The attack singles out users searching for Notepad++ and PDF converters to

Ransomware Realities in 2023: One Employee Mistake can Cost a Company Millions

20 October 2023
Ransomware attacks can cost victim organizations millions of dollars, leading to significant financial and reputational damage, particularly for small and mid-sized businesses.

Hackers Exploit QR Codes with QRLJacking for Malware Distribution

20 October 2023
Quishing involves circulating QR codes embedded with malicious links or malware downloads, while QRLJacking exploits the login with QR code feature to trick users into logging into fake websites and steal their sensitive data.

Vietnamese Hackers Target U.K., U.S., and India with DarkGate Malware

20 October 2023
Attacks leveraging the DarkGate commodity malware targeting entities in the U.K., the U.S., and India have been linked to Vietnamese actors associated with the use of the infamous Ducktail stealer. "The overlap of tools and campaigns is very likely due to the effects of a cybercrime marketplace," WithSecure said in a report published today. "Threat actors are able to acquire and use multiple