Latest Cybersecurity News and Articles


Dreambus Malware Exploits RocketMQ Flaw to Infect Servers

30 August 2023
The researchers also observed the threat actor downloading a malicious bash script named ‘reketed’ from a Tor proxy service, which evaded detection from AV engines on VirusTotal.

AiTM Attacks Evolve: Warns Microsoft

30 August 2023
Microsoft is alerting about a rise in AiTM phishing methods within the PhaaS cybercrime model, enabling widespread large-scale phishing campaigns. The primary aim of these attacks is to steal session cookies, allowing malicious actors to gain entry to privileged systems without needing to authenticate again. As cybercriminal sophistication continues to grow, organizations must implement comprehensive cybersecurity measures to combat these evolving threats.

Critical Vulnerability in VMware Aria Operations Puts Networks at Risk of Remote Attacks

30 August 2023
The vulnerabilities, which affect VMware Aria Operations Networks versions 6.2, 6.3, 6.4, 6.5.1, 6.6, 6.7, 6.8, 6.9, and 6.10, have been addressed in a series of patches released by VMware for each of the versions.

Critical Vulnerability Alert: VMware Aria Operations Networks at Risk from Remote Attacks

30 August 2023
VMware has released software updates to correct two security vulnerabilities in Aria Operations for Networks that could be potentially exploited to bypass authentication and gain remote code execution. The most severe of the flaws is CVE-2023-34039 (CVSS score: 9.8), which relates to a case of authentication bypass arising as a result of a lack of unique cryptographic key generation. "A

MalDoc in PDF: New Malicious Attack Discovered by JPCERT

30 August 2023
Japan CERT has uncovered a novel attack technique named 'MalDoc in PDF' that involves embedding a malicious Word file into a PDF document to evade detection. While the file appears as a PDF, it can be opened in Word and execute malicious macros. JPCERT has shared detection details and a Yara rule in its report.

FBI Dismantles QakBot Malware, Frees 700,000 Computers, Seizes $8.6 Million

30 August 2023
A coordinated law enforcement effort codenamed Operation Duck Hunt has felled QakBot, a notorious Windows malware family that's estimated to have compromised over 700,000 computers globally and facilitated financial fraud as well as ransomware. To that end, the U.S. Justice Department (DoJ) said the malware is "being deleted from victim computers, preventing it from doing any more harm," adding

U.S. Hacks QakBot, Quietly Removes Botnet Infections

29 August 2023
The U.S. government today announced a coordinated crackdown against QakBot, a complex malware family used by multiple cybercrime groups to lay the groundwork for ransomware infections. The international law enforcement operation involved seizing control over the botnet's online infrastructure, and quietly removing the Qakbot malware from tens of thousands of infected Microsoft Windows computer systems.

University of Michigan Shuts Down Network After Cyberattack

29 August 2023
The University of Michigan has taken all of its systems and services offline to deal with a cybersecurity incident, causing a widespread impact on online services the night before classes started.

DarkGate Malware Activity Spikes as Developer Rents Out Malware to Affiliates

29 August 2023
"The current spike in DarkGate malware activity is plausible given the fact that the developer of the malware has recently started to rent out the malware to a limited number of affiliates," Telekom Security said in a report published last week.

Japan’s Cybersecurity Agency Breached by Suspected Chinese Hackers: Report

29 August 2023
Suspected Chinese hackers breached Japan’s cybersecurity agency and potentially accessed sensitive data stored on its networks for nine months before being discovered, it was reported on Tuesday.

US Government Email Servers Hacked in Barracuda Zero-Day Attacks

29 August 2023
The attacks' motivation was espionage, with the threat actor (tracked as UNC4841) engaging in targeted exfiltration from systems belonging to high-profile users in government and high-tech verticals.

Meta Fights Sprawling Chinese ‘Spamouflage’ Operation

29 August 2023
The network typically posted praise for China and its Xinjiang province and criticisms of the United States, Western foreign policies, and critics of the Chinese government including journalists and researchers, the Meta report says.

80% of organizations expect ransomware spending to increase

29 August 2023
Ransomware was analyzed in a recent report by Enterprise Strategy Group (ESG) finding that ransomware is seen as a top threat for organizations.

Chinese Hacking Group Exploits Barracuda Zero-Day to Target Government, Military, and Telecom

29 August 2023
A suspected Chinese-nexus hacking group exploited a recently disclosed zero-day flaw in Barracuda Networks Email Security Gateway (ESG) appliances to breach government, military, defense and aerospace, high-tech industry, and telecom sectors as part of a global espionage campaign. Mandiant, which is tracking the activity under the name UNC4841, described the threat actor as "highly responsive to

DarkGate Malware Activity Spikes as Developer Rents Out Malware to Affiliates

29 August 2023
A new malspam campaign has been observed deploying an off-the-shelf malware called DarkGate. "The current spike in DarkGate malware activity is plausible given the fact that the developer of the malware has recently started to rent out the malware to a limited number of affiliates," Telekom Security said in a report published last week. The latest findings build on recent findings from security

86% of organizations using AI agree on need for clear AI guidelines

29 August 2023
Organizations' leadership and workforce were surveyed by Conversica on artificial intelligence (AI) use and opinions, including data security.

Compromised OpenCart Payment Module Steals Credit Card Information

29 August 2023
Attackers are increasingly using backend PHP infections, making it more challenging to detect Magecart infections without access to the compromised website's backend code.

Is the Cybersecurity Community’s Obsession With Compliance Counter-Productive?

29 August 2023
Cybersecurity professionals should focus on effectively defending their organizations against common breach types, rather than prioritizing compliance and checking boxes on audit forms.

Android Banking Trojan MMRat Carries Out Bank Fraud via Fake App Stores

29 August 2023
MMRat uses customized command-and-control protocols and remains undetected on VirusTotal, highlighting its ability to evade detection and exploit large volumes of data transfer.

CISA publishes resource for migrating to post-quantum cryptography  

29 August 2023
CISA urges organizations to begin early planning for migration to post-quantum cryptographic standards by developing quantum-readiness roadmaps.