Latest Cybersecurity News and Articles


Lazarus APT Lures Employees of Spanish Aerospace Company with Trojanized Coding Challenges

29 September 2023
The attack involved the deployment of a sophisticated backdoor called LightlessCan, which mimics native Windows commands and implements techniques to avoid detection by security monitoring software.

FBI Warns Organizations of Dual Ransomware, Wiper Attacks

29 September 2023
As part of this trend, which was observed in July 2023, the FBI notes in a new private industry notification, threat actors deploy two ransomware variants in close date proximity to one another.

Nexusflow Raises $10.6m to Build Conversational Interface for Security Tools

29 September 2023
By synthesizing data from various security sources and utilizing natural language commands, Nexusflow aims to revolutionize cybersecurity operations by seamlessly interpreting human instructions and providing insights.

Hackers Set Sights on Apache NiFi Flaw That Exposes Many Organizations to Attacks

29 September 2023
“The impact of this vulnerability is severe, as it grants attackers the ability to gain unauthorized access to systems, exfiltrate sensitive data, and execute malicious code remotely,” Cyfirma notes in an analysis of the bug and its exploitation.

Misconfigured AWS Storage Bucket of WSBC Leaks 4,600 Passports

29 September 2023
The World Baseball Softball Confederation (WBSC) left a data repository exposed, including sensitive files such as copies of 4,600 national passports, putting individuals at risk of identity theft and other fraudulent activities.

CISA, NSA, FBI and Japan warn of BlackTech, PRC-linked cyber activity

29 September 2023
CISA has recently published a Joint Cybersecurity Advisory about malicious activity by People’s Republic of China (PRC)-linked cyber actors known as BlackTech.

Security leaders discuss implications as Sony investigates recent cyber attack

29 September 2023
Here, security leaders discuss their thoughts on the most recent alleged Sony attack and what lessons can be learned.

Tech Industry Leaders and White House Clash Over Plan for Improved Cloud Security

29 September 2023
The industry argues that KYC could cost billions of dollars in administrative costs and raise privacy concerns, while sophisticated hackers would easily work around these requirements.

Budworm Strikes Again: Updated SysUpdate Targets Government and Telecom Sectors

29 September 2023
The Budworm APT group is evolving its cyber arsenal. Budworm’s signature technique consists of executing SysUpdate on victims' networks by sideloading the DLL payload using the authentic INISafeWebSSO application - a tactic it has employed since at least 2018. Organizations should proactively update and patch their systems to counter known vulnerabilities exploited by tools like SysUpdate.

Russian Flight Booking System Leonardo Suffers Massive DDoS Attack

29 September 2023
The attack caused delays at airports and affected several Russian air carriers, including Aeroflot. The Ukrainian hacktivist group IT Army claimed responsibility for the attack.

Lazarus Group Impersonates Recruiter from Meta to Target Spanish Aerospace Firm

29 September 2023
The North Korea-linked Lazarus Group has been linked to a cyber espionage attack targeting an unnamed aerospace company in Spain in which employees of the firm were approached by the threat actor posing as a recruiter for Meta. "Employees of the targeted company were contacted by a fake recruiter via LinkedIn and tricked into opening a malicious executable file presenting itself as a coding

Progress Software Says Business Impact ‘Minimal’ From MOVEit Attack Spree

29 September 2023
While the financial consequences for Progress have been minimal so far, potential litigation and class-action lawsuits related to the vulnerability could still have an impact in the future.

Post-Quantum Cryptography: Finally Real in Consumer Apps?

29 September 2023
Most people are barely thinking about basic cybersecurity, let alone post-quantum cryptography. But the impact of a post-quantum world is coming for them regardless of whether or not it's keeping them up tonight.  Today, many rely on encryption in their daily lives to protect their fundamental digital privacy and security, whether for messaging friends and family, storing files and photos, or

Malicious Ads Served Inside Bing's AI Chatbot to Infect Victims with Malware

29 September 2023
Ads are now being inserted into Bing Chat conversations, which poses a risk for users searching for software downloads. Malicious actors can trick users into visiting malicious sites and installing malware.

NSA is Creating a Hub for AI Security, Nakasone Says

29 September 2023
The center will focus on leveraging foreign intelligence insights, developing best practices, and creating risk frameworks to protect against digital attacks and prevent the theft of innovative AI capabilities.

Budworm: APT Group Uses Updated Custom Tool in Attacks on Government and Telecoms Organization

29 September 2023
The Budworm APT group continues to actively develop its toolset, as evidenced by its recent use of an updated version of its SysUpdate backdoor to target organizations in the Middle East and Asia.

Asian Banks are a Favorite Target of Cybercooks, and Malicious Bots Their Preferred Tool

29 September 2023
Asia-Pacific is the second-most targeted region for malicious bot requests against financial services, with global hubs Singapore, Australia, and Japan the region's top three most targeted, accounting for the bulk of web application and API attacks.

Stealing Credentials Through Legitimate Dropbox Pages

29 September 2023
Cybercriminals are using Dropbox to launch phishing attacks. They create a free Dropbox account, share a document with someone, and the recipient receives a legitimate-looking email from Dropbox with a link.

Security Researcher Stopped at US Border for Investigating Crypto Scam

29 September 2023
The researcher's role in investigating the scam led to a grand jury subpoena, highlighting the potential legal risks faced by ethical hackers and defenders involved in similar work.

Booking.com Customers Hit by Phishing Campaign Delivered Via Compromised Hotels Accounts

29 September 2023
The phishing attacks are highly convincing, using personalized messages and a meticulously crafted phishing page that mimics the Booking.com interface, leading victims to unknowingly provide their credit card or bank information.