Latest Cybersecurity News and Articles
21 August 2023
Seiko apologized to the potentially impacted customers and business partners and urged them to be vigilant against email or other communication attempts potentially impersonating Seiko.
21 August 2023
The HiatusRAT malware group reemerged to target Taiwan-based organizations and a U.S. military procurement system allegedly to snoop on military contracts. The audacity of threat actors is evident in their disregard for previous disclosures and their minimal efforts to change their payload servers. The IOCs from this campaign are available for organizations to proactively take action in thwarting such threats.
21 August 2023
The CraxsRAT builder, Cyfirma says, generates highly obfuscated packages, allowing threat actors to customize the contents based on the type of attack they are preparing, including with WebView page injections.
21 August 2023
According to a recent Strata Identity report, 60% of organizations do not have the resources or time to rewrite old, outdated applications.
21 August 2023
A notification letter sent to impacted people reveals that the data breach is related to a couple of former employees sending confidential information to German media outlet Handelsblatt.
21 August 2023
The new policy, National Credit Union Administration (NCUA) announced, comes into effect on September 1, and will cover all incidents that impact information systems or the integrity, confidentiality, or availability of data on those systems.
21 August 2023
A high-severity security flaw has been disclosed in the WinRAR utility that could be potentially exploited by a threat actor to achieve remote code execution on Windows systems.
Tracked as CVE-2023-40477 (CVSS score: 7.8), the vulnerability has been described as a case of improper validation while processing recovery volumes.
"The issue results from the lack of proper validation of user-supplied
21 August 2023
The organization that manages Australia’s internet domain .au denied that it was affected by a data breach on Friday after a ransomware gang added it to their list of victims.
21 August 2023
The SLED focused Cybersecurity Insights Report highlights how leaders are budgeting differently for the industry’s top edge use cases.
21 August 2023
The feature, set for release alongside Chrome 117, allows users to be notified when an add-on has been unpublished by a developer, taken down for violating Chrome Web Store policy, or marked as malware.
21 August 2023
The threat actors behind the HiatusRAT malware have returned from their hiatus with a new wave of reconnaissance and targeting activity aimed at Taiwan-based organizations and a U.S. military procurement system.
21 August 2023
The Cuba ransomware group has been seen deploying a comprehensive toolset. The criminals used a couple of exploits - Veeam Backup & Replication vulnerability (CVE-2023-27532) and the ZeroLogon bug (CVE-2020-1472) against critical Infrastructure sector in the U.S. and Latin America-based IT integrator.
21 August 2023
Google added generative AI technology to its OSS-FUZZ project (a free service that runs fuzzers for open-source projects) and discovered a massive improvement in code coverage when LLMs are used to create new fuzz targets.
21 August 2023
Suspected North Korean hackers have attempted an attack targeting a major joint military exercise between Seoul and Washington that starts on Monday, South Korean police said.
21 August 2023
ProjectDiscovery today announced that it raised $25 million in a Series A funding round led by CRV with participation from Point72, SignalFire, Rain Capital, Mango Capital, Accel, and Lightspeed.
21 August 2023
From a user’s perspective, OAuth works like magic. In just a few keystrokes, you can whisk through the account creation process and gain immediate access to whatever new app or integration you’re seeking. Unfortunately, few users understand the implications of the permissions they allow when they create a new OAuth grant, making it easy for malicious actors to manipulate employees into giving
21 August 2023
The U.S. intelligence agencies are warning about unnamed foreign intelligence entities targeting the private space sector to steal sensitive data related to satellite payloads and disrupting and degrading US satellite capabilities.
21 August 2023
A recent cybersecurity study has brought to light a concerning vulnerability crisis affecting web applications. A substantial 74% of assets housing personally identifiable information (PII) as susceptible to well-known significant exploits.
21 August 2023
Threat actors are leveraging access to malware-infected Windows and macOS machines to deliver a proxy server application and use them as exit nodes to reroute proxy requests.
According to AT&T Alien Labs, the unnamed company that offers the proxy service operates more than 400,000 proxy exit nodes, although it's not immediately clear how many of them were co-opted by malware installed on
21 August 2023
Requiring companies to report unpatched vulnerabilities before adequate fixes could potentially lead to information misuse and make organizations and EU citizens less secure.