Latest Cybersecurity News and Articles


Nonprofit Service Provider Blackbaud Settles Data Breach Case for $49.5M With States

06 October 2023
The fundraising software company Blackbaud has agreed to pay $49.5 million to settle claims brought by the attorneys general of 49 states and Washington, D.C., related to a 2020 data breach. The post Nonprofit Service Provider Blackbaud Settles Data Breach Case for $49.5M With States appeared first on SecurityWeek.

Lorenz Ransomware Embroiled in its Own Two-Year Data Leak

06 October 2023
The leaked data from a misconfigured web server includes names, email addresses, and subject lines of individuals who sought information from Lorenz, spanning from June 2021 to September 2023.

New OS Tool Tells You Who Has Access to What Data

06 October 2023
Ensuring sensitive data remains confidential, protected from unauthorized access, and compliant with data privacy regulations is paramount. Data breaches result in financial and reputational damage but also lead to legal consequences. Therefore, robust data access security measures are essential to safeguard an organization’s assets, maintain customer trust, and meet regulatory requirements.  A

Factors Leading to Organizations Losing Control Over IT and Security Environments

06 October 2023
IT and security teams are facing new responsibilities, such as ensuring security for remote and hybrid workers, managing applications in public cloud environments, and securing data in SaaS environments.

CISA Reverses Course on Malicious Exploitation of Video Conferencing Device Flaws

06 October 2023
CISA has removed from its KEV catalog five Owl Labs video conferencing flaws that require the attacker to be in Bluetooth range. The post CISA Reverses Course on Malicious Exploitation of Video Conferencing Device Flaws appeared first on SecurityWeek.

CISA Warns of Active Exploitation of JetBrains and Windows Vulnerabilities

06 October 2023
The authentication bypass vulnerability in JetBrains TeamCity has already seen exploitation attempts from 74 unique IP addresses, while the privilege escalation flaw in Microsoft Windows CNG Key Isolation Service has no documented exploitation.

Cybersecurity Preparedness Pays Big Dividends for Businesses

06 October 2023
Businesses are investing more in cybersecurity resources and training, resulting in a decrease in phishing links clicked by workers and ransomware attacks, according to GetApp.

Analysis and Config Extraction of Lu0Bot, a Node.js Malware with Considerable Capabilities

06 October 2023
The Node.js malware Lu0Bot uses unconventional programming languages and multi-layer obfuscation. Lu0Bot utilizes a unique approach to domain connection and assembles various parts into a single entity within the JavaScript code.

GitHub's Secret Scanning Feature Now Covers AWS, Microsoft, Google, and Slack

06 October 2023
GitHub has announced an improvement to its secret scanning feature that extends validity checks to popular services such as Amazon Web Services (AWS), Microsoft, Google, and Slack. Validity checks, introduced by the Microsoft subsidiary earlier this year, alert users whether exposed tokens found by secret scanning are active, thereby allowing for effective remediation measures. It was first

Update: Clorox Warns of Quarterly Loss Related to August Cyberattack, Production Delays

06 October 2023
Clorox anticipates continued operational strain in the second quarter but hopes to benefit from restocking retailer inventory, while assessing the long-term impact on earnings.

Malware-Infected Devices Sold Through Major Retailers

06 October 2023
The scheme, known as BADBOX, deploys the Triada malware as a "backdoor" on various devices such as CTV boxes, smartphones, and tablets during the supply chain process in China.

Update: Cyberattack Against Johnson Controls Sparks Downstream Concerns

06 October 2023
The Department of Homeland Security is investigating the attack to determine if sensitive physical security information was compromised, but it was not a breach of any DHS network or system.

Researchers Warn of 100,000 Industrial Control Systems Exposed Online

06 October 2023
The United States, Canada, and Italy are the countries with the highest number of organizations with exposed ICSs, while sectors such as Education, Technology, and Government show the least secure ICS security.

Supermicro's BMC Firmware Found Vulnerable to Multiple Critical Vulnerabilities

06 October 2023
Multiple security vulnerabilities have been disclosed in the Intelligent Platform Management Interface (IPMI) firmware for Supermicro baseboard management controllers (BMCs) that could result in privilege escalation and execution of malicious code on affected systems. The seven flaws, tracked from CVE-2023-40284 through CVE-2023-40290, vary in severity from High to Critical, according to Binarly

Cisco Plugs Gaping Hole in Emergency Responder Software

05 October 2023
Cisco warns that unauthenticated, remote attackers can log into devices using root account, which has default, static credentials that cannot be changed or deleted. The post Cisco Plugs Gaping Hole in Emergency Responder Software appeared first on SecurityWeek.

New GoldDigger Android Trojan Drains Victim Bank Accounts

05 October 2023
The GoldDigger trojan has been active since at least June 2023 and is currently targeting users of over 50 Vietnamese banking apps, as well as e-wallets and crypto-wallets.

PLAY Ransomware Group Added Six New Organizations to its Victim List

05 October 2023
The organizations targeted by PLAY include Roof Management, Security Instrument Corp, Filtration Control Ltd, Cinépolis Cinemas, CHARMANT Group, and Stavanger Municipality.

Stream-Jacking Attacks on YouTube Steal From Victims via Cryptocurrency Scams

05 October 2023
Attackers redirect victims to scams that involve QR codes and phishing websites promising to double their cryptocurrency investments, often using deep fake videos of Elon Musk to add credibility.

Why Stream-Jacking is Taking Over YouTube: A Comprehensive Analysis

05 October 2023
Stream-jacking attacks on YouTube are increasing, targeting popular channels to spread deceptive content. Cybercriminals hijack these channels, often impersonating famous figures or brands like Elon Musk and Tesla, promoting scams like crypto doubling. Viewers should be cautious of videos with clickbait titles, especially those promoting financial opportunities.

Global CRM Provider Exposed Millions of Clients’ Files Online

05 October 2023
Really Simple Systems exposed a non-password-protected database with over 3 million records, including highly sensitive customer information such as medical records and tax documents.