Latest Cybersecurity News and Articles
06 September 2023
A reworked variant of the Chaes malware, Chae$ 4, is causing havoc in the banking and logistics sectors with significant overhauls. It has been completely rewritten in Python to bypass traditional security defenses and improve communication protocols. It's essential to regularly update and patch software, and employ robust endpoint security solutions to safeguard against such threats.
06 September 2023
The role of the CISO keeps taking center stage as a business enabler: CISOs need to navigate the complex landscape of digital threats while fostering innovation and ensuring business continuity. Three CISOs; Troy Wilkinson, CISO at IPG; Rob Geurtsen, former Deputy CISO at Nike; and Tammy Moskites, Founder of CyAlliance and former CISO at companies like Warner Brothers and Home Depot – shared
06 September 2023
The vulnerability centers on Mend.io’s implementation of the Security Assertion Markup Language (SAML) login option, a standard method for enabling Single Sign-On (SSO) authentication across various online services.
06 September 2023
Nine security flaws have been disclosed in electric power management products made by Schweitzer Engineering Laboratories (SEL).
“The most severe of those nine vulnerabilities would allow a threat actor to facilitate remote code execution (RCE) on an engineering workstation,” Nozomi Networks said in a report published last week.
The issues, tracked as CVE-2023-34392 and from CVE-2023-31168
06 September 2023
Nine vulnerabilities, including potentially serious flaws, were patched recently in a couple of electric power management products made by Schweitzer Engineering Laboratories (SEL).
06 September 2023
A malware campaign targeting software developers in multiple ecosystems (PyPI, npm, and RubyGems) has been discovered, with packages collecting and exfiltrating data from macOS machines.
06 September 2023
An unidentified threat actor weaponized critical security holes in the MinIO high-performance object storage system, gaining unauthorized code execution on targeted servers. Upon launching the application, attackers exploit the flaws to add a backdoor that allows them to conduct remote code execution attacks on victims’ systems. It is recommended to apply the available security update to protect their assets from Evil MinIO exploit attacks.
06 September 2023
These packages have unconventional names and some of them do not follow naming guidelines. While not all of them pose a security risk, they could potentially cause confusion or break software development tooling.
06 September 2023
A previously undocumented "phishing empire" has been linked to cyber attacks aimed at compromising Microsoft 365 business email accounts over the past six years.
"The threat actor created a hidden underground market, named W3LL Store, that served a closed community of at least 500 threat actors who could purchase a custom phishing kit called W3LL Panel, designed to bypass MFA, as well as 16
06 September 2023
"New BLISTER update includes keying feature that allows for precise targeting of victim networks and lowers exposure within VM/sandbox environments," Elastic Security Labs researchers said in a technical report published late last month.
06 September 2023
The Computer Emergency Response Team of Ukraine (CERT-UA) on Tuesday said it thwarted a cyber attack against an unnamed critical energy infrastructure facility in the country.
The intrusion, per the agency, started with a phishing email containing a link to a malicious ZIP archive that activates the infection chain.
“Visiting the link will download a ZIP archive containing three JPG images (
06 September 2023
A report from JUMPSEC noted an 87% increase in attacker-reported ransomware in the U.K and a 37% globally in H1 2023. The mass exploitation of vulnerabilities is the primary contributor to this growth. One key reason for the surge in attack figures is due to the growing number of ransomware variants.Organizations must continually enhance their strategies for responding to cyber extortion.
05 September 2023
In November 2022, the password manager service LastPass disclosed a breach in which hackers stole password vaults containing both encrypted and plaintext data for more than 25 million users. Since then, a steady trickle of six-figure cryptocurrency heists targeting security-conscious people throughout the tech industry has led some security experts to conclude that crooks likely have succeeded at cracking open some of the stolen LastPass vaults.
05 September 2023
According to a recent report on security leaders, a career in cybersecurity is becoming more difficult in an increasingly challenging environment.
05 September 2023
A recent report by Syxsense shows that 78% of respondents report experiencing an increase in vulnerability volume over the past 12 months.
05 September 2023
The Australian government is aware of the data breach as well as potential incidents affecting real estate firm Barry Plant and owners corporation management company Strata Plan, national cybersecurity coordinator Darren Goldie said in a statement.
05 September 2023
Highgate Wood School in Crouch End will now begin accepting pupils on September 11 rather than September 5 as originally intended. The secondary school, which serves local students aged 11–16, appears to have escaped the worst of the attack.
05 September 2023
This new variant, primarily targeting logistics and financial sectors, has undergone significant changes, including being rewritten in Python, enhanced communication protocols, and new modules.
05 September 2023
Amerity and parent company announced a data breach that exposed personal information after learning of suspicious activity on their computer network.
05 September 2023
Some of the malware families employed by Andariel in its attacks include Gh0st RAT, DTrack, YamaBot, NukeSped, Rifdoor, Phandoor, Andarat, Andaratm, TigerRAT (and its successor MagicRAT), and EarlyRAT.