Latest Cybersecurity News and Articles


Threat Actors Targeting Microsoft SQL Servers to Deploy FreeWorld Ransomware

02 September 2023
Cybersecurity firm Securonix, which has dubbed the campaign DB#JAMMER, said it stands out for the way the toolset and infrastructure are employed against poorly secured Microsoft SQL servers.

Okta Warns of Social Engineering Attacks Targeting Super Administrator Privileges

02 September 2023
Central to the attacks is a commercial phishing kit called 0ktapus, which offers pre-made templates to create realistic fake authentication portals and ultimately harvest credentials and MFA codes. It also has a built-in C2 channel via Telegram.

Update: Exploit Released for Critical VMware SSH Authentication Bypass Vulnerability

02 September 2023
The proof-of-concept (PoC) exploit targets all Aria Operations for Networks versions from 6.0 to 6.10, and it was developed and released by Summoning Team vulnerability researcher Sina Kheirkhah.

Okta Warns of Social Engineering Attacks Targeting Super Administrator Privileges

02 September 2023
Identity services provider Okta on Friday warned of social engineering attacks orchestrated by threat actors to obtain elevated administrator permissions. “In recent weeks, multiple US-based Okta customers have reported a consistent pattern of social engineering attacks against IT service desk personnel, in which the caller’s strategy was to convince service desk personnel to reset all

Golf Gear Giant Callaway Data Breach Exposes Info of 1.1 Million

01 September 2023
Topgolf Callaway (Callaway) suffered a data breach at the start of August, which exposed the sensitive personal and account data of more than a million customers. Callaway is an American golf equipment maker and seller.

Data Breach Could Affect More Than 100,000 in Pima County

01 September 2023
More than 100,000 Pima County residents could be affected by a nationwide data breach that affected the company that handled COVID-19 case investigations and contact tracing here, officials say.

LogicMonitor Customers Hit by Hackers Due to Weak Default Passwords

01 September 2023
Some customers of the network security company LogicMonitor have been hacked due to the use of default passwords, TechCrunch has learned. A LogicMonitor spokesperson confirmed “a security incident” affecting some of the company’s customers.

Free Decryptor Available for ‘Key Group’ Ransomware

01 September 2023
Also known as keygroup777, Key Group is a Russian-speaking cybercrime actor known for selling personally identifiable information (PII) and access to compromised devices, as well as extorting victims for money.

Sourcegraph Discloses Data Breach Following Access Token Leak

01 September 2023
According to the platform, the admin access token used in the attack was leaked in a July 14 commit that passed internal code analysis tools. The token “had broad privileges to view and modify account information on Sourcegraph.com”.

New SuperBear Trojan Emerges in Targeted Phishing Attack on South Korean Activists

01 September 2023
The intrusion singled out an unnamed activist, who was contacted in late August 2023 and received a malicious LNK file from an address impersonating a member of the organization, non-profit entity Interlabs said in a new report.

Threat Actors Targeting Microsoft SQL Servers to Deploy FreeWorld Ransomware

01 September 2023
Threat actors are exploiting poorly secured Microsoft SQL (MS SQL) servers to deliver Cobalt Strike and a ransomware strain called FreeWorld. Cybersecurity firm Securonix, which has dubbed the campaign DB#JAMMER, said it stands out for the way the toolset and infrastructure is employed. “Some of these tools include enumeration software, RAT payloads, exploitation and credential stealing software

Why is .US Being Used to Phish So Many of Us?

01 September 2023
Domain names ending in “.US” — the top-level domain for the United States — are among the most prevalent in phishing scams, new research shows. This is noteworthy because .US is overseen by the U.S. government, which is frequently the target of phishing domains ending in .US. Also, .US domains are only supposed to be available to U.S. citizens and to those who can demonstrate that they have a physical presence in the United States.

Malware top consumer threat from May to July 2023

01 September 2023
According to a cybersecurity trends report, malware was the top online consumer threat from May to July 2023, accounting for 58% of all detections.

Classiscam Scam-as-a-Service Raked in $64.5 Million During the COVID-19 Pandemic

01 September 2023
Among the methods employed by cybercriminals to carry out the scheme is to trick users into buying falsely-advertised goods or services via social engineering schemes and directing potential victims to the automatically generated phishing sites.

CISA report: Russian cyber actors using “Infamous Chisel” malware

01 September 2023
CISA recently published a joint report on a malware campaign conducted by Russian cyber actors against the Ukrainian military.

Russian GRU Hacking Tools Dubbed 'Infamous Chisel' Targeting Ukrainian Military Devices

01 September 2023
Western intelligence and cybersecurity agencies published a report on Thursday highlighting a collection of hacking tools being used by Russia’s military intelligence service against Android devices operated by the Ukrainian Armed Forces.

Rising Cyber Incidents Challenge Healthcare Organizations

01 September 2023
Healthcare organizations are facing many cybersecurity challenges that require them to increasingly prioritize cybersecurity and compliance, according to a report by Claroty.

Open-Source Information Stealer 'SapphireStealer' Enables Credential and Data Theft

01 September 2023
Multiple actors are using SapphireStealer, modifying and improving the original code to create several variants. The malware is often delivered through multi-stage infection processes, with attackers using open-source loaders like FUD-Loader.

Russian State-Backed 'Infamous Chisel' Android Malware Targets Ukrainian Military

01 September 2023
Cybersecurity and intelligence agencies from Australia, Canada, New Zealand, the U.K., and the U.S. on Thursday disclosed details of a mobile malware strain targeting Android devices used by the Ukrainian military. The malicious software, dubbed Infamous Chisel and attributed to a Russian state-sponsored actor called Sandworm, has capabilities to “enable unauthorized access to compromised

"Smishing Triad" Targeted USPS and US Citizens for Data Theft

01 September 2023
The campaign, conducted by a group called "Smishing Triad," impersonates various postal services and government agencies to deceive victims into providing personal and financial information.