Latest Cybersecurity News and Articles


Update: Mass Exploitation Attempts Against WS_FTP Have Begun

02 October 2023
Progress Software released fixes for eight vulnerabilities in WS_FTP, including one with a maximum severity score, but evidence of exploitation was discovered shortly after.

LUCR-3 aka Scattered Spider Getting SaaS-y in the Cloud

02 October 2023
LUCR-3 is a financially motivated attacker that targets Fortune 2000 companies, using compromised credentials and leveraging SaaS applications to steal Intellectual Property for extortion.

How Should Organizations Navigate the Risks and Opportunities of AI?

02 October 2023
As AI technology evolves rapidly, organizations need to stay vigilant, monitor the AI landscape, and adapt their cybersecurity programs to effectively defend against new threats posed by cybercriminals.

UK Royal Family Website Taken Down by DDoS Attack

02 October 2023
According to reports, the official website of the UK’s royal family was taken offline by a DDoS attack on Sunday. The Royal.uk site was unavailable for around 90 minutes, starting at 10 am local time, according to The Independent.

AWS Using MadPot Decoy System to Disrupt APTs, Botnets

02 October 2023
Cloud computing giant AWS says an internal threat intel decoy system called MadPot has been used successfully to trap malicious activity, including nation-state-backed APTs like Volt Typhoon and Sandworm.

Update: Recently Patched TeamCity Vulnerability Exploited to Hack Servers

02 October 2023
In-the-wild exploitation of a critical vulnerability in JetBrains’ TeamCity continuous integration and continuous deployment (CI/CD) server started just days after the availability of a patch was announced.

Cybersecurity Budgets Show Moderate Growth

02 October 2023
According to research from IANS and Artico Search, security budgets as a share of IT budgets are increasing, indicating a moderate impact on security spending compared to overall IT spending.

Government shutdown averted: What security leaders can learn

02 October 2023
Here security leaders discuss what a government shutdown would mean for security professionals and how it could affect the security industry.

New LostTrust Ransomware is a Likely Rebrand of the MetaEncryptor Gang

02 October 2023
The LostTrust encryptor disables various Windows services and appends the ".losttrustencoded" extension to encrypted files, with ransom demands ranging from $100,000 to millions.

Financial Crime Compliance Costs Exceed $206 Billion

02 October 2023
AI and advanced analytics are being employed by 72% of financial crime professionals to enhance compliance procedures, but challenges such as data quality and legacy systems persist, according to LexisNexis Risk Solutions.

LUCR-3: Scattered Spider Getting SaaS-y in the Cloud

02 October 2023
LUCR-3 overlaps with groups such as Scattered Spider, Oktapus, UNC3944, and STORM-0875 and is a financially motivated attacker that leverages the Identity Provider (IDP) as initial access into an environment with the goal of stealing Intellectual Property (IP) for extortion. LUCR-3 targets Fortune 2000 companies across various sectors, including but not limited to Software, Retail, Hospitality,

APIs: Unveiling the Silent Killer of Cyber Security Risk Across Industries

02 October 2023
Introduction In today's interconnected digital ecosystem, Application Programming Interfaces (APIs) play a pivotal role in enabling seamless communication and data exchange between various software applications and systems. APIs act as bridges, facilitating the sharing of information and functionalities. However, as the use of APIs continues to rise, they have become an increasingly attractive

Silent Skimmer: A Year-Long Web Skimming Campaign Targeting Online Payment Businesses

02 October 2023
A financially motivated campaign has been targeting online payment businesses in the Asia Pacific, North America, and Latin America with web skimmers for more than a year. The BlackBerry Research and Intelligence Team is tracking the activity under the name Silent Skimmer, attributing it to an actor who is knowledgeable in the Chinese language. Prominent victims include online businesses and

Ransomware Attack Leads to Payroll Issues at 21 Pinal County School Districts

02 October 2023
Efforts are underway to restore access to data and distribute paychecks, with some school districts providing emergency loans and food assistance to affected staff members.

Phishing, Smishing Surge Targets USPS

02 October 2023
Recent weeks have witnessed a significant increase in cyberattacks targeting the US Postal Service (USPS), mainly through phishing and smishing campaigns, according to DomainTools researchers who shared their findings in an advisory last week.

Russian Company Offers $20m For Non-NATO Mobile Exploits

02 October 2023
The Russian firm Operation Zero unveiled this increased payout on X (formerly Twitter) last week, aiming to attract top-tier researchers and developer teams to collaborate with their platform.

Norway Wants Europe-Wide Ban on Facebook Behavioral Ads

02 October 2023
Norway is urging the European Data Protection Board (EDPB) to ban Meta (formerly Facebook) from harvesting user data for advertising purposes permanently and extend the ban across Europe.

UK Privacy Regulator Orders End to Spreadsheet FOI Responses

02 October 2023
The UK's data protection regulator issued an advisory notice to all public authorities in the wake of a hugely damaging leak at the Police Service of Northern Ireland (PSNI) last month.

Post-Quantum Cryptography: Finally Real in Consumer Apps?

02 October 2023
Post-quantum cryptography (PQC) offers a solution by providing algorithms that are resistant to both classical and quantum computer attacks, ensuring the security of data in a quantum computing era.

OpenRefine's Zip Slip Vulnerability Could Let Attackers Execute Malicious Code

02 October 2023
Tracked as CVE-2023-37476 (CVSS score: 7.8), the vulnerability is a Zip Slip vulnerability that could have adverse impacts when importing a specially crafted project in versions 3.7.3 and below.