Latest Cybersecurity News and Articles
10 October 2023
Millennial and Gen Z workers exhibit more unsafe cybersecurity habits compared to older age groups, such as using the same passwords on multiple devices and sharing work devices with family and friends.
10 October 2023
A sophisticated Magecart campaign has been observed manipulating websites' default 404 error page to conceal malicious code in what's been described as the latest evolution of the attacks.
The activity, per Akamai, targets Magento and WooCommerce websites, with some of the victims belonging to large organizations in the food and retail industries.
"In this campaign, all the victim websites we
10 October 2023
Google's research team has launched v8CTF, a capture-the-flag (CTF) challenge focused on its Chrome browser’s V8 JavaScript engine. The competition opened on October 6, 2023, and is accessible to any exploit writers.
10 October 2023
The vulnerability, known as CVE-2023-3519, was disclosed in July but had been exploited since June. By mid-August, threat actors had backdoored around 2,000 NetScaler instances.
10 October 2023
The vulnerability, tracked as CVE-2023-43641, allows for remote code execution (RCE) on affected hosts. The issue is related to memory corruption in libcue and affects versions 2.2.1 and earlier.
10 October 2023
23andMe initially denied the legitimacy of the data but later acknowledged that unauthorized access to individual accounts may have occurred, highlighting the vulnerability of customer data even without deep network breaches.
10 October 2023
The use of cross-chain bridges and asset-hopping typologies have contributed to a significant increase in funds sent via such services, making it a recognized money laundering typology.
10 October 2023
A new security flaw has been disclosed in the libcue library impacting GNOME Linux systems that could be exploited to achieve remote code execution (RCE) on affected hosts.
Tracked as CVE-2023-43641 (CVSS score: 8.8), the issue is described as a case of memory corruption in libcue, a library designed for parsing cue sheet files. It impacts versions 2.2.1 and prior.
libcue is incorporated into
10 October 2023
A recently disclosed critical flaw in Citrix NetScaler ADC and Gateway devices is being exploited by threat actors to conduct a credential harvesting campaign.
IBM X-Force, which uncovered the activity last month, said adversaries exploited "CVE-2023-3519 to attack unpatched NetScaler Gateways to insert a malicious script into the HTML content of the authentication web page to capture user
10 October 2023
Common targets of cyberattacks in Q2 2023
09 October 2023
Recent weeks have seen a sizable uptick in the number of phishing scams targeting U.S. Postal Service (USPS) customers. Here's a look at an extensive SMS phishing operation that tries to steal personal and financial data by spoofing the USPS, as well as postal services in at least a dozen other countries worldwide.
09 October 2023
The Federal Trade Commission (FTC) released data finding that social media-based scams account for more losses than any other contact method.
09 October 2023
A group of experts noted a rapid evolution in Balada Injector's infrastructure and attack methods, which resulted in a significant number of compromised WordPress sites. Balada malware injection attacks have been found exploiting a vulnerable tagDiv premium theme plugin to target Newspaper and Newsmag websites. It is recommended to remove all unwanted admin users and redundant plugins to stay safe.
09 October 2023
Ahmed Fessi was hired as Chief Transformation & Information Officer at Medius. Fessi brings 15 years' of experience with AI, data and cybersecurity.
09 October 2023
An ad fraud botnet dubbed PEACHPIT leveraged an army of hundreds of thousands of Android and iOS devices to generate illicit profits for the threat actors behind the scheme.
The botnet is part of a larger China-based operation codenamed BADBOX, which also entails selling off-brand mobile and connected TV (CTV) devices on popular online retailers and resale sites that are backdoored with an
09 October 2023
In a filing with the Securities and Exchange Commission, MGM Resorts reported that a recent cyberattack is expected to cost the company an estimated $100 million.
09 October 2023
In a filing with the Securities and Exchange Commission, MGM Resorts reported that a recent cyberattack is expected to cost the company an estimated $100 million.
09 October 2023
The combination of AI's adaptive algorithms and data processing capabilities has empowered mal actors to develop complex social engineering attacks.
09 October 2023
Recently patched TagDiv Composer plugin vulnerability exploited to hack thousands of WordPress sites as part of the Balada Injector campaign.
The post Recently Patched TagDiv Plugin Flaw Exploited to Hack Thousands of WordPress Sites appeared first on SecurityWeek.
09 October 2023
Various hacker groups from around the world, including Ghosts of Palestine and Garuna, have joined the cyber conflict, targeting private and public infrastructure in Israel and the Palestinian territories.