Latest Cybersecurity News and Articles


Lost and Stolen Devices: A Gateway to Data Breaches and Leaks

18 October 2023
By implementing strong security practices,, organizations can significantly reduce the risks associated with lost and stolen computers and safeguard their sensitive information. The post Lost and Stolen Devices: A Gateway to Data Breaches and Leaks appeared first on SecurityWeek.

Federal Agencies are Falling Behind on Meeting Key Privacy Goal Set Five Years Ago

18 October 2023
The slow progress in implementing privacy requirements and the lack of resources and guidance for emerging technologies pose significant challenges for the government in addressing privacy risks.

Cybersecurity M&A Roundup for First Half of October 2023

18 October 2023
More than a dozen cybersecurity-related M&A deals were announced in the first half of October 2023. The post Cybersecurity M&A Roundup for First Half of October 2023 appeared first on SecurityWeek.

Malvertising Campaign Uses Fake Notepad++ Ads on Google

18 October 2023
The campaign involves malicious ads that redirect users to a fake Notepad++ website, where a system fingerprinting process takes place. If the user passes the checks, they are assigned a unique ID and given a time-sensitive download link.

Recent NetScaler Vulnerability Exploited as Zero-Day Since August

18 October 2023
Mandiant says the recently patched Citrix NetScaler vulnerability CVE-2023-4966 had been exploited as zero-day since August. The post Recent NetScaler Vulnerability Exploited as Zero-Day Since August appeared first on SecurityWeek.

Tens of Thousands of Cisco Devices Hacked via Zero-Day Vulnerability

18 October 2023
Tens of thousands of Cisco devices have reportedly been hacked via the exploitation of the zero-day vulnerability CVE-2023-20198. The post Tens of Thousands of Cisco Devices Hacked via Zero-Day Vulnerability appeared first on SecurityWeek.

Users of Telegram, AWS, and Alibaba Cloud Targeted in Latest Supply Chain Attack

18 October 2023
Attackers are using Starjacking and Typosquatting techniques to inject malicious code into open-source projects, compromising developers' systems and stealing sensitive data.

OpenSSF Launches Malicious Packages Repository

18 October 2023
The Malicious Packages Repository, which has already collected over 15,000 reports, provides a centralized database for shared intelligence, enabling early detection and prevention of malicious code in open-source projects.

TetrisPhantom: Cyber Espionage via Secure USBs Targets APAC Governments

18 October 2023
Government entities in the Asia-Pacific (APAC) region are the target of a long-running cyber espionage campaign dubbed TetrisPhantom. "The attacker covertly spied on and harvested sensitive data from APAC government entities by exploiting a particular type of secure USB drive, protected by hardware encryption to ensure the secure storage and transfer of data between computer systems," Kaspersky 

AIDS Alabama Takes Swift Action After Massive Data Breach

18 October 2023
AIDS Alabama has confirmed a data breach that occurred between October 2021 and August 2022. Sensitive personal information such as names, addresses, Social Security numbers, medical diagnoses, and more were compromised.

Prove Identity Nabs $40M to Expand in Mobile-Based Authentication Tech

18 October 2023
Prove Identity, the smartphone-based identity verification startup formerly known as Payfone, has raised $40 million in funding co-led by MassMutual Ventures and Capital One Ventures.

Update: IBM Says 631K Affected in Johnson & Johnson Database Breach

18 October 2023
Two federal class action lawsuits have been filed against IBM and Johnson & Johnson, alleging negligence in protecting sensitive health information and seeking financial damages and improved data security practices.

Malicious Version of RedAlert Rocket Alert App Used to Spy on Israel

18 October 2023
Hackers are targeting Israeli Android users by distributing a malicious version of the popular RedAlert – Rocket Alerts app, which acts as spyware and collects sensitive data from victims. To tackle the current threat, Android users are advised to avoid using internet URLs or third-party app stores to download the app.

New Admin Takeover Vulnerability Exposed in Synology's DiskStation Manager

18 October 2023
The vulnerability stems from the use of the insecure randomness of the JavaScript Math.random() method, which can be exploited to predict and access restricted functionality.

New Admin Takeover Vulnerability Exposed in Synology's DiskStation Manager

18 October 2023
A medium-severity flaw has been discovered in Synology's DiskStation Manager (DSM) that could be exploited to decipher an administrator's password and remotely hijack the account. "Under some rare conditions, an attacker could leak enough information to restore the seed of the pseudorandom number generator (PRNG), reconstruct the admin password, and remotely take over the admin account,"

D-Link Confirms Data Breach: Employee Falls Victim to Phishing Attack

17 October 2023
Taiwanese networking equipment manufacturer D-Link has confirmed a data breach that led to the exposure of what it said is "low-sensitivity and semi-public information." "The data was confirmed not from the cloud but likely originated from an old D-View 6 system, which reached its end of life as early as 2015," the company said. "The data was used for registration purposes back then. So far, no

Critical Vulnerabilities Uncovered in Open Source CasaOS Cloud Software

17 October 2023
Two critical security flaws in CasaOS personal cloud software allowed attackers to bypass authentication and gain full access to the system, posing a significant cyber threat.

Researchers Warn of Increased Malware Delivery via Fake Browser Updates

17 October 2023
The threat group behind the SocGholish campaigns is likely responsible for the ClearFake malware delivery campaign, which uses compromised WordPress sites to push malicious fake browser updates.

Critical Vulnerabilities Expose ​​Weintek HMIs to Attacks

17 October 2023
The US cybersecurity agency, CISA, has warned organizations about critical vulnerabilities found in a human-machine interface (HMI) product made by the Taiwan-based Weintek. The impacted product is used globally, including in critical manufacturing.

63% of organizations restore data after a ransomware attack

17 October 2023
According to a recent data recovery report, 63% of organizations successfully restore their data when they experience a ransomware attack.