Latest Cybersecurity News and Articles


Xenomorph Android Malware Reappears in a New Campaign Targeting U.S. Banks

27 September 2023
A new Xenomorph malware campaign was detected in August 2023. It appears to have widened its target scope, including financial institutions and crypto-wallet apps, with each sample aiming at over 100 different targets. This Android malware leverages its Automated Transfer System for versatile actions based on specific conditions. With the emergence of this variant, researchers anticipate more attacks in the future.

ALPHV Ransomware Group Targets Clarion, Phil-Data Business Systems, and MNGI Digestive Health

26 September 2023
The ALPHV ransomware group, also known as the BlackCat hacker collective, has recently targeted three new victims in their cyberattacks. The group has demonstrated adaptability and employed advanced technical methods in their attacks.

Microsoft is Rolling out Support for Passkeys in Windows 11

26 September 2023
Microsoft is officially rolling out support for passkeys in Windows 11 today as part of a major update to the desktop operating system. The feature allows users to login to websites and applications without having to provide a username and password, instead relying on their device PIN or biometric information to complete the step. Based on FIDO standards, Passkeys were first announced in May

Smishing Triad Stretches its Tentacles into the United Arab Emirates

26 September 2023
"Smishing Triad" is leveraging compromised Apple iCloud accounts and illegally obtained databases containing personally identifiable information (PII) to carry out their attacks.

Decade Worth of Newborn Child Registry Data Stolen in MOVEit Hack at BORN Ontario

26 September 2023
The stolen data includes names, addresses, health card numbers, and clinical information related to fertility, pregnancy, newborn, and child healthcare, with potential impacts on individuals from January 2010 to May 2023.

ShadowSyndicate: A New Cybercrime Group Linked to 7 Ransomware Families

26 September 2023
Cybersecurity experts have shed light on a new cybercrime group known as ShadowSyndicate (formerly Infra Storm) that may have leveraged as many as seven different ransomware families over the past year. "ShadowSyndicate is a threat actor that works with various ransomware groups and affiliates of ransomware programs," Group-IB and Bridewell said in a new joint report. The actor, active since

Hackers Actively Exploiting Openfire Flaw to Encrypt Servers

26 September 2023
The flaw, CVE-2023-32315, allows attackers to bypass authentication and create new admin accounts, enabling them to install malicious Java plugins and execute arbitrary code on compromised servers.

Kuwait Isolates Some Government Systems Following Attack on its Finance Ministry

26 September 2023
The attack started on September 18, and officials immediately took steps to isolate and shut down affected systems. The Ministry of Finance assured that payment and payroll systems were on a separate network and that workers would be paid.

Report shows cybersecurity budgets increased 6% for 2022-2023 cycle

26 September 2023
A new report shows despite economic uncertainty and inflation, security budgets generally continued to rise but at a lower rate than prior years.

Stratascale Acquires VECTOR0 To Strengthen Its Cybersecurity Services

26 September 2023
Through the acquisition, Stratascale professionals and their customers gain visibility of attack vectors and points of vulnerability, enhancing Stratascale’s ability to deliver proactive cybersecurity services.

85% of IT anticipate leaving their role due to burnout

26 September 2023
According to a report, a majority of IT security leaders say that stress has caused them and others to make errors that led to data breaches.

ShadowSyndicate Hackers Linked to Multiple Ransomware Operations, 85 Servers

26 September 2023
ShadowSyndicate is believed to be an initial access broker (IAB) or an affiliate working with multiple ransomware operations, including Quantum, Nokoyawa, BlackCat/ALPHV, Clop, Royal, Cactus, and Play, based on evidence found by researchers.

40% of organizations have hybrid cloud environments

26 September 2023
According to a recent report, 75% of respondents are extremely or very concerned about cloud security and 40% have hybrid cloud environments.

Update: Royal Lurked in Dallas’ Systems Weeks Before Ransomware Attack

26 September 2023
The Royal ransomware group infiltrated Dallas' systems, surveilled and exfiltrated data for a month before launching a ransomware attack, causing widespread disruption to critical city services.

75% who didn't report cyber attack to leadership, felt guilty about it

26 September 2023
Research finds 40% of organizations have experienced a cybersecurity incident, yet 48% didn't disclose those incidents to the appropriate authorities.

Sandman APT Brings LuaDream, Targets Telcos in Middle East

26 September 2023
SentinelOne found the Sandman APT group targeting telecommunications companies in the Middle East, Western Europe, and South Asia using a novel backdoor called LuaDream. The researchers noted that the campaign began in August and demonstrates advanced tactics. With this, the Middle East is once again under cyberespionage scrutiny.

Despite Rising Insider Risk Costs, Budgets are Being Wasted in the Wrong Places

26 September 2023
The cost of insider risks for organizations is at an all-time high, with the average annual cost reaching $16.2 million, a 40% increase in four years, according to DTEX Systems.

Chinese Hackers TAG-74 Targets South Korean Organizations in a Multi-Year Campaign

26 September 2023
Social engineering attacks mounted by the adversary make use of Microsoft CHM file lures to drop a custom variant of an open-source Visual Basic Script backdoor called ReVBShell, which subsequently serves to deploy the Bisonal remote access trojan.

Security leaders weigh in on latest MOVEit data breach

26 September 2023
A U.S. educational nonprofit has announced that nearly 900 schools using the organization’s services may have been affected by a recent data breach.

Essential Guide to Cybersecurity Compliance

26 September 2023
SOC 2, ISO, HIPAA, Cyber Essentials – all the security frameworks and certifications today are an acronym soup that can make even a compliance expert’s head spin. If you’re embarking on your compliance journey, read on to discover the differences between standards, which is best for your business, and how vulnerability management can aid compliance. What is cybersecurity compliance?