Latest Cybersecurity News and Articles
27 September 2023
A new Xenomorph malware campaign was detected in August 2023. It appears to have widened its target scope, including financial institutions and crypto-wallet apps, with each sample aiming at over 100 different targets. This Android malware leverages its Automated Transfer System for versatile actions based on specific conditions. With the emergence of this variant, researchers anticipate more attacks in the future.
26 September 2023
The ALPHV ransomware group, also known as the BlackCat hacker collective, has recently targeted three new victims in their cyberattacks. The group has demonstrated adaptability and employed advanced technical methods in their attacks.
26 September 2023
Microsoft is officially rolling out support for passkeys in Windows 11 today as part of a major update to the desktop operating system.
The feature allows users to login to websites and applications without having to provide a username and password, instead relying on their device PIN or biometric information to complete the step.
Based on FIDO standards, Passkeys were first announced in May
26 September 2023
"Smishing Triad" is leveraging compromised Apple iCloud accounts and illegally obtained databases containing personally identifiable information (PII) to carry out their attacks.
26 September 2023
The stolen data includes names, addresses, health card numbers, and clinical information related to fertility, pregnancy, newborn, and child healthcare, with potential impacts on individuals from January 2010 to May 2023.
26 September 2023
Cybersecurity experts have shed light on a new cybercrime group known as ShadowSyndicate (formerly Infra Storm) that may have leveraged as many as seven different ransomware families over the past year.
"ShadowSyndicate is a threat actor that works with various ransomware groups and affiliates of ransomware programs," Group-IB and Bridewell said in a new joint report.
The actor, active since
26 September 2023
The flaw, CVE-2023-32315, allows attackers to bypass authentication and create new admin accounts, enabling them to install malicious Java plugins and execute arbitrary code on compromised servers.
26 September 2023
The attack started on September 18, and officials immediately took steps to isolate and shut down affected systems. The Ministry of Finance assured that payment and payroll systems were on a separate network and that workers would be paid.
26 September 2023
A new report shows despite economic uncertainty and inflation, security budgets generally continued to rise but at a lower rate than prior years.
26 September 2023
Through the acquisition, Stratascale professionals and their customers gain visibility of attack vectors and points of vulnerability, enhancing Stratascale’s ability to deliver proactive cybersecurity services.
26 September 2023
According to a report, a majority of IT security leaders say that stress has caused them and others to make errors that led to data breaches.
26 September 2023
ShadowSyndicate is believed to be an initial access broker (IAB) or an affiliate working with multiple ransomware operations, including Quantum, Nokoyawa, BlackCat/ALPHV, Clop, Royal, Cactus, and Play, based on evidence found by researchers.
26 September 2023
According to a recent report, 75% of respondents are extremely or very concerned about cloud security and 40% have hybrid cloud environments.
26 September 2023
The Royal ransomware group infiltrated Dallas' systems, surveilled and exfiltrated data for a month before launching a ransomware attack, causing widespread disruption to critical city services.
26 September 2023
Research finds 40% of organizations have experienced a cybersecurity incident, yet 48% didn't disclose those incidents to the appropriate authorities.
26 September 2023
SentinelOne found the Sandman APT group targeting telecommunications companies in the Middle East, Western Europe, and South Asia using a novel backdoor called LuaDream. The researchers noted that the campaign began in August and demonstrates advanced tactics. With this, the Middle East is once again under cyberespionage scrutiny.
26 September 2023
The cost of insider risks for organizations is at an all-time high, with the average annual cost reaching $16.2 million, a 40% increase in four years, according to DTEX Systems.
26 September 2023
Social engineering attacks mounted by the adversary make use of Microsoft CHM file lures to drop a custom variant of an open-source Visual Basic Script backdoor called ReVBShell, which subsequently serves to deploy the Bisonal remote access trojan.
26 September 2023
A U.S. educational nonprofit has announced that nearly 900 schools using the organization’s services may have been affected by a recent data breach.
26 September 2023
SOC 2, ISO, HIPAA, Cyber Essentials – all the security frameworks and certifications today are an acronym soup that can make even a compliance expert’s head spin. If you’re embarking on your compliance journey, read on to discover the differences between standards, which is best for your business, and how vulnerability management can aid compliance.
What is cybersecurity compliance?