Latest Cybersecurity News and Articles


Urgent FBI Warning: Barracuda Email Gateways Vulnerable Despite Recent Patches

25 August 2023
The U.S. Federal Bureau of Investigation (FBI) is warning that Barracuda Networks Email Security Gateway (ESG) appliances patched against a recently disclosed critical flaw continue to be at risk of potential compromise from suspected Chinese hacking groups. It also deemed the fixes as "ineffective" and that it "continues to observe active intrusions and considers all affected Barracuda ESG

WinRAR Zero-Day Actively Exploited to Distribute Malware

25 August 2023
A recently discovered zero-day vulnerability in WinRAR has been exploited in a malware distribution campaign that has been ongoing since April. The vulnerability, known as CVE-2023-3881, allows attackers to create malicious zip archives with spoofed file extensions, concealing them as harmless files. It is highly recommended that users upgrade to the latest version (6.23) of WinRAR.

IT leaders report concern over generative AI in SaaS applications

24 August 2023
When asked in a survey how they would feel if a SaaS vendor used generative AI without their knowledge, more than half of IT leaders reported concern.

Sensitive Data of 10m at Risk After French Employment Agency Breach

24 August 2023
In a public statement published on August 23, 2023, Pôle emploi confirmed “a breach in the information system of one of its service providers, involving a risk of disclosure of jobseekers' personal data.”

Millions stolen from crypto platforms Exactly Protocol and Harbor Protocol

24 August 2023
Two DeFi platforms, Exactly and Harbor, fell victim to cyberattacks resulting in the theft of millions of dollars' worth of cryptocurrency. Exactly Protocol confirmed suffering a loss of around $7.3 million worth of ETH.

Cyberattack disrupts major Mississippi health system

24 August 2023
Despite the shutdown of certain internal systems following the detection of unusual network activity, SRHS disclosed that workarounds have been implemented to ensure the partial continuation of business operations.

Lazarus Group Exploits Critical Zoho ManageEngine Flaw to Deploy Stealthy QuiteRAT Malware

24 August 2023
The North Korea-linked threat actor known as Lazarus Group has been observed exploiting a now-patched critical security flaw impacting Zoho ManageEngine ServiceDesk Plus to distribute a remote access trojan called such as QuiteRAT. Targets include internet backbone infrastructure and healthcare entities in Europe and the U.S., cybersecurity company Cisco Talos said in a two-part analysis 

Smoke Loader Drops Whiffy Recon Wi-Fi Scanning and Geolocation Malware

24 August 2023
Whiffy Recon works by checking for the WLAN AutoConfig service (WLANSVC) on the infected system and terminating itself if the service name doesn't exist. Persistence is achieved by means of a shortcut that's added to the Windows Startup folder.

Malicious web application transactions increased by 500% in 2023

24 August 2023
According to a Radware cyberattack report, the number of malicious web application transactions increased by 500% compared to the first half of 2022.

Telekopye: Hunting Mammoths using Telegram bot

24 August 2023
The exact origins of the threat actors, dubbed Neanderthals, are unclear, but evidence points to Russia as the country of origin of the toolkit's authors and users, owing to the use of Russian SMS templates.

Lazarus Group Exploits ManageEngine Vulnerability to Deploy QuiteRAT

24 August 2023
QuiteRAT is clearly an evolution of MagicRAT. While MagicRAT is a bigger, bulkier malware family averaging around 18MB in size, QuiteRAT is a much much smaller implementation, averaging around 4 to 5MB in size.

Social Security Numbers were exposed in 69% of breaches in 2023

24 August 2023
According to a recent TransUnion report, Social Security Number has passed date of birth as second most often exposed credential in data breaches.

New Telegram Bot "Telekopye" Powering Large-scale Phishing Scams from Russia

24 August 2023
A new financially motivated operation is leveraging a malicious Telegram bot to help threat actors scam their victims. Dubbed Telekopye, a portmanteau of Telegram and kopye (meaning "spear" in Russian), the toolkit functions as an automated means to create a phishing web page from a premade template and send the URL to potential victims, codenamed Mammoths by the criminals. "This toolkit is

St Helens Council Warns of Phishing After Ransomware Breach

24 August 2023
The council warned in a further message on its website for locals to watch out for phishing emails impersonating their bank and informing them of a new direct debit. That would suggest that the hackers have access to citizens’ personal information.

nao-sec.org

24 August 2023
The APT group starts by sending a spear-phishing email, which consists of a DOC file embedded with a URL for a ZIP file download. Once the ZIP file gets downloaded, it contains an EXE file and a DLL file which are executed to infect malware.

91% of security pros say cybercriminals are using AI in email attacks

24 August 2023
A recent report reveals that the majority of organizations believe cybercriminals are already using artificial intelligence (AI) in email attacks targeting their organizations.

The Hidden Dangers of Public Wi-Fi

24 August 2023
Public Wi-Fi, which has long since become the norm, poses threats to not only individual users but also businesses. With the rise of remote work, people can now work from virtually anywhere: a cafe close to home, a hotel in a different city, or even while waiting for a plane at the airport. Next, let's explore the risks of connecting to public Wi-Fi, both for you personally and for businesses.

New "Whiffy Recon" Malware Triangulates Infected Device Location via Wi-Fi Every Minute

24 August 2023
The SmokeLoader malware is being used to deliver a new Wi-Fi scanning malware strain called Whiffy Recon on compromised Windows machines. "The new malware strain has only one operation. Every 60 seconds it triangulates the infected systems' positions by scanning nearby Wi-Fi access points as a data point for Google's geolocation API," Secureworks Counter Threat Unit (CTU) said in a statement

More than 3,000 Openfire servers exposed to attacks using a new exploit

24 August 2023
The experts pointed out that the bug has been exploited for more than two months, but yet to be added to the CISA KEV catalog. The researchers discovered approximately 6,300 servers on Shodan and a bit more using the Censys search engine.

Bugs in NVIDIA Graphics Driver Leads to Memory Corruption

24 August 2023
An attacker could exploit these vulnerabilities from guest machines running virtualization environments to perform a guest-to-host escape, as we’ve illustrated with previous vulnerabilities in NVIDIA graphics drivers.