Latest Cybersecurity News and Articles


Motel One Group discloses data breach

03 October 2023
The Motel One Group announced that the company was the target of a cyberattack affecting address data and customer credit card information.

81% of security leaders say that API security is a higher priority

03 October 2023
According to a recent Noname Security report, API security is more of a priority for 81% of security leaders than it was 12 months ago.

Qualcomm Releases Patch for 3 new Zero-Days Under Active Exploitation

03 October 2023
Chipmaker Qualcomm has released security updates to address 17 vulnerabilities in various components, while warning that three other zero-days have come under active exploitation. Of the 17 flaws, three are rated Critical, 13 are rated High, and one is rated Medium in severity. "There are indications from Google Threat Analysis Group and Google Project Zero that CVE-2023-33106, CVE-2023-33107,

Microsoft Edge, Teams Get Fixes for Zero-Days in Open-Source Libraries

03 October 2023
The vulnerabilities are caused by heap buffer overflow weaknesses in open-source libraries used by the products, and they can lead to crashes or arbitrary code execution.

Warning: PyTorch Models Vulnerable to Remote Code Execution via ShellTorch

03 October 2023
Cybersecurity researchers have disclosed multiple critical security flaws in the TorchServe tool for serving and scaling PyTorch models that could be chained to achieve remote code execution on affected systems. Israel-based runtime application security company Oligo, which made the discovery, has coined the vulnerabilities ShellTorch. "These vulnerabilities [...] can lead to a full chain Remote

US Executives Targeted in Phishing Attacks Exploiting Flaw in Indeed Job Platform

03 October 2023
A recent phishing campaign has exploited an open redirection vulnerability in the popular job search platform Indeed, targeting executives in senior roles to steal their Microsoft credentials.

Lorenz Ransomware Group Attacks Allcare Pharmacy in Major Cyber Assault

03 October 2023
The Allcare Pharmacy data breach, claimed by the Lorenz ransomware group, has exposed sensitive customer information, including Social Security Numbers, raising concerns about data security and patient privacy in the healthcare sector.

Hackers Seen Exploiting Bugs in Browsers and Popular File Transfer Tool

03 October 2023
The Cybersecurity and Infrastructure Security Agency (CISA) warned on Monday that hackers are exploiting CVE-2023-5217 — a vulnerability affecting Google Chrome, Mozilla Firefox, and more.

Over 3 Dozen Data-Stealing Malicious npm Packages Found Targeting Developers

03 October 2023
Nearly three dozen counterfeit packages have been discovered in the npm package repository that are designed to exfiltrate sensitive data from developer systems, according to findings from Fortinet FortiGuard Labs. One set of packages – named @expue/webpack, @expue/core, @expue/vue3-renderer, @fixedwidthtable/fixedwidthtable, and @virtualsearchtable/virtualsearchtable – harbored an obfuscated

New Wave of Mirai Botnet Variants Like hailBot, kiraiBot, and catDDoS Mount a Fierce Onslaught

03 October 2023
These variants utilize different tactics such as modifying go-live processes, introducing new encryption algorithms, and incorporating OpenNIC domains to evade detection and enhance their malicious activities.

Android’s October 2023 Security Updates Patch Two Exploited Vulnerabilities

03 October 2023
Google on Monday announced the release of patches for 51 vulnerabilities as part of the October 2023 security updates for Android, including fixes for two zero-day flaws exploited in malicious attacks.

Medusa Ransomware Group Claims Intrusions at Two New Victims, Sets Ransom Deadline

03 October 2023
The Medusa ransomware group has recently targeted two companies, Karam Chand Thapar & Bros. (Coal Sales) Ltd in India and the Sweden-based Windak Group, demanding significant ransoms for the release of encrypted data.

Update: Some Prospect Medical Hospitals in Dire State, Post-Attack

03 October 2023
The hospitals are facing financial difficulties and are struggling to pay vendors. This incident highlights the vulnerability of financially unstable hospitals to cyberattacks and the potential risks to patient care.

BlackCat Ransomware Gang Allegedly Stole Over 24 Million Files From Motel One

03 October 2023
Motel One has been given a five-day deadline to pay the ransom or risk the public release of the stolen data, which would result in significant reputational and legal consequences for the company.

CISA kicks off 20th Cybersecurity Awareness Month

03 October 2023
Cybersecurity and Infrastructure Security Agency announced the kickoff of the 20th Cybersecurity Awareness Month.

API Security Trends 2023 – Have Organizations Improved their Security Posture?

03 October 2023
APIs, also known as application programming interfaces, serve as the backbone of modern software applications, enabling seamless communication and data exchange between different systems and platforms. They provide developers with an interface to interact with external services, allowing them to integrate various functionalities into their own applications. However, this increased reliance on

Protecting your IT infrastructure with Security Configuration Assessment (SCA)

03 October 2023
Security Configuration Assessment (SCA) is critical to an organization's cybersecurity strategy. SCA aims to discover vulnerabilities and misconfigurations that malicious actors exploit to gain unauthorized access to systems and data. Regular security configuration assessments are essential in maintaining a secure and compliant environment, as this minimizes the risk of cyber attacks. The

Global Events Fuel DDoS Attack Campaigns

03 October 2023
Cybercriminals launched around 7.9 million DDoS attacks in the first half of 2023, a 31% increase compared to the previous year, according to NETSCOUT. These attacks have been driven by global events such as the Russia-Ukraine war and NATO bids.

FDA Cyber Mandates for Medical Devices Goes Into Effect

03 October 2023
New FDA regulations require medical device vendors to enhance security features and address vulnerabilities, aiming to reduce the risk of compromised devices reaching consumers.

Chalk: Open-Source Software Security and Infrastructure Visibility Tool

03 October 2023
Chalk offers convenience for compliance by producing SBOMs, embedding code provenance details and digitally signing reports, addressing regulatory requirements, and saving costs on unnecessary tools licenses.