Latest Cybersecurity News and Articles


OpenRefine's Zip Slip Vulnerability Could Let Attackers Execute Malicious Code

02 October 2023
A high-severity security flaw has been disclosed in the open-source OpenRefine data cleanup and transformation tool that could result in arbitrary code execution on affected systems. Tracked as CVE-2023-37476 (CVSS score: 7.8), the vulnerability is a Zip Slip vulnerability that could have adverse impacts when importing a specially crafted project in versions 3.7.3 and below. "Although OpenRefine

New BunnyLoader Malware-as-a-Service Threat Emerges in the Cybercrime Underground

02 October 2023
The BunnyLoader malware incorporates anti-sandbox and antivirus evasion techniques and has been continuously developed since September 2023, with updates addressing critical flaws.

Study Reveals Conti Affiliates Money Laundering Practices

02 October 2023
Contrary to the popular notion that ransomware hackers are sophisticated launderers of their stolen money, research shows they use straightforward mechanisms to transfer their bitcoin - allowing researchers to follow their money trail.

BunnyLoader: New Malware-as-a-Service Threat Emerges in the Cybercrime Underground

02 October 2023
Cybersecurity experts have discovered yet another malware-as-a-service (MaaS) threat called BunnyLoader that's being advertised for sale on the cybercrime underground. "BunnyLoader provides various functionalities such as downloading and executing a second-stage payload, stealing browser credentials and system information, and much more," Zscaler ThreatLabz researchers Niraj Shivtarkar and

Zanubis Android Banking Trojan Poses as Peruvian Government App to Target Users

02 October 2023
An emerging Android banking trojan called Zanubis is now masquerading as a Peruvian government app to trick unsuspecting users into installing the malware. "Zanubis's main infection path is through impersonating legitimate Peruvian Android applications and then tricking the user into enabling the Accessibility permissions in order to take full control of the device," Kaspersky said in an

A Closer Look at the Snatch Data Ransom Group

30 September 2023
Earlier this week, KrebsOnSecurity revealed that the darknet website for the Snatch ransomware group was leaking data about its users and the crime gang's internal operations. Today, we'll take a closer look at the history of Snatch, its alleged founder, and their claims that everyone has confused them with a different, older ransomware group by the same name.

FBI Warns of Rising Trend of Dual Ransomware Attacks Targeting U.S. Companies

30 September 2023
The U.S. Federal Bureau of Investigation (FBI) is warning of a new trend of dual ransomware attacks targeting the same victims, at least since July 2023. "During these attacks, cyber threat actors deployed two different ransomware variants against victim companies from the following variants: AvosLocker, Diamond, Hive, Karakurt, LockBit, Quantum, and Royal," the FBI said in an alert. "Variants

Iranian APT Group OilRig Using New Menorah Malware for Covert Operations

30 September 2023
Sophisticated cyber actors backed by Iran known as OilRig have been linked to a spear-phishing campaign that infects victims with a new strain of malware called Menorah. "The malware was designed for cyberespionage, capable of identifying the machine, reading and uploading files from the machine, and downloading another file or malware," Trend Micro researchers Mohamed Fahmy and Mahmoud Zohdy 

Researchers Extract Sounds From Still Images on Smartphone Cameras

30 September 2023
A group of academic researchers has devised a technique to extract sounds from still images captured using smartphone cameras with rolling shutters and movable lens structures.

Large Michigan Healthcare Provider Confirms Ransomware Attack

30 September 2023
McLaren HealthCare, one of the largest healthcare systems in Michigan, has confirmed a ransomware attack, potentially impacting patient data and causing disruptions in their computer network.

New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks

30 September 2023
The Exim maintainers and the Zero Day Initiative (ZDI) have experienced delays and communication issues in addressing these vulnerabilities, raising concerns about the handling of security flaws in widely used software.

FBI Warns Energy Sector of Likely Increase in Targeting by Chinese, Russian Hackers

30 September 2023
The FBI warns that changes in the global energy supply, including US exports of liquefied natural gas and shifts in the crude oil supply chain, are likely to boost the targeting of critical energy infrastructure by Chinese and Russian hackers.

APT34 Deploys Phishing Attack With New Menorah Malware

30 September 2023
The Menorah malware is designed for cyberespionage and possesses capabilities such as machine identification, file reading and uploading, shell command execution, and file downloading.

CISA Warns of Old JBoss RichFaces Vulnerability Being Exploited in Attacks

30 September 2023
The flaw, tracked as CVE-2018-14667, was added by CISA on Thursday to its Known Exploited Vulnerabilities (KEV) Catalog, with federal agencies being instructed to apply mitigations or discontinue the use of the product by October 19.

New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks

30 September 2023
Multiple security vulnerabilities have been disclosed in the Exim mail transfer agent that, if successfully exploited, could result in information disclosure and remote code execution. The list of flaws, which were reported anonymously way back in June 2022, is as follows - CVE-2023-42114 (CVSS score: 3.7) - Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability

Cybercriminals Using New ASMCrypt Malware Loader Flying Under the Radar

29 September 2023
Threat actors are selling a new crypter and loader called ASMCrypt, which has been described as an "evolved version" of another loader malware known as DoubleFinger. "The idea behind this type of malware is to load the final payload without the loading process or the payload itself being detected by AV/EDR, etc.," Kaspersky said in an analysis published this week. DoubleFinger was first

City of Fort Lauderdale, Florida, Taken for $1.2m in Email Scam

29 September 2023
The payment, intended for a new police headquarters building, was made to a scammer who posed as the legitimate contractor, Moss Construction. The incident underscores the need for increased cybersecurity measures against business email compromise.

What Happens to Government Devices During a Shutdown?

29 September 2023
Government-issued devices face heightened security risks during a federal shutdown, as furloughed employees are typically restricted from using them, leaving networks and devices vulnerable.

Lazarus APT Lures Employees of Spanish Aerospace Company with Trojanized Coding Challenges

29 September 2023
The attack involved the deployment of a sophisticated backdoor called LightlessCan, which mimics native Windows commands and implements techniques to avoid detection by security monitoring software.

FBI Warns Organizations of Dual Ransomware, Wiper Attacks

29 September 2023
As part of this trend, which was observed in July 2023, the FBI notes in a new private industry notification, threat actors deploy two ransomware variants in close date proximity to one another.