Latest Cybersecurity News and Articles


New SuperBear Trojan Emerges in Targeted Phishing Attack on South Korean Activists

01 September 2023
A new phishing attack likely targeting civil society groups in South Korea has led to the discovery of a novel remote access trojan called SuperBear. The intrusion singled out an unnamed activist, who was contacted in late August 2023 and received a malicious LNK file from an address impersonating a member of the organization, non-profit entity Interlabs said in a new report. The LNK file, upon

It's a Zero-day? It's Malware? No! It's Username and Password

01 September 2023
As cyber threats continue to evolve, adversaries are deploying a range of tools to breach security defenses and compromise sensitive data. Surprisingly, one of the most potent weapons in their arsenal is not malicious code but simply stolen or weak usernames and passwords. This article explores the seriousness of compromised credentials, the challenges they present to security solutions, and the

Update: ALPHV Group Takes Credit for Ransomware Attack on Georgia County

01 September 2023
Forsyth County officials had acknowledged an attack in June, but offered few details about what happened. On Tuesday, AlphV took credit for the attack and added the county to its leak site, threatening to expose 350GB of allegedly stolen data.

Prime Therapeutics LLC (Prime)/Magellan Rx Issues Notification of Data Security Incident

01 September 2023
On July 11, 2023, Prime became aware that an unauthorized actor obtained access to an employee's mobile email account containing documents that included members' PHI, including name, address, date of birth, member ID number, and medication(s).

Multiple Threats Target Adobe ColdFusion Vulnerabilities

01 September 2023
Attackers are using the ColdFusion vulnerability to probe, establish reverse shells, and distribute malware, including XMRig Miner, Satan DDoS/Lucifer, RudeMiner, and BillGates/Setag backdoor.

Peeling Back the Layers of RemcosRAT Malware

01 September 2023
The Remcos RAT utilizes complex obfuscation techniques to evade detection and deliver a sophisticated remote access payload. It has multiple stages of execution, including VBS and PowerShell scripts, to download and execute the final payload.

Classiscam Scam-as-a-Service Raked $64.5 Million During the COVID-19 Pandemic

01 September 2023
The Classiscam scam-as-a-service program has reaped the criminal actors $64.5 million in illicit earnings since its emergence in 2019. "Classiscam campaigns initially started out on classified sites, on which scammers placed fake advertisements and used social engineering techniques to convince users to pay for goods by transferring money to bank cards," Group-IB said in a new report. "Since

The NCSC announces Ollie Whitehouse as new CTO

31 August 2023
Ollie Whitehouse has been announced as the new CTO of the National Cyber Security Centre.

Earth Estries Group Targets Government and IT Organizations

31 August 2023
A new cyberespionage campaign called Earth Estries has been discovered, targeting governments and organizations in the technology sector. Active since at least 2020, the campaign shows similarities with another APT group called FamousSparrow. It is essential for organizations to track and analyze the tactics and techniques used by Earth Estries to set their security preferences and protect their digital assets. 

Unmasking Trickbot, One of the World’s Top Cybercrime Gangs

31 August 2023
Maksim Sergeevich Galochkin, a member of the Russian cybercrime syndicate Trickbot, has been identified by cybercrime researchers. The identification of Galochkin comes after a comprehensive investigation into leaked data from the Trickbot group.

BadBazaar Espionage Tool Targets Android Users

31 August 2023
ESET discovered two active campaigns distributing trojanized Signal and Telegram apps that aim to exfiltrate user data and spy on victims’ communications. They have been spreading the BadBazaar Android spyware. Mitigation includes cautious app selection, avoiding suspicious sources, and maintaining up-to-date security measures.

VMConnect Supply Chain Attack Continues, Evidence Points to North Korea

31 August 2023
The recently discovered malicious Python packages, such as tablediter, request-plus, and requestspro, are believed to be a continuation of the VMConnect campaign attributed to North Korean threat actors.

Netgear Releases Patches for Two High-Severity Vulnerabilities

31 August 2023
The network hardware giant Netgear has discovered two vulnerabilities affecting one of its router models and its network management software. One of the flaws, tracked as CVE-2023-41183, allows hackers to exploit Netgear’s Orbi 760 routers.

13% of employees admit to falling for phishing attacks working at home

31 August 2023
Cyber threats facing remote workers were analyzed in a report by Lookout. The report included phishing campaigns and cybersecurity recommendations.

Forever 21 Data Breach Leaks Personal Information of Over 539,000 Individuals

31 August 2023
Forever 21 experienced a data breach that compromised the personal information, including names and Social Security numbers, of over 539,000 individuals. The breach occurred between January 5, 2023, and March 21, 2023.

SapphireStealer Malware: A Gateway to Espionage and Ransomware Operations

31 August 2023
An open-source .NET-based information stealer malware dubbed SapphireStealer is being used by multiple entities to enhance its capabilities and spawn their own bespoke variants. “Information-stealing malware like SapphireStealer can be used to obtain sensitive information, including corporate credentials, which are often resold to other threat actors who leverage the access for additional

Compliance and Risk Management Startup Hyperproof Raises $40M

31 August 2023
Hyperproof, a software-as-a-service risk and compliance management company, today announced that it raised $40 million in a funding round led by Riverwood Capital, with participation from Toba Capital, an early-stage VC firm.

National Safety Council Data Leak Impacts Credentials of NASA, Tesla, DoJ, Verizon, and 2000 Other Firms

31 August 2023
The National Safety Council has leaked nearly 10,000 emails and passwords of their members, exposing 2000 companies, including governmental organizations and big corporations.

North Korean Hackers Deploy New Malicious Python Packages in PyPI Repository

31 August 2023
Three additional malicious Python packages have been discovered in the Package Index (PyPI) repository as part of an ongoing malicious software supply chain campaign called VMConnect, with signs pointing to the involvement of North Korean state-sponsored threat actors. The findings come from ReversingLabs, which detected the packages tablediter, request-plus, and requestspro. First disclosed at

The Power of Passive OS Fingerprinting for Accurate IoT Device Identification

31 August 2023
To effectively safeguard against the risks of IoT sprawl, continuous monitoring, and absolute control are crucial. However, that requires accurate identification of all IoT devices and operating systems (OSes) within the enterprise network.