Latest Cybersecurity News and Articles


New GPU Side-Channel Attack Allows Malicious Websites to Steal Data

27 September 2023
The new attack method, named GPU.zip, was discovered and detailed by representatives of the University of Texas at Austin, Carnegie Mellon University, University of Washington, and University of Illinois Urbana-Champaign.

DarkBeam Leaks Billions of Credentials via Unsecured Elasticsearch and Kibana Interface

27 September 2023
The leaked data, including email and password pairs, provides cybercriminals with almost limitless attack capabilities, making affected users vulnerable to targeted phishing campaigns.

CISA releases HBOM framework for supply chain risk management

27 September 2023
The CISA released the new Hardware Bill of Materials Framework for Supply Chain Risk Management product from the Information and Communications Technology Supply Chain Risk Management Task Force.

‘Snatch’ Ransom Group Exposes Visitor IP Addresses

27 September 2023
The victim shaming site operated by the Snatch ransomware group is leaking data about its true online location and internal operations, as well as the Internet addresses of its visitors, KrebsOnSecurity has found. The leaked data suggest that Snatch is one of several ransomware groups using paid ads on Google.com to trick people into installing malware disguised as popular free software, such as Microsoft Teams, Adobe Reader, Mozilla Thunderbird, and Discord.

New Survey Uncovers How Companies Are Confronting Data Security Challenges Head-On

27 September 2023
Data security is in the headlines often, and it’s almost never for a positive reason. Major breaches, new ways to hack into an organization’s supposedly secure data, and other threats make the news because well, it’s scary — and expensive.  Data breaches, ransomware and malware attacks, and other cybercrime might be pricey to prevent, but they are even more costly when they occur, with the 

New AtlasCross Hackers Use American Red Cross as Phishing Lure

27 September 2023
The group's malware includes trojans named DangerAds and AtlasAgent, with AtlasAgent being a custom C++ trojan that can execute various commands and evade detection by security tools.

Ukraine Cyber Defenders Prepare for Winter

27 September 2023
Ukrainian cyber defenders are girding for an onslaught of cyberattacks against energy and other critical infrastructure sectors as cold weather returns to the country, currently in its second year of fending off a Russian war of conquest.

Philippines State Health Organization Struggling to Recover From Ransomware Attack

27 September 2023
The Philippine Health Insurance Corporation (PhilHealth), which manages the country's universal healthcare system, has been hit by a ransomware attack. The incident forced the organization to shut down several websites and portals.

Pension Firms Report 4000% Surge in Breaches

27 September 2023
Pension providers reported a staggering quadruple-digit percentage increase in data breaches to the UK regulator last year, according to new data compiled by professional services firm RPC.

UK Logistics Firm Blames Ransomware Attack for Insolvency, 730 Redundancies

27 September 2023
The attack affected key systems and financial information, making it difficult for the company to secure investment and funding, ultimately leading to job losses for hundreds of employees.

Half of Cyberattacks Go Unreported

27 September 2023
A global survey by Keeper Security highlighted the shortcomings in reporting cyberattacks and breaches. It found that 40% of IT and security leaders had experienced a cyberattack, while 74% were concerned about future cybersecurity disasters.

Polish Privacy Regulator Probes OpenAI's ChatGPT

27 September 2023
The complainant alleges that ChatGPT generated false information about them and that OpenAI failed to address their concerns regarding the processing of their personal data, violating GDPR requirements.

New ZenRAT Malware Targeting Windows Users via Fake Password Manager Software

27 September 2023
A new malware strain called ZenRAT has emerged in the wild that's distributed via bogus installation packages of the Bitwarden password manager. "The malware is specifically targeting Windows users and will redirect people using other hosts to a benign web page," enterprise security firm Proofpoint said in a technical report. "The malware is a modular remote access trojan (RAT) with information

Tech Giants Launch Post-Quantum Cryptography Coalition

27 September 2023
The PQC Coalition features Microsoft, IBM Quantum, MITRE, PQShield, SandboxAQ, and the University of Waterloo among its founding members. The goal will be to improve the uptake of PQC in commercial and open-source technologies.

Update: Sony Investigating After Hackers Offer to Sell Stolen Data

27 September 2023
The majority of the leaked files seem to originate from servers associated with Creators Cloud, and the hackers have not provided evidence that all Sony systems have been compromised.

Microsoft Brings Passkeys, Bad Code Protection to Windows 11

27 September 2023
Microsoft updated Windows 11 on Tuesday to simplify passwordless adoption, protect against malicious code, and have the ability to refresh configuration in the event of tampering.

Critical libwebp Vulnerability Under Active Exploitation - Gets Maximum CVSS Score

27 September 2023
The vulnerability in libwebp, which stems from an issue in the Huffman coding algorithm, can result in out-of-bounds data writing to the heap when processing specially crafted WebP lossless files.

CommonSpirit Details Financial Fallout of $160M Cyberattack

27 September 2023
The cyberattack on the entity on October 2, 2022, resulted in about $160 million in damages, including lost revenue, remediation costs, and related expenses, not counting insurance recoveries, according to CommonSpirit.

New ZeroFont Phishing Tricks Outlook Into Showing Fake AV-Scans

27 September 2023
The ZeroFont phishing technique exploits flaws in AI and natural language processing systems to insert hidden words or characters in emails, evading security filters and tricking recipients.

Critical libwebp Vulnerability Under Active Exploitation - Gets Maximum CVSS Score

27 September 2023
Google has assigned a new CVE identifier for a critical security flaw in the libwebp image library for rendering images in the WebP format that has come under active exploitation in the wild. Tracked as CVE-2023-5129, the issue has been given the maximum severity score of 10.0 on the CVSS rating system. It has been described as an issue rooted in the Huffman coding algorithm - With a specially