Latest Cybersecurity News and Articles


Ransomware Intrusion Impacts All Servers of Danish Cloud Provider

23 August 2023
The attack occurred on August 18, and since then, efforts have been made to restore the data, but it has proved difficult. CloudNordic has stated that it will not pay the ransom demanded by the hackers.

Supply Chain Attack: Carderbee APT Strikes Hong Kong Organizations

23 August 2023
Undocumented threat cluster Carderbee was observed targeting organizations in Hong Kong and other Asian regions via a trojanized version of the legitimate software EsafeNet Cobra DocGuard Client to deliver the PlugX backdoor and gain access to victim networks. Strengthening supply chain security through thorough vendor assessments and continuous monitoring is essential.

Defense Contractor Belcan Leaks Admin Password With a List of Flaws

23 August 2023
On May 15th, the Cybernews research team discovered an open Kibana instance containing sensitive information regarding Belcan, their employees, and internal infrastructure.

Cybercriminals Turn to AI to Bypass Modern Email Security Measures

23 August 2023
Cybercriminals employ AI to create complex email threats like phishing and business email compromise (BEC) attacks, while modern email security systems use AI to counter these attacks, according to Perception Point and Osterman Research.

Scarab Ransomware Deployed Worldwide via Spacecolon Toolset

23 August 2023
According to an advisory published by ESET, the toolset is believed to gain entry into victim organizations by exploiting vulnerable web servers or leveraging brute-force attacks on Remote Desktop Protocol (RDP) credentials.

North Korean Affiliates Suspected in $40M Cryptocurrency Heist, FBI Warns

23 August 2023
The U.S. Federal Bureau of Investigation (FBI) on Tuesday warned that threat actors affiliated with North Korea may attempt to cash out stolen cryptocurrency worth more than $40 million. The law enforcement agency attributed the blockchain activity to an adversary the U.S. government tracks as TraderTraitor, which is also known by the name Jade Sleet. An investigation undertaken by the FBI found

Open Redirect Flaws Increasingly Exploited by Phishers

23 August 2023
Phishing attacks using open redirect flaws are on the rise again, according to Kroll’s Cyber Threat Intelligence (CTI) team, which means organizations should consider refreshing employees’ awareness and knowledge on how to spot them.

Meta Set to Enable Default End-to-End Encryption on Messenger by Year End

23 August 2023
Meta has once again reaffirmed its plans to roll out support for end-to-end encryption (E2EE) by default for one-to-one friends and family chats on Messenger by the end of the year. As part of that effort, the social media giant said it's upgrading "millions more people's chats" effective August 22, 2023, exactly seven months after it started gradually expanding the feature to more users in

Scraped Data of 2.6 Million DuoLingo Users Released on Hacking Forum

23 August 2023
This data includes a mixture of public login and real names, and non-public information, including email addresses and internal information related to the DuoLingo service.

The evolving generative AI risk landscape

23 August 2023
Jeremy Ventura, Director of Security Strategy & Field CISO at ThreatX, discusses challenges associated with the use of generative AI in cybersecurity, and more. in this episode of The Security Podcast.

Less than 50% of companies have API security testing tools in place

23 August 2023
A new survey highlights what application security professionals view as the top security risks related to Application Programming Interfaces (APIs).

Report reveals insights on cybersecurity conversations with children

23 August 2023
A new study reveals 30% of parents haven't had conversations with their children about cybersecurity.

Syrian Threat Actor EVLF Unmasked as Creator of CypherRAT and CraxsRAT Android Malware

23 August 2023
A Syrian threat actor named EVLF has been outed as the creator of malware families CypherRAT and CraxsRAT. "These RATs are designed to allow an attacker to remotely perform real-time actions and control the victim device's camera, location, and microphone," Cybersecurity firm Cyfirma said in a report published last week. CypherRAT and CraxsRAT are said to be offered to other cybercriminals as

Agile Approach to Mass Cloud Credential Harvesting and Crypto Mining Sprints Ahead

23 August 2023
Developers are not the only people who have adopted the agile methodology for their development processes. From 2023-06-15 to 2023-07-11, Permiso Security’s p0 Labs team identified and tracked an attacker developing and deploying eight (8) incremental iterations of their credential harvesting malware while continuing to develop infrastructure for an upcoming (spoiler: now launched) campaign

Fake Roblox Packages Target NPM With Luna Grabber Information-Stealing Malware

23 August 2023
Researchers at ReversingLabs have discovered a malicious campaign targeting Roblox developers on the npm public repository. The campaign involves malicious packages that imitate the legitimate package noblox.js, a Node.js Roblox API wrapper.

Zoom’s AI terms overhaul sets stage for broader data use scrutiny

23 August 2023
Zoom updated its terms and conditions — again — on Friday following persistent criticism related to language that allowed the company to use customer data to train its AI systems.

Tesla Sues Two Former Employees Over Insider Data Breach

23 August 2023
The Austin, Texas-based electric car manufacturer began notifying affected individuals Friday, as part of its ongoing probe into a May data breach it blamed on "insider wrongdoing."

Report: 15% Drop in Healthcare Breaches, 31% Surge in Victims

23 August 2023
A report from Critical Insight notes an overall decrease of 15% in total breaches during the first half of 2023 compared to the latter half of 2022 – a positive development given the healthcare industry’s previous upward trend in attacks.

Spacecolon Toolset Fuels Global Surge in Scarab Ransomware Attacks

23 August 2023
A malicious toolset dubbed Spacecolon is being deployed as part of an ongoing campaign to spread variants of the Scarab ransomware across victim organizations globally. "It probably finds its way into victim organizations by its operators compromising vulnerable web servers or via brute forcing RDP credentials," ESET security researcher Jakub Souček said in a detailed technical write-up

Profile Stealers Spread via LLM-themed Facebook Ads

23 August 2023
Threat actors are exploiting paid Facebook promotions featuring LLMs to spread malware and steal victims' credentials. The malicious code is distributed through fake profiles and ads promising access to AI tools like Google Bard or Meta AI.