Latest Cybersecurity News and Articles


British Intelligence is Tipping off Ransomware Targets to Disrupt Attacks

22 August 2023
On average, every 72 hours for the past three months, cyber experts at the UK’s NCSC have detected the beginnings of a new ransomware attack against a British organization and then tipped off the target in a bid to prevent the attack from executing.

CISOs Tout SaaS Cybersecurity Confidence, But 79% Admit to SaaS Incidents, New Report Finds

22 August 2023
A new State of SaaS Security Posture Management Report from SaaS cybersecurity provider AppOmni indicates that Cybersecurity, IT, and business leaders alike recognize SaaS cybersecurity as an increasingly important part of the cyber threat landscape. And at first glance, respondents appear generally optimistic about their SaaS cybersecurity. Over 600 IT, cybersecurity, and business leaders at

Australian Software Provider Energy One Hit by Cyberattack

22 August 2023
Wholesale energy software provider Energy One reported on Friday a cyberattack had affected "certain corporate systems" in Australia and the UK. In a statement, the company said analysis is underway to identify which systems have been affected.

Deceptive AI Bots Spread Malware, Raise Security Concerns

22 August 2023
According to a new advisory published by ESET security researchers, the campaign came to light when an advertisement on Facebook promoted the download of what seemed to be the latest version of Google’s authentic AI tool, “Bard.”

TP-Link Smart Bulbs can Let Hackers Steal Your WiFi Password

22 August 2023
Researchers from Italy and the UK have discovered four vulnerabilities in the TP-Link Tapo L530E smart bulb and TP-Link’s Tapo app, which could allow attackers to steal their target’s WiFi password.

Carderbee Attacks: Hong Kong Organizations Targeted via Malicious Software Updates

22 August 2023
A previously undocumented threat cluster has been linked to a software supply chain attack targeting organizations primarily located in Hong Kong and other regions in Asia. The Symantec Threat Hunter Team, part of Broadcom, is tracking the activity under its insect-themed moniker Carderbee. The attacks, per the cybersecurity firm, leverage a trojanized version of a legitimate software called

US CISA Urges Security by Design for AI

22 August 2023
The U.S federal government is advocating for artificial intelligence developers to embrace security as a core requirement, warning that machine learning code is particularly difficult and expensive to fix after deployment.

French Town of Sartrouville Recovering From Cyberattack Claimed by Ransomware Gang

22 August 2023
Officials noted that the town’s IT department has set up a “robust” backup system that allowed them to preserve critical data and “minimize disruption to the operation of municipal services.

Rust Developers Push Back as Serde Project Ships Precompiled Binaries

22 August 2023
Serde is a commonly used serialization and deserialization framework for Rust data structures that, according to its website, is designed to conduct these operations "efficiently and generically."

Critical Adobe ColdFusion Flaw Added to CISA's Exploited Vulnerability Catalog

22 August 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw in Adobe ColdFusion to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

Police Insider Tipped Off Criminal Friend About EncroChat Bust

22 August 2023
An intelligence analyst working for police in the North West of England shared information about a major countrywide operation with a criminal contact, in what has been described as a “disgraceful” betrayal of her colleagues.

Ivanti Warns of New Actively Exploited Sentry Zero-Day Bug

22 August 2023
Discovered and reported by researchers at mnemonic, the critical vulnerability enables unauthenticated attackers to gain access to sensitive admin portal configuration APIs exposed over port 8443, used by MobileIron Configuration Service (MICS).

Australian Lender Latitude Financial Reports $50 Million in Cyberattack Costs

22 August 2023
In a financial report covering the first half of 2023, the consumer lender reported AU$76 million (roughly US$50 million) of pre-tax costs and provisions relating to the cyber incident.

New Variant of XLoader macOS Malware Disguised as 'OfficeNote' Productivity App

22 August 2023
A new variant of an Apple macOS malware called XLoader has surfaced in the wild, masquerading its malicious features under the guise of an office productivity app called "OfficeNote." "The new version of XLoader is bundled inside a standard Apple disk image with the name OfficeNote.dmg," SentinelOne security researchers Dinesh Devadoss and Phil Stokes said in a Monday analysis. "The application

Ivanti Warns of Critical Zero-Day Flaw Being Actively Exploited in Sentry Software

22 August 2023
Software services provider Ivanti is warning of a new critical zero-day flaw impacting Ivanti Sentry (formerly MobileIron Sentry) that it said is being actively exploited in the wild, marking an escalation of its security woes. Tracked as CVE-2023-38035 (CVSS score: 9.8), the issue has been described as a case of authentication bypass impacting versions 9.18 and prior due to what it called an

Critical Adobe ColdFusion Flaw Added to CISA's Exploited Vulnerability Catalog

21 August 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw in Adobe ColdFusion to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability, cataloged as CVE-2023-26359 (CVSS score: 9.8), relates to a deserialization flaw present in Adobe ColdFusion 2018 (Update 15 and earlier) and ColdFusion 2021 (

Customer data used for unwanted romantic contact, UK poll shows

21 August 2023
Customer data used for unwanted romantic contact, UK poll shows Almost one in three people aged 18-34 have been messaged by staff after giving personal details to a businessAlmost one in three people aged 18-34 have received unwanted romantic contact after giving their personal information to a business, a UK poll has shown.The Information Commissioner’s Office (ICO) has called for recipients of such texts to come forward to help the regulator gather evidence of the impact of this phenomenon.The ICO has an online form for people who want to report an experience of unwanted contact. Continue reading...

Detecting malware cited as a challenge for organizations

21 August 2023
According to a report, threat actors leverage malware as an initial foothold to infiltrate targeted infrastructures to gain long-term access.

Sneaky Amazon Google Ad Leads to Microsoft Support Scam

21 August 2023
A fake Amazon ad in Google search results is redirecting users to a tech support scam that poses as a Microsoft Defender alert. The tech support scam locks up the browser in full-screen mode.

Researchers Spoof an Apple Device and Trick Users Into Sharing Sensitive Data

21 August 2023
The spoofed Apple device prompts users to connect their Apple ID or share a password with a nearby Apple TV, allowing threat actors to collect data such as phone numbers and Apple ID emails.