Latest Cybersecurity News and Articles


APT Attacks From 'Earth Estries' Hit Governments, Tech Firms Across the Globe

31 August 2023
Earth Estries uses advanced techniques such as DLL sideloading and has developed three custom malware tools: Zingdoor, TrillClient, and HemiGate. It has been active since at least 2020 and has similarities with another group called FamousSparrow.

SEC Cyber Incident Reporting Regulations Prompt 10 Questions for CISOs

31 August 2023
Board members must have a strong grasp of the cybersecurity landscape and ask their CISOs critical questions about cyber risk and management to comply with SEC regulations.

Paramount Discloses Data Breach Following Security Incident

31 August 2023
Paramount said in breach notification letters signed by Nickelodeon Animation Studio EVP Brian Keane sent to affected individuals that the attackers had access to its systems between May and June 2023.

Numbers Don't Lie: Exposing the Harsh Truths of Cyberattacks in New Report

31 August 2023
How often do cyberattacks happen? How frequently do threat actors target businesses and governments around the world? The BlackBerry® Threat Research and Intelligence Team recently analyzed 90 days of real-world data to answer these questions. Full results are in the latest BlackBerry Global Threat Intelligence Report, but read on for a teaser of several interesting cyber attack statistics.

Why Criminals Keep Reusing Leaked Ransomware Builders

31 August 2023
Ransomware attacks are increasingly using stolen or reused strains of malware, making it difficult to attribute attacks to specific groups. Attackers are creating Frankenstein ransomware by combining different pieces of malware.

Montreal Electricity Organization is the Latest Victim in LockBit Ransomware Spree

31 August 2023
On Wednesday, the gang took credit for an attack on the Commission des services electriques de Montréal (CSEM) — a 100-year-old municipal organization that manages electrical infrastructure in the city of Montreal.

The Secret Habits of Top-Performing CISOs

31 August 2023
69% of top-performing CISOs dedicate recurring time on their calendars for personal professional development, according to Gartner. This is compared with just 36% of bottom-performing CISOs who do so.

Hackers can Exploit Windows Container Isolation Framework to Bypass Endpoint Security

31 August 2023
New findings show that malicious actors could leverage a sneaky malware detection evasion technique and bypass endpoint security solutions by manipulating the Windows Container Isolation Framework.

Gangs Forcing Hundreds of Thousands of People Into Cybercrime in South-East Asia, Says UN

31 August 2023
Hundreds of thousands of people have been trafficked and forced to work for online scamming operations in south-east Asia run by criminal gangs, according to a UN report.

Hacking Campaign Brute-Forces Cisco VPNs to Breach Networks

31 August 2023
Hackers are targeting Cisco Adaptive Security Appliance (ASA) SSL VPNs in credential stuffing and brute-force attacks that take advantage of lapses in security defenses, such as not enforcing multi-factor authentication (MFA).

BGP Flaw can Be Exploited for Prolonged Internet Outages

31 August 2023
A serious flaw affecting several major Border Gateway Protocol (BGP) implementations can be exploited to cause prolonged internet outages, but some vendors are not patching it, a researcher warned on Tuesday.

High-Severity Memory Corruption Vulnerabilities Patched in Firefox, Chrome

31 August 2023
Mozilla released Firefox 117 with patches for 13 vulnerabilities, including seven rated ‘high severity’, four of which are described as memory corruption bugs affecting the browser’s components.

WordPress Migration Add-on Flaw Could Lead to Data Breaches

31 August 2023
All-in-One WP Migration, a popular data migration plugin for WordPress sites with 5 million active installations, suffers from unauthenticated access token manipulation that could allow attackers to access sensitive site information.

Nordic Users Targeted by National Danish Police Phishing Attack

31 August 2023
The phishing attack involves sending an email with a cryptic message and a PDF attachment that claims to detail the recipient's involvement in illegal internet activity related to child pornography, in an attempt to coerce them into responding.

Earth Estries' Espionage Campaign Targets Governments and Tech Titans Across Continents

31 August 2023
A hacking outfit nicknamed Earth Estries has been attributed to a new, ongoing cyber espionage campaign targeting government and technology industries based in the Philippines, Taiwan, Malaysia, South Africa, Germany, and the U.S. "The threat actors behind Earth Estries are working with high-level resources and functioning with sophisticated skills and experience in cyber espionage and illicit

SailPoint to Buy Privileged Access Vendor Osirium for $8.3M

31 August 2023
SailPoint has agreed to purchase U.K.-based privileged access management vendor Osirium for $8.3 million to better protect privileged and non-privileged identities on a single platform.

Crooks Using Stealers and Stolen Cookies to Hack Airbnb Accounts

31 August 2023
Researchers at SlashNext warned that cybercriminals are using a variety of methods, including stealers and stolen cookies, to gain unauthorized access to Airbnb accounts and carry out fraudulent activities.

MMRat Android Malware Targets Banking Users in Southeast Asia

31 August 2023
A new Android banking trojan called MMRat has been found targeting mobile users in Southeast Asia since June, allowing threat actors to carry out bank fraud on victim's devices. The malware collects personal data, including contact lists and installed apps. To protect against this malware, Android users are advised to check rating, user reviews before downloading apps.

Unpatched Citrix NetScaler Devices Under Attack, Connected to FIN8

31 August 2023
A threat actor linked to the FIN8 threat group is exploiting a critical vulnerability in unpatched Citrix NetScaler systems, potentially leading to ransomware attacks. In the series of attacks, the attacker carried out the exploitation by inserting two harmful code payloads in different processes. Over 31,000 Citrix NetScaler instances are still vulnerable to the flaw, despite security updates being available for over a month.

UK and allies support Ukraine calling out Russia's GRU for new malware campaign

30 August 2023
Malware, dubbed Infamous Chisel, enables unauthorised access to compromised Android devices.