Latest Cybersecurity News and Articles


New Chae$ 4 Strain Targets Financial and Logistics Customers

06 September 2023
A reworked variant of the Chaes malware, Chae$ 4, is causing havoc in the banking and logistics sectors with significant overhauls. It has been completely rewritten in Python to bypass traditional security defenses and improve communication protocols.  It's essential to regularly update and patch software, and employ robust endpoint security solutions to safeguard against such threats.

Three CISOs Share How to Run an Effective SOC

06 September 2023
The role of the CISO keeps taking center stage as a business enabler: CISOs need to navigate the complex landscape of digital threats while fostering innovation and ensuring business continuity. Three CISOs; Troy Wilkinson, CISO at IPG; Rob Geurtsen, former Deputy CISO at Nike; and Tammy Moskites, Founder of CyAlliance and former CISO at companies like Warner Brothers and Home Depot – shared

Mend.io SAML Vulnerability Exposed

06 September 2023
The vulnerability centers on Mend.io’s implementation of the Security Assertion Markup Language (SAML) login option, a standard method for enabling Single Sign-On (SSO) authentication across various online services.

9 Alarming Vulnerabilities Uncovered in SEL's Power Management Products

06 September 2023
Nine security flaws have been disclosed in electric power management products made by Schweitzer Engineering Laboratories (SEL). “The most severe of those nine vulnerabilities would allow a threat actor to facilitate remote code execution (RCE) on an engineering workstation,” Nozomi Networks said in a report published last week. The issues, tracked as CVE-2023-34392 and from CVE-2023-31168

Nine Vulnerabilities Patched in SEL Power System Management Products

06 September 2023
Nine vulnerabilities, including potentially serious flaws, were patched recently in a couple of electric power management products made by Schweitzer Engineering Laboratories (SEL).

Nascent Malware Campaign Targets npm, PyPI, and RubyGems Developers

06 September 2023
A malware campaign targeting software developers in multiple ecosystems (PyPI, npm, and RubyGems) has been discovered, with packages collecting and exfiltrating data from macOS machines.

Evil MinIO Exploits: A New Attack Vector to Breach Corporate Networks

06 September 2023
An unidentified threat actor weaponized critical security holes in the MinIO high-performance object storage system, gaining unauthorized code execution on targeted servers. Upon launching the application, attackers exploit the flaws to add a backdoor that allows them to conduct remote code execution attacks on victims’ systems. It is recommended to apply the available security update to protect their assets from Evil MinIO exploit attacks.

Yes, There's an npm Package Called @(-.-)/env and Some Others Like it

06 September 2023
These packages have unconventional names and some of them do not follow naming guidelines. While not all of them pose a security risk, they could potentially cause confusion or break software development tooling.

W3LL Store: How a Secret Phishing Syndicate Targets 8,000+ Microsoft 365 Accounts

06 September 2023
A previously undocumented "phishing empire" has been linked to cyber attacks aimed at compromising Microsoft 365 business email accounts over the past six years. "The threat actor created a hidden underground market, named W3LL Store, that served a closed community of at least 500 threat actors who could purchase a custom phishing kit called W3LL Panel, designed to bypass MFA, as well as 16

New BLISTER Malware Update Fuelling Stealthy Network Infiltration

06 September 2023
"New BLISTER update includes keying feature that allows for precise targeting of victim networks and lowers exposure within VM/sandbox environments," Elastic Security Labs researchers said in a technical report published late last month.

Ukraine's CERT Thwarts APT28's Cyberattack on Critical Energy Infrastructure

06 September 2023
The Computer Emergency Response Team of Ukraine (CERT-UA) on Tuesday said it thwarted a cyber attack against an unnamed critical energy infrastructure facility in the country. The intrusion, per the agency, started with a phishing email containing a link to a malicious ZIP archive that activates the infection chain. “Visiting the link will download a ZIP archive containing three JPG images (

Ransomware Attacks Soar by 87% in U.K, Reveals JUMPSEC

06 September 2023
A report from JUMPSEC noted an 87% increase in attacker-reported ransomware in the U.K and a 37% globally in H1 2023. The mass exploitation of vulnerabilities is the primary contributor to this growth.  One key reason for the surge in attack figures is due to the growing number of ransomware variants.Organizations must continually enhance their strategies for responding to cyber extortion.

Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach

05 September 2023
In November 2022, the password manager service LastPass disclosed a breach in which hackers stole password vaults containing both encrypted and plaintext data for more than 25 million users. Since then, a steady trickle of six-figure cryptocurrency heists targeting security-conscious people throughout the tech industry has led some security experts to conclude that crooks likely have succeeded at cracking open some of the stolen LastPass vaults.

71% of organizations are impacted by cybersecurity skills shortage

05 September 2023
According to a recent report on security leaders, a career in cybersecurity is becoming more difficult in an increasingly challenging environment.

65% of organizations prioritize vulnerabilities based on risk

05 September 2023
A recent report by Syxsense shows that 78% of respondents report experiencing an increase in vulnerability volume over the past 12 months.

Suspected ALPHV Ransomware Attack on Melbourne Pathology Clinic Possibly Exposed Patient Data

05 September 2023
The Australian government is aware of the data breach as well as potential incidents affecting real estate firm Barry Plant and owners corporation management company Strata Plan, national cybersecurity coordinator Darren Goldie said in a statement.

More UK Schools Hit by Cyberattacks Before Term Begins

05 September 2023
Highgate Wood School in Crouch End will now begin accepting pupils on September 11 rather than September 5 as originally intended. The secondary school, which serves local students aged 11–16, appears to have escaped the worst of the attack.

New Chaes Malware Variant Targeting Financial and Logistics Customers

05 September 2023
This new variant, primarily targeting logistics and financial sectors, has undergone significant changes, including being rewritten in Python, enhanced communication protocols, and new modules.

Amerita and PharMerica announce data breach

05 September 2023
Amerity and parent company announced a data breach that exposed personal information after learning of suspicious activity on their computer network.

Researchers Warn of Cyber Weapons Used by Lazarus Group's Andariel Cluster

05 September 2023
Some of the malware families employed by Andariel in its attacks include Gh0st RAT, DTrack, YamaBot, NukeSped, Rifdoor, Phandoor, Andarat, Andaratm, TigerRAT (and its successor MagicRAT), and EarlyRAT.