Latest Cybersecurity News and Articles


SEC Investigating Progress Software Over MOVEit Hack

13 October 2023
Progress Software has received a subpoena from the SEC and faces multiple class action lawsuits and claims for indemnification due to the MOVEit vulnerability, resulting in significant costs.

Critical Heap Overflow Vulnerability in Curl Fixed After a Week Long Wait

13 October 2023
After nearly a week of intense speculation regarding the security issues in cURL, the latest version of this command-line transfer tool has been released with a fix. Vulnerable systems could allow potential attacks via a malicious HTTPS server redirect. Organizations are urged to promptly update and secure systems using cURL or libcurl. 

FBI, CISA Warn of Rising AvosLocker Ransomware Attacks Against Critical Infrastructure

13 October 2023
The AvosLocker ransomware gang has been linked to attacks against critical infrastructure sectors in the U.S., with some of them detected as recently as May 2023. That's according to a new joint cybersecurity advisory released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) detailing the ransomware-as-a-service (RaaS) operation's

Ransomware Attacks Now Target Unpatched WS_FTP Servers

13 October 2023
The Reichsadler Cybercrime Group attempted to deploy ransomware on unpatched WS_FTP servers using a stolen LockBit 3.0 builder. The attackers used the GodPotato tool to escalate privileges on the servers.

Dozens of Squid Proxy Vulnerabilities Remain Unpatched 2 Years After Disclosure

13 October 2023
Dozens of Squid caching proxy vulnerabilities remain unpatched two years after a researcher reported them to developers. The post Dozens of Squid Proxy Vulnerabilities Remain Unpatched 2 Years After Disclosure appeared first on SecurityWeek.

Microsoft Offers Up to $15,000 in New AI Bug Bounty Program

13 October 2023
Microsoft is offering rewards of up to $15,000 in a new bug bounty program dedicated to its new AI-powered Bing. The post Microsoft Offers Up to $15,000 in New AI Bug Bounty Program appeared first on SecurityWeek.

Apple Releases iOS 16 Update to Patch Exploited Vulnerability

13 October 2023
Apple has released iOS and iPadOS updates to fix a local privilege escalation kernel vulnerability (CVE-2023-42824) that has been actively exploited in attacks, potentially by commercial spyware vendors.

Edwardian Hotels London Cyberattack Claim Surface with Samples of Bank Data, Passport

13 October 2023
The luxury hotel group Edwardian Hotels London has reportedly been targeted by the Black Basta ransomware group. Cybersecurity researchers have shared screenshots of the claims made by the hackers.

ShellBot Uses Hex IPs to Evade Detection in Attacks on Linux SSH Servers

13 October 2023
ShellBot is capable of launching DDoS attacks and deploying cryptocurrency miners, highlighting the importance of strong passwords and regular password changes to resist dictionary attacks.

Phishing Campaigns Affecting Italy Witness a Surge

12 October 2023
The Italian Postal Police and CERT-AgID have recently reported numerous phishing campaigns impersonating popular brands such as Poste Italiane, Intesa Sanpaolo, and Zimbra.

Update: BianLian Extortion Group Claims Recent Air Canada Breach

12 October 2023
While Air Canada previously stated that the breach only involved limited personal information, the hackers now say they have accessed much more extensive data, amounting to 210GB.

79% of organizations say bots are more difficult to detect

12 October 2023
Bot attacks were analyzed in a recent report by Kasada, finding that bot attacks were becoming increasingly difficult to detect by security teams.

SEC Investigating Progress Software Over MOVEit Hack

12 October 2023
Progress Software confirms the SEC has launched its own investigation into costly ransomware zero-days in the MOVEit file transfer software. The post SEC Investigating Progress Software Over MOVEit Hack appeared first on SecurityWeek.

SYN Ventures Announces $75 Million Seed Fund for US Cybersecurity Firms

12 October 2023
The venture capital firm, led by former Fortune 500 CISOs and security executives, plans to focus on the seed stage to help early-stage companies develop next-generation cyber solutions and find product-market fit faster.

Researchers Discover SeroXen RAT in Typosquatted NuGet Package

12 October 2023
The package contains a malicious install script that executes covertly during installation, downloading an obfuscated batch script that ultimately constructs and executes a PowerShell script.

European Police Hackathon Hunts Down Traffickers

12 October 2023
The three-day operation took place in the Dutch municipality of Apeldoorn, with officers from all 22 EU member states and four “third countries” taking part, alongside representatives from Interpol, the European Labour Authority, and others.

Shadow PC Warns of Data Breach as Hacker Tries to Sell Gamers’ Information

12 October 2023
The breach occurred due to a social engineering attack targeting an employee, resulting in the theft of customer data including names, email addresses, billing addresses, and credit card expiration dates.

Encrypted pager use on the rise in healthcare since 2022

12 October 2023
Healthcare communication methods were analyzed in a recent report by Spok Holdings, including budget constraints and security concerns.

Backdoor Malware Found on WordPress Website Disguised as Legitimate Plugin

12 October 2023
A backdoor deployed on a compromised WordPress website poses as a legitimate plugin to hide its presence. The post Backdoor Malware Found on WordPress Website Disguised as Legitimate Plugin appeared first on SecurityWeek.

R2R Stomping – Are You Ready to Run?

12 October 2023
ReadyToRun (R2R) stomping is a new method that allows for hidden implanted code in .NET binaries, altering the original intermediate language (IL) code and prioritizing pre-compiled native code for execution.