Latest Cybersecurity News and Articles


Threats in Cloud Top List of Executive Cyber Concerns, Pwc Finds

05 October 2023
Despite the focus on cloud security, many organizations still have risk management lapses, such as not addressing disaster recovery and backup with their cloud service provider.

Operation Jacana Targets Governmental Entity in Guyana with DinodasRAT

05 October 2023
While the specific APT group behind the campaign could not be identified, there is medium confidence that it is a China-aligned threat group based on the use of a variant of Korplug, which is commonly associated with such groups.

GitHub Improves Secret Scanning Feature With Expanded Token Validity Checks

05 October 2023
GitHub beefs up its secret scanning feature, now allowing users to check the validity of exposed credentials for major cloud services. The post GitHub Improves Secret Scanning Feature With Expanded Token Validity Checks appeared first on SecurityWeek.

Scammers Impersonate Companies to Steal Cryptocurrency From Job Seekers

05 October 2023
Dubbed “WebWyrm” by CloudSEK, the operation has already targeted more than 100,000 individuals across over 50 countries by impersonating over 1000 companies across 10 industries. It has already potentially netted the scammers over $100m.

False Amazon callers one of the top phone scams in 2023

05 October 2023
Phone call fraud and spam callers were analyzed in a recent report by Hiya, finding Amazon impersonation scams in the top scams of 2023.

North Korean Hackers Target South Korean Naval Shipyards

05 October 2023
South Korea's National Intelligence Service said it is notifying shipbuilders of threats to their systems and networks and advising major shipyards to conduct independent security audits to plug security holes in digital infrastructure.

Cyber Mavens Slam Europe's Cyber Resilience Act

05 October 2023
According to some experts, the proposed EU mandate for software publishers to disclose zero-day exploits within 24 hours risks compromising cybersecurity efforts by giving government agencies access to a real-time database of vulnerabilities.

AWS Kicks off Cloud Race to Mandate MFA by Default

05 October 2023
The move towards MFA by default aligns with the push for secure-by-default tactics recommended by cyber authorities and highlights the shared responsibility model in cloud security.

Microsoft Warns of Cyberattacks Attempting to Breach Cloud via SQL Server Instance

05 October 2023
The attackers exploited a SQL injection vulnerability in an application, allowing them to gain access and elevated permissions on a Microsoft SQL Server instance deployed in an Azure Virtual Machine.

Red Cross Releases Wartime Hacktivist Rules

05 October 2023
Writing in the European Journal of International Law (EJIL), the ICRC warned that cyberattacks by civilians during wartime are causing disruption to non-military targets such as hospitals, pharmacies, and banks – impacting innocent civilians.

Attacker Deployed Hundreds of Rogue Python Packages with 75,000 Downloads to Steal Sensitive Data

05 October 2023
The malicious packages aim to steal sensitive data from systems, applications, browsers, and users. They also target cryptocurrency users by redirecting transactions to the attacker's account.

Coalition to give NGOs free access to cybersecurity services to protect against attacks

05 October 2023
The CyberPeace Institute, in collaboration with other organizations, will establish a portal to provide free training and support to help NGOs in the Netherlands enhance their cybersecurity resilience.

QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks

05 October 2023
Despite the disruption to its infrastructure, the threat actors behind the QakBot malware have been linked to an ongoing phishing campaign since early August 2023 that led to the delivery of Ransom Knight (aka Cyclops) ransomware and Remcos RAT. This indicates that “the law enforcement operation may not have impacted Qakbot operators’ spam delivery infrastructure but rather only their

Report: Ransomware dwell time hits low of 24 hours

05 October 2023
Analysis from new annual report shows ransomware median dwell time has dropped from 4.5 days to less than 24 hours in a year.

Banned Applications Used as a Lure to Target Russian Users

05 October 2023
Cyble identifies a phishing campaign targeting Russians with fake sites for ExpressVPN, WeChat, and Skype. Criminals aim to deliver a RMS, gain initial access, and deploy malware. Researchers cite that TA505 might be behind this campaign. It is recommended to implement application whitelisting to restrict the execution of unknown or unapproved applications. 

Cisco Releases Urgent Patch to Fix Critical Flaw in Emergency Responder Systems

05 October 2023
Cisco has released updates to address a critical security flaw impacting Emergency Responder that allows unauthenticated, remote attackers to sign into susceptible systems using hard-coded credentials. The vulnerability, tracked as CVE-2023-20101 (CVSS score: 9.8), is due to the presence of static user credentials for the root account that the company said is usually reserved for use during

Cyberattacks in Arizona, Missouri Limit Access to Community Services

05 October 2023
The limited access to patient information systems and critical tools used by doctors due to cyberattacks can have detrimental effects on patient care, potentially costing lives.

Analysis and Config Extraction of Lu0Bot, a Node.js Malware with Considerable Capabilities

05 October 2023
Nowadays, more malware developers are using unconventional programming languages to bypass advanced detection systems. The Node.js malware Lu0Bot is a testament to this trend. By targeting a platform-agnostic runtime environment common in modern web apps and employing multi-layer obfuscation, Lu0Bot is a serious threat to organizations and individuals. Although currently, the malware has low

Guyana Governmental Entity Hit by DinodasRAT in Cyber Espionage Attack

05 October 2023
A governmental entity in Guyana has been targeted as part of a cyber espionage campaign dubbed Operation Jacana. The activity, which was detected by ESET in February 2023, entailed a spear-phishing attack that led to the deployment of a hitherto undocumented implant written in C++ called DinodasRAT. The Slovak cybersecurity firm said it could link the intrusion to a known threat actor or group,

Google and Yahoo Say They Will Crack Down on Spam With New Measures

05 October 2023
Yahoo will implement rules requiring all bulk senders to use robust email authentication, while also pushing for one-click unsubscribe options. Google will require bulk senders to validate their identities and strongly authenticate their emails.