Latest Cybersecurity News and Articles


Google Releases Patch for Actively Exploited Zero-Day Vulnerability in Chrome

28 September 2023
Tracked as CVE-2023-5217, the high-severity vulnerability has been described as a heap-based buffer overflow in the VP8 compression format in libvpx, a free software video codec library from Google and the Alliance for Open Media (AOMedia).

Threat Actors Exploit the Tensions Between Azerbaijan and Armenia

28 September 2023
A spearphishing campaign targeting management teams associated with an Azerbaijanian company exploits the conflict between Azerbaijan and Armenia, using malware disguised as an infected memo to gather basic computer information from its targets.

Researchers Release Details of New RCE Exploit Chain for SharePoint

28 September 2023
Attackers can exploit a couple of vulnerabilities, tracked as CVE-2023-29357 and CVE-2023-24955, to gain admin privileges, execute arbitrary code, and potentially cause denial of service attacks or compromise sensitive data.

Firefox 118 Patches High-Severity Vulnerabilities

28 September 2023
The vulnerabilities in Firefox include out-of-bounds write issues, memory leaks, use-after-free conditions, and memory corruption, which could potentially allow attackers to execute arbitrary code or cause crashes.

Gem Security Raises $23M for Its Cloud Security Platform

28 September 2023
The cloud security company raised $23 million in a Series A funding round led by GGV Capital, with participation from IBM Ventures, Team8, and Silicon Valley CISO Investments.

Update Chrome Now: Google Releases Patch for Actively Exploited Zero-Day Vulnerability

27 September 2023
Google on Wednesday rolled out fixes to address a new actively exploited zero-day in the Chrome browser. Tracked as CVE-2023-5217, the high-severity vulnerability has been described as a heap-based buffer overflow in the VP8 compression format in libvpx, a free software video codec library from Google and the Alliance for Open Media (AOMedia). Exploitation of such buffer overflow flaws can

Github Repositories Bombarded by Info-Stealing Commits Masked as Dependabot

27 September 2023
The attack involves creating fake commit messages titled "fix" to introduce malware that extracts secrets from targeted repositories and steals passwords from web-form submissions.

ShadowSyndicate: New RaaS Connected to Multiple Ransomware Families

27 September 2023
Researchers have discovered the infrastructure linked to a threat group called ShadowSyndicate, believed to have launched attacks using seven distinct ransomware families in the last year. ShadowSyndicate has been identified as using a consistent SSH fingerprint across 85 servers.

Newly Discovered ZenRAT Malware Targets Windows Users

27 September 2023
A new malware strain called ZenRAT has emerged in the wild to steal information from Windows systems. It was initially discovered on a website pretending to be associated with the open-source password manager Bitwarden. People should be wary of ads in search engine results as they remain a major driver of malware infection.

Creating an impactful culture in remote work environment

27 September 2023
Jim Barkdoll, CEO at Axiomatics, discusses what initiatives or strategies organizations can utilize to build or maintain an impactful culture in a remote work environment, and more.

Red Cross-Themed Phishing Attacks Distributing DangerAds and AtlasAgent Backdoors

27 September 2023
A new threat actor known as AtlasCross has been observed leveraging Red Cross-themed phishing lures to deliver two previously undocumented backdoors named DangerAds and AtlasAgent. NSFOCUS Security Labs described the adversary as having a "high technical level and cautious attack attitude," adding that "the phishing attack activity captured this time is part of the attacker's targeted strike on

Attacks on EMEA Financial Services Double in a Year

27 September 2023
A new report from Akamai revealed that financial services organizations in the EMEA region suffered around one billion web app and API attacks during the period, with insurance the most attacked sub-sector, accounting for 55% of all web attacks.

CISA Publishes Hardware Bill of Materials Framework

27 September 2023
The US Cybersecurity and Infrastructure Security Agency (CISA) has published new guidance designed to improve the accuracy of risk assessments related to hardware products in the supply chain.

40% of U.S. security leaders cite malware as threat focus

27 September 2023
According to a report from CompTIA, cybersecurity leaders struggle with conflicting challenges and interests when it comes to prioritizing threats.

The CISO Carousel and its Effect on Enterprise Cybersecurity

27 September 2023
CISOs often face being used as scapegoats for security incidents, leading to high turnover rates in the role. Lack of board support and prioritization of cybersecurity contributes to CISO churn.

Canadian Flair Airlines Leaked MySQL Database Credentials, SMTP Configs, and Other Sensitive Data

27 September 2023
The leak consisted of publicly accessible environment files hosted on the airline's website. It included MySQL database credentials, SMTP configuration, and other sensitive information, potentially allowing unauthorized access and phishing attacks.

Voting Equipment Giants Team Up For Security

27 September 2023
While certified election systems are regularly tested, this represents the first time that manufacturers have voluntarily opened their systems to third-party scrutiny as part of a vulnerability disclosure process.

Researchers Uncover New GPU Side-Channel Vulnerability Leaking Sensitive Data

27 September 2023
A novel side-channel attack called GPU.zip renders virtually all modern graphics processing units (GPU) vulnerable to information leakage. "This channel exploits an optimization that is data dependent, software transparent, and present in nearly all modern GPUs: graphical data compression," a group of academics from the University of Texas at Austin, Carnegie Mellon University, University of

New GPU Side-Channel Attack Allows Malicious Websites to Steal Data

27 September 2023
The new attack method, named GPU.zip, was discovered and detailed by representatives of the University of Texas at Austin, Carnegie Mellon University, University of Washington, and University of Illinois Urbana-Champaign.

DarkBeam Leaks Billions of Credentials via Unsecured Elasticsearch and Kibana Interface

27 September 2023
The leaked data, including email and password pairs, provides cybercriminals with almost limitless attack capabilities, making affected users vulnerable to targeted phishing campaigns.