Latest Cybersecurity News and Articles


Deadglyph: New Advanced Backdoor with Distinctive Malware Tactics

23 September 2023
Cybersecurity researchers have discovered a previously undocumented advanced backdoor dubbed Deadglyph employed by a threat actor known as Stealth Falcon as part of a cyber espionage campaign. "Deadglyph's architecture is unusual as it consists of cooperating components – one a native x64 binary, the other a .NET assembly," ESET said in a new report shared with The Hacker News. "This combination

Update: Dallas Says Royal Ransomware Breached Its Network Using Stolen Account

23 September 2023
Royal gained access to the City's network using a stolen domain service account in early April and maintained access to the compromised systems between April 7 and May 4.

Government of Bermuda Links Cyberattack to Russian Hackers

23 September 2023
"The public is advised that the Government Is currently experiencing internet/email and phone service interruptions. All Departments are impacted," the Bermuda Government said.

Chinese, North Korean Nation-State Groups Target Health Data

23 September 2023
Financially motivated groups originating in North Korea and China "have all the sophistication of many other cybercriminal gangs but also have the resources - technological, financial and diplomatic - of a state behind them," HHS HC3 warned.

Apple and Chrome Zero-Days Exploited to Hack Egyptian ex-MP with Predator Spyware

23 September 2023
The three zero-day flaws addressed by Apple on September 21, 2023, were leveraged as part of an iPhone exploit chain in an attempt to deliver a spyware strain called Predator targeting former Egyptian member of parliament Ahmed Eltantawy between May and September 2023. "The targeting took place after Eltantawy publicly stated his plans to run for President in the 2024 Egyptian elections," the

Crypto Firm Nansen Asks Users to Reset Passwords After Vendor Breach

23 September 2023
Nansen stopped the malicious activity shortly after the affected vendor informed them about the incident, but the ensuing investigation confirmed that user data was compromised.

LastPass: ‘Horse Gone Barn Bolted’ is Strong Password

22 September 2023
The password manager service LastPass is now forcing some of its users to pick longer master passwords. LastPass says the changes are needed to ensure all customers are protected by their latest security improvements. But critics say the move is little more than a public relations stunt that will do nothing to help countless early adopters whose password vaults were exposed in a 2022 breach at LastPass.

Iranian Nation-State Actor OilRig Targets Israeli Organizations

22 September 2023
The campaigns, dubbed Outer Space and Juicy Mix, entailed the use of two previously documented first-stage backdoors called Solar and Mango, which were deployed to collect sensitive information from major browsers and the Windows Credential Manager.

Hotel Hackers Redirect Guests to Fake booking.com to Steal Cards

22 September 2023
Despite the sophisticated techniques used, users can still protect themselves by being cautious of unsolicited links, suspicious messages, and checking URLs for deception, as well as contacting the company directly for clarification.

Risk management legislation introduced to House of Representatives

22 September 2023
The National Risk Management Act, designed to strengthen the defense of critical infrastructure, was introduced to the U.S. House of Representatives.

BBTok Banking Trojan Impersonates Over 40 Banks to Hijack Victim Accounts

22 September 2023
The campaign uses advanced obfuscation techniques, phishing links, and geofencing to ensure victims are located only in Brazil and Mexico, demonstrating an evolution in the attackers' tactics.

New Variant of Banking Trojan BBTok Targets Over 40 Latin American Banks

22 September 2023
An active malware campaign targeting Latin America is dispensing a new variant of a banking trojan called BBTok, particularly users in Brazil and Mexico. "The BBTok banker has a dedicated functionality that replicates the interfaces of more than 40 Mexican and Brazilian banks, and tricks the victims into entering its 2FA code to their bank accounts or into entering their payment card number,"

S&P 500 companies find gaps in their cybersecurity leadership

22 September 2023
A report found that S&P 500 organizations have gaps in their cybersecurity leadership (CISOs and/or CIOs) when it comes to risk mitigation.

Ohio Community College Data Theft Breach Affects Nearly 300K

22 September 2023
In a breach notification on Wednesday, Lakeland Community College didn't provide any details on the attack, which occurred between March 7 and March 31, but the Vice Society ransomware group had earlier listed the college on its data leak site.

57% of LockBit victims were organizations with 200 employees or fewer

22 September 2023
A Trend Micro Incorporated report found that many ransomware actors are targeting smaller organizations that have 200 or fewer employees.

Attacker Unleashes Stealthy Crypto Mining via Malicious Python Package

22 September 2023
The Python package "Culturestreak" is a malicious software that hijacks system resources for unauthorized cryptocurrency mining. The package utilizes obfuscated code and random filenames to evade detection, making it a persistent threat.

Sandman APT Infiltrates Telecommunications Companies Using LuaDream Backdoor

22 September 2023
The activities of Sandman suggest espionage motivations, with a focus on telecommunications providers and a potential connection to a private contractor or mercenary group.

Apple Emergency Updates Fix Three New Zero-Days Exploited in Attacks

22 September 2023
Apple released emergency security updates to patch three new zero-day vulnerabilities exploited in attacks targeting iPhone and Mac users, for a total of 16 zero-days fixed this year.

Rising OT/ICS Cybersecurity Incidents Reveal Alarming Trend

22 September 2023
Approximately 60% of cyberattacks on the industrial sector are carried out by state-affiliated actors, often with the unintentional assistance of internal personnel (about 33% of the time), according to Rockwell Automation.

Air Canada Says Hackers Accessed Limited Employee Records During Cyberattack

22 September 2023
Canada’s largest airline, Air Canada, announced a data breach this week that involved the information of employees, but said its operations and customer data were not impacted.