Latest Cybersecurity News and Articles


Bankrupt Crypto Platforms FTX and BlockFi Warn Customers of Data Breach

25 August 2023
FTX learned that Kroll, the claims agent in the bankruptcy, experienced a cybersecurity incident that compromised non-sensitive customer data of certain claimants in the pending bankruptcy case.

32% of security leaders struggle with prioritizing improvements

25 August 2023
According to a Cloud Security Alliance report, 32% of respondents disclosed that they're struggling with prioritizing security improvements.

Kroll Employee SIM-Swapped for Crypto Investor Data

25 August 2023
Security consulting giant Kroll disclosed today that a SIM-swapping attack against one of its employees led to the theft of user information for multiple cryptocurrency platforms that are relying on Kroll services in their ongoing bankruptcy proceedings. And there are indications that fraudsters may already be exploiting the stolen data in phishing attacks. Cryptocurrency lender BlockFi and the now-collapsed crypto trading platform FTX each disclosed data breaches this week thanks to a recent SIM-swapping attack targeting an employee of Kroll -- the company handling both firms' bankruptcy restructuring.

Cisco NX-OS Software TACACS+ or RADIUS Remote Authentication Directed Request Denial of Service Vulnerability

25 August 2023
This vulnerability can only be exploited over Telnet, which is disabled by default, or over the console management connection. This vulnerability cannot be exploited over SSH connections to the device.

Ransomware With an Identity Crisis Targets Small Businesses, Individuals

25 August 2023
A key reason it was so tricky for researchers to identify TZW as a spinoff of Adhubllka is because of the small ransom demands the group typically makes. At such a level, victims often pay attackers and the attackers continue to fly under the radar.

Gary Perkins hired as Chief Information Security Officer at CISO Global

25 August 2023
Gary Perkins has been hired as CISO at CISO Global. In his new role, Perkins will spearhead cybersecurity strategies and risk management initiatives.

Two LAPSUS$ Hackers Convicted in London Court for High-Profile Tech Firm Hacks

25 August 2023
Two U.K. teenagers have been convicted by a jury in London for being part of the notorious LAPSUS$ transnational gang and for orchestrating a series of brazen, high-profile hacks against major tech firms and demanding a ransom in exchange for not leaking the stolen information. This includes Arion Kurtaj (aka White, Breachbase, WhiteDoxbin, and TeaPotUberHacker), an 18-year-old from Oxford, and

Nearly 1,000 Organizations, 60 Million Individuals Impacted by MOVEit Hack

25 August 2023
On August 14 and 15, the cybercriminals leaked nearly 1 Tb of information allegedly stolen from 16 of the victims, Resecurity said. These victims include UCLA, Siemens Energy, Cognizant, and cybersecurity firms Norton LifeLock and Netscout.

Sextortion Scams Surge 178% in a Year

25 August 2023
The good news is that the scam is an empty threat that aims to play on the victim’s fear of leaking data. By knowing this, they can then be confidently ignored. ESET traced one scam wherein an actor demanded £1000 ($1260) in BTC from the victim.

IT leaders optimistic about how AI will transform their business

25 August 2023
 A new survey of global IT leaders which found that three in four IT leaders are optimistic about the potential benefits of artificial intelligence. 

US Small Business Administration announces $6M in cybersecurity grants

25 August 2023
Six organizations will receive a total of $6 million funding from the U.S. Small Business Administration Cybersecurity for Small Business Pilot Program.

Learn How Your Business Data Can Amplify Your AI/ML Threat Detection Capabilities

25 August 2023
In today's digital landscape, your business data is more than just numbers—it's a powerhouse. Imagine leveraging this data not only for profit but also for enhanced AI and Machine Learning (ML) threat detection. For companies like Comcast, this isn't a dream. It's reality. Your business comprehends its risks, vulnerabilities, and the unique environment in which it operates. No generic,

Title Lender TMX Now Says Payment Card Data Stolen in Breach

25 August 2023
A revised data breach notification is being sent to victims stating that attackers may have also stolen their credit/debit card number, beyond the raft of personal information.

Navigating Legacy Infrastructure: A CISO's Actionable Strategy for Success

25 August 2023
Every company has some level of tech debt. Unless you’re a brand new start-up, you most likely have a patchwork of solutions that have been implemented throughout the years, often under various leadership teams with different priorities and goals. As those technologies age, they can leave your organization vulnerable to cyber threats. While replacing legacy technologies can be costly, those

China-based 'Flax Typhoon' hackers targeting Taiwan govt: Microsoft

25 August 2023
The activities observed suggest the threat actor intends to perform espionage and maintain access to organizations across a broad range of industries for as long as possible.

China-Linked Flax Typhoon Cyber Espionage Targets Taiwan's Key Sectors

25 August 2023
A nation-state activity group originating from China has been linked to cyber attacks on dozens of organizations in Taiwan as part of a suspected espionage campaign. The Microsoft Threat Intelligence team is tracking the activity under the name Flax Typhoon, which is also known as Ethereal Panda. "Flax Typhoon gains and maintains long-term access to Taiwanese organizations' networks with minimal

Time keeps on slippin’ slippin’ slippin’: The 2023 Active Adversary Report for Tech Leaders

25 August 2023
In H1 2023, compromised credentials accounted for 50% of root causes, whereas exploiting a bug came in at 23%. We can’t conclusively say that attackers are favoring compromised credentials over vulnerabilities, but it can’t be denied either.

Researchers released PoC exploit for Ivanti Sentry flaw CVE-2023-38035

25 August 2023
The vulnerability could be exploited to access sensitive API data and configurations, run system commands, or write files onto the system. The vulnerability CVE-2023-38035 impacts Sentry versions 9.18 and prior.

New Luna Grabber Poses as Roblox Packages, Strikes NPM

25 August 2023
Malicious actors are targeting Roblox developers with a new malware called Luna Grabber, distributed through npm packages that impersonate legitimate software. These fake packages, including noblox.js-vps, noblox.js-ssh, and noblox.js-secure, house malicious multi-stage payloads. This campaign underscores the recurring strategy of threat actors employing typosquatting as a tactic to deceive developers.

Rockwell ThinManager Vulnerabilities Could Expose Industrial HMIs to Attacks

25 August 2023
Exploitation of the vulnerabilities can allow causing a denial-of-service (DoS) condition, deleting arbitrary files with system privileges, and uploading arbitrary files to any folder on the drive where ThinServer.exe is installed.