Latest Cybersecurity News and Articles


UK Security Agency Publishes New Cryptographic Designs

25 September 2023
These designs aim to mitigate risks caused by accidental misuse of cryptography, ensuring cryptographic security is maintained even in the event of significant human error.

Stealth Falcon APT Preying Over Middle Eastern Skies With Deadglyph

25 September 2023
The backdoor does not have traditional commands implemented; instead, it dynamically receives commands from a command and control server in the form of additional modules.

From Watering Hole to Spyware: EvilBamboo Targets Tibetans, Uyghurs, and Taiwanese

25 September 2023
Tibetan, Uyghur, and Taiwanese individuals and organizations are the targets of a persistent campaign orchestrated by a threat actor codenamed EvilBamboo to gather sensitive information. "The attacker has created fake Tibetan websites, along with social media profiles, likely used to deploy browser-based exploits against targeted users," Volexity security researchers Callum Roxan, Paul

CISA Urges Use of Memory Safe Code in Software Development

25 September 2023
The Cybersecurity and Infrastructure Security Agency is urging the software industry to embrace the use of memory safe programming languages as part of a wider effort to eliminate security vulnerabilities in code.

Cato Networks Raises $238M on $3B Valuation to Move Upmarket

25 September 2023
Cato Networks has secured a $238 million equity investment to enhance its SASE platform by integrating CASB and DLP capabilities, catering to the needs of large enterprises.

Gelsemium APT Suspected Behind an Attack on Southeast Asian Government

25 September 2023
A recent report by Palo Alto Networks Unit42 researchers reveals that a stealthy APT group known as Gelsemium likely targeted a Southeast Asian government between 2022 and 2023.

Update: Nova Scotia Says All Victims of MOVEit Breach Have Been Notified

25 September 2023
The security incident highlights the time-consuming process of analyzing stolen data and notifying affected individuals, emphasizing the need for improved cybersecurity measures.

Faster Patching Pace Validates CISA’s KEV Catalog Initiative

25 September 2023
The Known Exploited Vulnerabilities (KEV) Catalog maintained by the US cybersecurity agency CISA has led to significant improvements in federal agencies’ patching efforts, with more than 1,000 vulnerabilities now included in the list.

New Zealand University Operating Despite Cyberattack

25 September 2023
Despite a cyberattack on Auckland University of Technology, the university has been able to continue normal operations with minimal disruption. The Monti ransomware gang claimed responsibility for the attack and demanded an undisclosed ransom.

Hidden Dangers Loom for Subsea Cables, the Invisible Infrastructure of the Internet

25 September 2023
Subsea cables are a critical component of the global internet infrastructure, and protecting them from accidental damage, natural phenomena, physical attacks, and cyberattacks is crucial.

Github Passkeys Generally Available for Passwordless Sign-Ins

25 September 2023
The adoption of passkeys by GitHub, Microsoft, and Google, among other technology giants, demonstrates a growing trend toward using passkeys for secure authentication across platforms.

New Apple Zero-Days Exploited to Target Egyptian ex-MP with Predator Spyware

25 September 2023
Apple recently addressed three zero-day vulnerabilities that were used as part of an iPhone exploit chain in an attempt to deliver spyware called Predator to former Egyptian member of parliament Ahmed Eltantawy.

LockBit, BlackCat, and Clop Prevail as Top RAAS Groups: Ransomware in First Half of 2023

25 September 2023
In the first half of 2023, small businesses were the most targeted victims of LockBit and BlackCat, while large enterprises were the primary targets of Clop ransomware attacks.

Update: T-Mobile Denies Rumors of a Breach Affecting Employee Data

25 September 2023
The stolen data, believed to be from an authorized retailer called Connectivity Source, includes employee IDs, login information, Social Security numbers, and service account details.

New Report Uncovers Three Distinct Clusters of China-Nexus Attacks on Southeast Asian Government

25 September 2023
An unnamed Southeast Asian government has been targeted by multiple China-nexus threat actors as part of espionage campaigns targeting the region over extended periods of time. "While this activity occurred around the same time and in some instances even simultaneously on the same victims' machines, each cluster is characterized by distinct tools, modus operandi and infrastructure," Palo Alto

Outer Space and Juicy Mix: OilRig Campaigns Targeting Israeli Organizations

25 September 2023
ESET revealed details on two cyberespionage campaigns conducted by the OilRig APT group against Israeli organizations, using spear-phishing emails. The Outer Space campaign utilized the Solar backdoor and the SC5k downloader, while the Juicy Mix campaign featured the Mango backdoor and additional browser-data dumpers and credential stealers. Organizations need to prioritize email security measures and employee training to combat spear-phishing attacks.

Teachers encouraged to enter schoolgirls into UK's flagship cyber security contest

24 September 2023
Registration opens for the CyberFirst Girls competition 2023/2024.

Deadglyph: New Advanced Backdoor with Distinctive Malware Tactics

23 September 2023
Cybersecurity researchers have discovered a previously undocumented advanced backdoor dubbed Deadglyph employed by a threat actor known as Stealth Falcon as part of a cyber espionage campaign. "Deadglyph's architecture is unusual as it consists of cooperating components – one a native x64 binary, the other a .NET assembly," ESET said in a new report shared with The Hacker News. "This combination

Update: Dallas Says Royal Ransomware Breached Its Network Using Stolen Account

23 September 2023
Royal gained access to the City's network using a stolen domain service account in early April and maintained access to the compromised systems between April 7 and May 4.

Government of Bermuda Links Cyberattack to Russian Hackers

23 September 2023
"The public is advised that the Government Is currently experiencing internet/email and phone service interruptions. All Departments are impacted," the Bermuda Government said.