Latest Cybersecurity News and Articles


Pentagon Moves Closer to Picking Leader for Top Cyber Job

20 October 2023
The U.S. Defense Department has received a report from the RAND Corporation on the creation of a new lead cyber policy chief. The report will inform decisions on the organizational structure and workforce of the new office.

ExelaStealer: A New Info-stealer Gaining Traction on Dark Web

20 October 2023
ExelaStealer, written in Python, is designed to capture sensitive data from compromised Windows systems. It can steal passwords, Discord tokens, credit card information, cookies, keystrokes, screenshots, and clipboard content. As this remains a prevalent threat, organizations are recommended to protect their critical assets and infrastructure with strong security measures.

Iranian Hackers Lurked for 8 Months in Government Network

20 October 2023
Iran-linked hacking group Crambus spent eight months inside a compromised network of a Middle Eastern government, Broadcom’s Symantec cybersecurity unit reports. The post Iranian Hackers Lurked for 8 Months in Government Network appeared first on SecurityWeek.

RagnarLocker Ransoms Its Last Victim as Law Enforcement Takes Down its Leak Site

20 October 2023
RagnarLocker, known for its double extortion tactic and refusal to negotiate ransom demands, has been a significant threat to critical infrastructure organizations, with 52 successful attacks reported.

Unleashing the Power of the Internet of Things and Cyber Security

20 October 2023
Due to the rapid evolution of technology, the Internet of Things (IoT) is changing the way business is conducted around the world. This advancement and the power of the IoT have been nothing short of transformational in making data-driven decisions, accelerating efficiencies, and streamlining operations to meet the demands of a competitive global marketplace. IoT At a Crossroads IoT, in its most

New ExelaStealer Malware Steals Passwords, Discord Tokens, Credit Cards, Cookies, and More

20 October 2023
The initial infection vector of ExelaStealer is not known, but it can be deployed through a decoy document and collects various data from infected systems, including screenshots and system information.

BlackCat Climbs the Summit With a New Tactic

20 October 2023
The BlackCat ransomware operators have introduced a new tool called Munchkin, which allows them to spread their malware to remote machines and shares on a victim organization's network.

How to go From Collecting Risk Data to Actually Reducing Risk?

20 October 2023
Implementing automated workflows, bi-directional ticketing system integration, and tracking performance metrics enables efficient and scalable risk reduction across the organization.

Clever Malvertising Attack Uses Punycode to Look Like Keepass’s Official Website

20 October 2023
Threat actors are using sophisticated techniques like Punycode and brand impersonation to deceive users and distribute malicious software. Users need to be cautious when downloading programs and should verify the authenticity of websites and ads.

US House Panel: AI Regulation Begins With Privacy

20 October 2023
Members of a House panel expressed concerns about China setting global expectations for data collection and use, and emphasized the need for the U.S. to lead in AI development and deployment.

Anticipating the Benefits of a Passwordless Tomorrow

20 October 2023
A majority of businesses are actively planning to move towards passwordless technology, with the expectation that passwords will represent less than a quarter of logins within five years or less.

Clearview AI Wins Appeal to Overturn $10 Million UK Privacy Fine

20 October 2023
The tribunal's decision highlights a specific exemption for foreign law enforcement, but does not prevent the ICO from taking action against international companies that process data of individuals in the UK.

ExelaStealer: A New Low-Cost Cybercrime Weapon Emerges

20 October 2023
A new information stealer named ExelaStealer has become the latest entrant to an already crowded landscape filled with various off-the-shelf malware designed to capture sensitive data from compromised Windows systems. "ExelaStealer is a largely open-source infostealer with paid customizations available from the threat actor," Fortinet FortiGuard Labs researcher James Slaughter said in a

600GB of Data and 308 Hrs Deadline Given Post USCS Cyberattack

20 October 2023
Knight has given a deadline of 308 hours and 2 minutes for the ransom payment, threatening to sell or publicly release the stolen data if the management of US Claims Solutions does not respond within 48 hours.

Casio Discloses Data Breach Impacting Customers in 149 Countries

20 October 2023
The exposed data includes customer names, email addresses, service usage details, and purchase information, but credit card information was not stored in the compromised database.

U.S. DoJ Cracks Down on North Korean IT Scammers Defrauding Global Businesses

20 October 2023
The U.S. government has announced the seizure of 17 website domains used by North Korean information technology (IT) workers as part of an illicit scheme to defraud businesses across the world, evade sanctions, and fund the country's ballistic missile program. The Department of Justice (DoJ) said the U.S. confiscated approximately $1.5 million of the revenue that these IT workers collected from

BlackCat Group Adopts a New Tactic to Circumvent Security Solutions

19 October 2023
The BlackCat ransomware group has introduced a new evasion tool called Munchkin, distributed as an ISO file, allowing them to run ransomware on remote machines. The controller malware is written in Rust and resembles the BlackCat malware family.  Organizations are recommended to leverage the updated IOCs associated with the malware to stay safe.

39% of individuals use the same password for multiple accounts

19 October 2023
According to a recent Yubico survey, 80% of respondents are concerned about the security of their online accounts and 39% admit to reusing passwords.

Harmonic Lands $7M Funding to Secure Generative AI Deployments

19 October 2023
British startup is working on software to mitigate against the ‘wild west’ of unregulated AI apps harvesting company data at scale. The post Harmonic Lands $7M Funding to Secure Generative AI Deployments appeared first on SecurityWeek.

Phishing emails impersonating HR are on the rise

19 October 2023
According to a recent phishing report, nearly one in three users are likely to click on a suspicious link or comply with a fraudulent request.