Latest Cybersecurity News and Articles


Chinese Hackers Target Semiconductor Firms in East Asia with Cobalt Strike

06 October 2023
Semiconductor companies in East Asia are being targeted by a China-linked threat actor using a backdoor called HyperBro to deploy Cobalt Strike beacons. The attack chain includes the use of social engineering techniques, such as decoy PDF documents.

Jeremy Rahn hired as Director of Data Governance, IT and Security Operations Team at DataDelivers

06 October 2023
Jeremy Rahn was hired as Director of Data Governance, IT and Security Operations Team at DataDelivers. Rahn has 15 years of cybersecurity experience.

North Korea's Lazarus Group Launders $900 Million in Cryptocurrency

06 October 2023
As much as $7 billion in cryptocurrency has been illicitly laundered through cross-chain crime, with the North Korea-linked Lazarus Group linked to the theft of roughly $900 million of those proceeds between July 2022 and July of this year. "As traditional entities such as mixers continue to be subject to seizures and sanctions scrutiny, the crypto crime displacement to chain- or asset-hopping

Android Devices With Backdoored Firmware Found in US Schools

06 October 2023
A global cybercriminal operation called BadBox has infected the firmware of more than 70,000 Android smartphones, CTV boxes, and tablets with the Triada malware. The post Android Devices With Backdoored Firmware Found in US Schools appeared first on SecurityWeek.

DNA Testing Service 23andMe Investigating Theft of User Data

06 October 2023
The data obtained by the attacker may include personal information, genetic ancestry results, and potential relatives' details of 23andMe customers who opted-in to the "DNA Relatives" service.

Human-Operated Ransomware Attacks Tripled Over Past Year: Report

06 October 2023
According to Microsoft, ransomware gangs are evolving their tactics, with an increase in data exfiltration attacks and the targeting of smaller organizations and less well-known software.

Canadian organizations unprepared for AI-driven cyber threats

06 October 2023
A new survey reveals that Canadian organizations are unprepared to handle and recover from new cyber threats including artificial intelligence.

TA505 Hacker Group Deploys Sneaky RMS Tool in Phishing Campaign

06 October 2023
The attackers are using a Remote Management System (RMS) executable to trick victims into downloading malware disguised as banned applications like ExpressVPN, WeChat, and Skype.

Data Breach at Melbourne’s Royal Women’s Hospital Puts Patient Information at Risk

06 October 2023
The Royal Women's Hospital in Melbourne has experienced a data breach, potentially compromising the personal information of 192 patients. The breach occurred when cybercriminals gained unauthorized access to a staff member's private email account.

Qakbot-Affiliated Actors Distribute Ransom Knight Malware Despite Infrastructure Takedown

06 October 2023
Qakbot malware operators have continued their malicious activities, distributing Ransom Knight ransomware and the Remcos backdoor via phishing emails, despite the recent infrastructure takedown.

Study: 37% intimidated, 39% frustrated with online security

06 October 2023
A new survey reveals 39% of participants express frustration and 37% feel intimidated by the process of staying secure online.

Microsoft Releases New Report on Cybercrime, State-Sponsored Cyber Operations

06 October 2023
US, Ukraine, and Israel remain the most heavily attacked by cyberespionage and cybercrime threat actors, Microsoft says. The post Microsoft Releases New Report on Cybercrime, State-Sponsored Cyber Operations appeared first on SecurityWeek.

GoldDigger: New Android Trojan Targeting Dozens of Vietnamese Banks

06 October 2023
Researchers have discovered a new Android Trojan called GoldDigger that can primarily target users of over 50 Vietnamese banking apps, as well as e-wallets and crypto-wallets. GoldDigger's reach may extend beyond Vietnam. Countering them demands client-side fraud protection solutions that emphasize real-time protection, adaptability, and a focus on behavioral indicators.

Nonprofit Service Provider Blackbaud Settles Data Breach Case for $49.5M With States

06 October 2023
The breach involved health information, Social Security numbers, and financial data of donors and clients, prompting Blackbaud to pay a ransom to the intruder in exchange for deleting the stolen data.

Commerical Construction Insurer Builders Mutual Discloses Data Breach

06 October 2023
Builders Mutual Insurance Co. experienced a data breach that compromised the personal information of over 64,000 customers and employees, including sensitive data like Social Security numbers and medical information.

Chinese Hackers Target Semiconductor Firms in East Asia with Cobalt Strike

06 October 2023
Threat actors have been observed targeting semiconductor companies in East Asia with lures masquerading as Taiwan Semiconductor Manufacturing Company (TSMC) that are designed to deliver Cobalt Strike beacons. The intrusion set, per EclecticIQ, leverages a backdoor called HyperBro, which is then used as a conduit to deploy the commercial attack simulation software and post-exploitation toolkit.

CISA Pivots Focus to China-Linked Threats Against Critical Infrastructure

06 October 2023
The CISA is focusing on the growing threat activity from China, which has become the top nation-state cyber adversary to the U.S., particularly targeting critical infrastructure like rail transportation and energy sectors.

In Other News: Funding Increase, Abuse of Smartphone Location Data, Legal Matters

06 October 2023
Noteworthy stories that might have slipped under the radar: cybersecurity funding increases, new laws, and government’s illegal use of smartphone location data. The post In Other News: Funding Increase, Abuse of Smartphone Location Data, Legal Matters appeared first on SecurityWeek.

Privacy Nonprofit Calls on FTC To Investigate Grindr’s Data Practices

06 October 2023
The Electronic Privacy Information Center (EPIC) has filed a complaint urging the FTC to investigate Grindr for potentially illegally storing and disclosing users' sensitive data, including HIV and vaccination status.

Organizations Warned of Top 10 Cybersecurity Misconfigurations Seen by CISA, NSA

06 October 2023
CISA and the NSA are urging network defenders and software developers to address the top ten cybersecurity misconfigurations. The post Organizations Warned of Top 10 Cybersecurity Misconfigurations Seen by CISA, NSA appeared first on SecurityWeek.