Latest Cybersecurity News and Articles


WinRAR Security Flaw Exploited in Zero-Day Attacks to Target Traders

24 August 2023
A recently patched security flaw in the popular WinRAR archiving software has been exploited as a zero-day since April 2023, new findings from Group-IB reveal. The vulnerability, cataloged as CVE-2023-38831, allows threat actors to spoof file extensions, thereby making it possible to launch malicious scripts contained within an archive that masquerades as seemingly innocuous image or text files.

National intelligence office issues cyber warning for government and commercial satellites

24 August 2023
The warning comes just about a month after three teams at the DEF CON 23 convention in Las Vegas managed to successfully hack a government satellite in orbit. Other less technical tactics are also being used to steal information.

SpyCloud raises $110 million to accelerate identity threat protection

24 August 2023
Its latest solution, SpyCloud Compass, enables Post-Infection Remediation of malware exposures, including the compromised assets most likely to lead to ransomware attacks.

HP Report Details Tactics Used to Evade Detection Tools

24 August 2023
None of these attacks are especially sophisticated, but they do show how cybercriminals are shifting their attack techniques by combining techniques in different ways to evade detection.

DarkGate Reloaded via Malvertising and SEO Poisoning Campaigns

24 August 2023
Two blog posts came out in early August, identifying new DarkGate attacks. Advanced IP Scanner is a popular tool used by IT administrators. Victims who click on the ad are presented with a decoy site.

Safe Online Surfing Launching for 2023-2024 School Year | Federal Bureau of Investigation

24 August 2023
The SOS program, created for students in third through eighth grades, covers topics like cyberbullying, passwords, malware, social media, and more. It also provides teachers with a curriculum that meets state and federal internet safety mandates.

Redline Stealer Demonstrates a Low-Barrier-to-Entry Threat

24 August 2023
Variants analyzed can target multiple browsers, including Firefox, Edge, Chrome, and Brave. It can log keystrokes, target Coinomi crypto-wallets, and provide thorough fingerprinting of the local system.

Brazil’s Top Escort Service Exposes Millions of Escort and Client Data

24 August 2023
The exposed data encompassed a vast array of information from the logging database containing around 14.7 million records, totalling a size of approximately 19.17 GB, to the AWS cloud storage which held over 3.5 million files.

Thousands of Unpatched Openfire XMPP Servers Still Exposed to High-Severity Flaw

24 August 2023
Thousands of Openfire XMPP servers are unpatched against a recently disclosed high-severity flaw and are susceptible to a new exploit, according to a new report from VulnCheck. Tracked as CVE-2023-32315 (CVSS score: 7.5), the vulnerability relates to a path traversal vulnerability in Openfire's administrative console that could permit an unauthenticated attacker to access otherwise restricted

Tornado Cash Founders Charged in Billion-Dollar Crypto Laundering Scandal

24 August 2023
The U.S. Justice Department (DoJ) on Wednesday unsealed an indictment against two founders of the now-sanctioned Tornado Cash cryptocurrency mixer service, charging them with laundering more than $1 billion in criminal proceeds. Both the individuals, Roman Storm and Roman Semenov, have been charged with conspiracy to commit money laundering, conspiracy to commit sanctions violations, and

Threat Actors Leverage LLMs-related Facebook Ads to Steal Credentials

24 August 2023
Threat actors were seen exploiting paid Facebook promotions to disseminate malicious code, aiming to deploy a harmful browser add-on for credential theft. Going by the keywords and variables noticed within the malicious script, researchers believe that Vietnamese threat actors could be behind the attack. To prevent falling victim to the ongoing attack campaign, Facebook users are advised to exercise caution when interacting with advertisements.

Security leaders report misalignment of investments and risk reduction

23 August 2023
Sixty-seven percent of organizations experienced a breach requiring attention within the last two years according to a recent Critical Start report.

Thoma Bravo Merges ForgeRock with Ping Identity

23 August 2023
Private equity powerhouse Thoma Bravo on Wednesday announced plans to merge the just-acquired ForgeRock with Ping Identity, combining two of the biggest names in the enterprise identity and access management market.

FBI Says North Korea’s Lazarus Hackers Behind Recent Crypto Heists

23 August 2023
June saw three headline-grabbing incidents involving cryptocurrency companies: a $100 million hack of Atomic Wallet on June 2, as well as two June 22 attacks in which cybercriminals stole $60 million from Alphapo and $37 million from CoinsPaid.

3,000 Openfire Servers Exposed to Attacks Targeting Recent Vulnerability

23 August 2023
Tracked as CVE-2023-32315, the high-severity flaw was discovered in Openfire’s administration console and is described as a path traversal bug via the setup environment that allows unauthenticated attackers to access restricted pages.

University of Minnesota Investigates Alleged Data Breach Involving Seven Million Alumni

23 August 2023
The University of Minnesota has contacted law enforcement and launched an investigation into a data breach that could impact millions of alumni. A hacker claimed to have collected 7 million Social Security numbers in July.

CISA Prioritizing On-Site K-12 Cybersecurity Reviews This School Year

23 August 2023
The assessments can encompass a wide range of individualized reviews and actions, from preventing cyber-enabled fraud schemes to combating ransomware attacks and other digital intrusions.

First Weekly Chrome Security Update Patches High-Severity Vulnerabilities

23 August 2023
Google this week announced a Chrome 116 security update that patches five memory safety vulnerabilities reported by external researchers, including four issues rated ‘high severity’.

Healthcare delivery organizations report concern over malware

23 August 2023
Healthcare delivery organizations' (HDOs) cybersecurity was analyzed in a recent report by Asimily, finding concerns over ransomware and malware.

Report: Ransomware Attackers' Dwell Time Shrinks

23 August 2023
Ransomware-wielding hackers are moving faster than ever to pull the trigger on malicious encryption - but they could be bumping up against the limits of how fast they can go, said security researchers from Sophos.