Latest Cybersecurity News and Articles


Poor Cybersecurity Habits are Common Among Younger Employees

10 October 2023
Millennial and Gen Z workers exhibit more unsafe cybersecurity habits compared to older age groups, such as using the same passwords on multiple devices and sharing work devices with family and friends.

New Magecart Campaign Alters 404 Error Pages to Steal Shoppers' Credit Cards

10 October 2023
A sophisticated Magecart campaign has been observed manipulating websites' default 404 error page to conceal malicious code in what's been described as the latest evolution of the attacks. The activity, per Akamai, targets Magento and WooCommerce websites, with some of the victims belonging to large organizations in the food and retail industries. "In this campaign, all the victim websites we

Google Bug Bounty Program Expands to Chrome V8, Google Cloud

10 October 2023
Google's research team has launched v8CTF, a capture-the-flag (CTF) challenge focused on its Chrome browser’s V8 JavaScript engine. The competition opened on October 6, 2023, and is accessible to any exploit writers.

Credential Harvesting Campaign Targets Unpatched NetScaler Instances

10 October 2023
The vulnerability, known as CVE-2023-3519, was disclosed in July but had been exploited since June. By mid-August, threat actors had backdoored around 2,000 NetScaler instances.

libcue Library Flaw Opens GNOME Linux Systems Vulnerable to RCE Attacks

10 October 2023
The vulnerability, tracked as CVE-2023-43641, allows for remote code execution (RCE) on affected hosts. The issue is related to memory corruption in libcue and affects versions 2.2.1 and earlier.

Update: 23andMe Scraping Incident Leaked Data on 1.3 Million Users of Ashkenazi and Chinese Descent

10 October 2023
23andMe initially denied the legitimacy of the data but later acknowledged that unauthorized access to individual accounts may have occurred, highlighting the vulnerability of customer data even without deep network breaches.

North Korea-Linked Lazarus APT Laundered Over $900 Million Through Cross-Chain Crime

10 October 2023
The use of cross-chain bridges and asset-hopping typologies have contributed to a significant increase in funds sent via such services, making it a recognized money laundering typology.

libcue Library Flaw Opens GNOME Linux Systems Vulnerable to RCE Attacks

10 October 2023
A new security flaw has been disclosed in the libcue library impacting GNOME Linux systems that could be exploited to achieve remote code execution (RCE) on affected hosts. Tracked as CVE-2023-43641 (CVSS score: 8.8), the issue is described as a case of memory corruption in libcue, a library designed for parsing cue sheet files. It impacts versions 2.2.1 and prior. libcue is incorporated into

Citrix Devices Under Attack: NetScaler Flaw Exploited to Capture User Credentials

10 October 2023
A recently disclosed critical flaw in Citrix NetScaler ADC and Gateway devices is being exploited by threat actors to conduct a credential harvesting campaign. IBM X-Force, which uncovered the activity last month, said adversaries exploited "CVE-2023-3519 to attack unpatched NetScaler Gateways to insert a malicious script into the HTML content of the authentication web page to capture user

The evolving cyber threat landscape

10 October 2023
Common targets of cyberattacks in Q2 2023

Phishers Spoof USPS, 12 Other Natl’ Postal Services

09 October 2023
Recent weeks have seen a sizable uptick in the number of phishing scams targeting U.S. Postal Service (USPS) customers. Here's a look at an extensive SMS phishing operation that tries to steal personal and financial data by spoofing the USPS, as well as postal services in at least a dozen other countries worldwide.

FTC finds that social media scams lead to more losses than other scams

09 October 2023
The Federal Trade Commission (FTC) released data finding that social media-based scams account for more losses than any other contact method. 

Latest Balada Injector Campaign Targets Unpatched tagDiv Plugin

09 October 2023
A group of experts noted a rapid evolution in Balada Injector's infrastructure and attack methods, which resulted in a significant number of compromised WordPress sites. Balada malware injection attacks have been found exploiting a vulnerable tagDiv premium theme plugin to target Newspaper and Newsmag websites. It is recommended to remove all unwanted admin users and redundant plugins to stay safe.

Ahmed Fessi joins Medius as Chief Transformation & Information Officer

09 October 2023
Ahmed Fessi was hired as Chief Transformation & Information Officer at Medius. Fessi brings 15 years' of experience with AI, data and cybersecurity.

PEACHPIT: Massive Ad Fraud Botnet Powered by Millions of Hacked Android and iOS

09 October 2023
An ad fraud botnet dubbed PEACHPIT leveraged an army of hundreds of thousands of Android and iOS devices to generate illicit profits for the threat actors behind the scheme. The botnet is part of a larger China-based operation codenamed BADBOX, which also entails selling off-brand mobile and connected TV (CTV) devices on popular online retailers and resale sites that are backdoored with an 

MGM Resorts cyberattack cost could exceed $100M

09 October 2023
In a filing with the Securities and Exchange Commission, MGM Resorts reported that a recent cyberattack is expected to cost the company an estimated $100 million.

MGM Resort cyberattack cost could exceed $100M

09 October 2023
In a filing with the Securities and Exchange Commission, MGM Resorts reported that a recent cyberattack is expected to cost the company an estimated $100 million.

AI's role in future advanced social engineering attacks

09 October 2023
The combination of AI's adaptive algorithms and data processing capabilities has empowered mal actors to develop complex social engineering attacks.

Recently Patched TagDiv Plugin Flaw Exploited to Hack Thousands of WordPress Sites

09 October 2023
Recently patched TagDiv Composer plugin vulnerability exploited to hack thousands of WordPress sites as part of the Balada Injector campaign. The post Recently Patched TagDiv Plugin Flaw Exploited to Hack Thousands of WordPress Sites appeared first on SecurityWeek.

Multiple Hacker Groups Join in on Israel-Hamas War With Disruptive Cyberattacks

09 October 2023
Various hacker groups from around the world, including Ghosts of Palestine and Garuna, have joined the cyber conflict, targeting private and public infrastructure in Israel and the Palestinian territories.