Latest Cybersecurity News and Articles


Chalk: Open-Source Software Security and Infrastructure Visibility Tool

03 October 2023
Chalk offers convenience for compliance by producing SBOMs, embedding code provenance details and digitally signing reports, addressing regulatory requirements, and saving costs on unnecessary tools licenses.

Arm Issues Patch for Mali GPU Kernel Driver Vulnerability Amidst Ongoing Exploitation

03 October 2023
The issue, credited to Maddie Stone of Google's Threat Analysis Group (TAG) and Jann Horn of Google Project Zero, has been addressed in Bifrost, Valhall and Arm 5th Gen GPU Architecture Kernel Driver r43p0.

Researcher Reveals New Techniques to Bypass Cloudflare's Firewall and DDoS Protection

03 October 2023
Firewall and distributed denial-of-service (DDoS) attack prevention mechanisms in Cloudflare can be circumvented by exploiting gaps in cross-tenant security controls, defeating the very purpose of these safeguards, it has emerged. "Attackers can utilize their own Cloudflare accounts to abuse the per-design trust-relationship between Cloudflare and the customers' websites, rendering the

Chertoff Group Arm to Buy Trustwave from Singtel for $205M

03 October 2023
The acquisition of Trustwave by The Chertoff Group's affiliate MC2 Security Fund signifies the private equity firm's continued investment in cybersecurity and its recognition of the potential value in Trustwave's offerings.

Virginia School District Open Despite Lockbit Ransomware Attack

03 October 2023
The LockBit ransomware gang claimed responsibility for the attack and demanded an undisclosed ransom, but the impact on student and staff information was minimal, and the school district has remained fully operational.

Exim Patches Three of Six Zero-Day Bugs Disclosed Last Week

03 October 2023
One of the vulnerabilities allows remote unauthenticated attackers to execute code in the context of the service account. The other two vulnerabilities patched include a remote code execution bug and an information disclosure issue.

Cyber Investments on Pace to Reach $215B in 2024: Gartner

03 October 2023
A survey by Moody's reveals that cybersecurity spending has increased by 70% from 2019 to 2023, with organizations allocating a larger share of their technology budgets to cybersecurity.

Update: Clorox Resumes Normal Plant Operations in the Wake of Cyberattack

03 October 2023
The cyberattack has had ripple effects on Clorox's operations, potentially impacting quarterly earnings and allowing rival firms to gain a foothold with consumers. The company is now focusing on ramping up production to replenish inventories.

Malicious Packages Found Hidden in NPM Registry

03 October 2023
Some packages exfiltrate data via webhooks or file-sharing links, while others scan for sensitive files and directories. Users are advised to be cautious and watch for suspicious install scripts.

Arm Issues Patch for Mali GPU Kernel Driver Vulnerability Amidst Ongoing Exploitation

03 October 2023
Arm has released security patches to contain a security flaw in the Mali GPU Kernel Driver that has come under active exploitation in the wild. Tracked as CVE-2023-4211, the shortcoming impacts the following driver versions - Midgard GPU Kernel Driver: All versions from r12p0 - r32p0 Bifrost GPU Kernel Driver: All versions from r0p0 - r42p0 Valhall GPU Kernel Driver: All versions from r19p0 -

FTC warns tax preparation companies against sharing confidential data

02 October 2023
Five tax preparation companies have been warned by the FTC in regards to what information can and can't be shared for outside purposes.

Financial sector sees rise in digital identity verification

02 October 2023
According to a Juniper Research report, the rate of digital identity verification checks is on the rise in response to increased identity theft.

Logic Flaws Let Attackers Bypass Cloudflare's Firewall and DDoS Protection

02 October 2023
Cloudflare has been found to have vulnerabilities in its Firewall and DDoS prevention system. Hackers can exploit these flaws by creating a free Cloudflare account and knowing the IP address of a targeted web server.

Android Banking Trojan Zanubis Evolves to Target Peruvian Users

02 October 2023
The Android banking Trojan Zanubis has taken on a new guise, posing as the official app for the Peruvian governmental organization SUNAT (Superintendencia Nacional de Aduanas y de Administración Tributaria).

Cybercriminals Using New ASMCrypt Malware Loader to Fly Under the Radar

02 October 2023
Threat actors are selling a new crypter and loader called ASMCrypt, which is an evolved version of the DoubleFinger loader. It allows them to build payloads for their campaigns by establishing contact with a backend service over the TOR network.

Hackers Steal User Database From European Telecommunications Standards Body

02 October 2023
ETSI has taken immediate action, involving France's cybersecurity agency, ANSSI, to investigate and fix the vulnerability that led to the attack and has strengthened its IT security procedures.

Healthcare top infrastructure target for cyberattacks

02 October 2023
According to the recent KnowBe4 report, healthcare is the top infrastructure topic for ransomware attacks with an increase in cyberattack frequency.

"Phantom Hacker" Scams Target Senior Citizens and Result in Victims Losing their Life Savings

02 October 2023
The FBI warned about a new scam called the "Phantom Hacker" scam, which is specifically targeting senior citizens. It involves imposters posing as tech support, financial institutions, and government representatives to gain the trust of victims.

Don’t Let Zombie Zoom Links Drag You Down

02 October 2023
Many organizations — including quite a few Fortune 500 firms — have exposed web links that allow anyone to initiate a Zoom video conference meeting as a valid employee. These company-specific Zoom links, which include a permanent user ID number and an embedded passcode, can work indefinitely and expose an organization’s employees, customers or partners to phishing and other social engineering attacks.

National Logistics Portal Leaks Sensitive Data Related to Operations at Indian Ports

02 October 2023
The publicly accessible AWS S3 buckets contained personal data, invoices, and internal documents, potentially disrupting trade and operations of India's ports and leading to significant ransom demands.