Latest Cybersecurity News and Articles


Report finds exposed sensitive data in more than 30% of cloud assets

16 August 2023
A new report reveals that more than 30% of cloud data assets contain sensitive information.

Experts Uncover Weaknesses in PowerShell Gallery Enabling Supply Chain Attacks

16 August 2023
The flaws have to do with the service's lax policy surrounding package names, lacking protections against typosquatting attacks, as a result enabling attackers to upload malicious PowerShell modules that appear genuine to unsuspecting users.

Chamber of Commerce Urges SEC to Delay Cyber Rule Implementation

16 August 2023
The U.S. Chamber of Commerce urged the Securities and Exchange Commission to delay by a year the effective date of new cybersecurity rules, saying the regulatory move could otherwise have “severe consequences” for companies.

Scott Sykes joins Asurity as Chief Information Security Officer

16 August 2023
Scott Sykes has been hired as CISO at Asurity Technologies. Sykes was previously CISO at Netcracker Technology and Tata Communications.

Raccoon Stealer Malware Returns With New Stealthier Version

16 August 2023
The developers of Raccoon Stealer information-stealing malware have ended their 6-month hiatus from hacker forums to promote a new 2.3.0 version of the malware to cybercriminals.

Automotive data privacy under scrutiny in California

16 August 2023
California regulators are examining how automakers and others handle data collected from internet-connected vehicles, the California Privacy Protection Agency said late last month.

Ransomware Attack on Rapattoni Disrupts US Real Estate Property Listings

16 August 2023
Real estate agents' ability to list or update property information has been compromised by an attack on California-based data services company Rapattoni, which hosts multiple listing services.

What's the State of Credential theft in 2023?

16 August 2023
At a little overt halfway through 2023, credential theft is still a major thorn in the side of IT teams. The heart of the problem is the value of data to cybercriminals and the evolution of the techniques they use to get hold of it. The 2023 Verizon Data Breach Investigations Report (DBIR) revealed that 83% of breaches involved external actors, with almost all attacks being financially motivated

Experts Uncover Weaknesses in PowerShell Gallery Enabling Supply Chain Attacks

16 August 2023
Active flaws in the PowerShell Gallery could be weaponized by threat actors to pull off supply chain attacks against the registry's users. "These flaws make typosquatting attacks inevitable in this registry, while also making it extremely difficult for users to identify the true owner of a package," Aqua security researchers Mor Weinberger, Yakir Kadkoda, and Ilay Goldman said in a report shared

Clorox Cleans up Security Breach That Disrupted Operations

16 August 2023
The intrusion continues to disrupt "parts of the company's business operations," and it is "working diligently to respond to and address this issue, and is also coordinating with law enforcement," according to the Form 8-K submission.

Guide: How Google Workspace-based Organizations can leverage Chrome to improve Security

16 August 2023
More and more organizations are choosing Google Workspace as their default employee toolset of choice. But despite the productivity advantages, this organizational action also incurs a new security debt. Security teams now have to find a way to adjust their security architecture to this new cloud workload. Some teams may rely on their existing network security solutions. According to a new guide

Prince George's County Public Schools Responds Suffers Network Outage Owing to Cyberattack

16 August 2023
District leaders initially said they were working to address a “broad network outage” that knocked out email and other services. On Monday night, the district released a statement saying 4,500 of the system’s 180,000 accounts were “impacted.”

Google Introduces First Quantum Resilient FIDO2 Security Key

16 August 2023
Google on Tuesday announced the first quantum resilient FIDO2 security key implementation as part of its OpenSK security keys initiative. "This open-source hardware optimized implementation uses a novel ECC/Dilithium hybrid signature schema that benefits from the security of ECC against standard attacks and Dilithium's resilience against quantum attacks," Elie Bursztein and Fabian Kaczmarczyck 

Critical Security Flaws Affect Ivanti Avalanche, Threatening 30,000 Organizations

16 August 2023
Multiple critical security flaws have been reported in Ivanti Avalanche, an enterprise mobile device management solution that’s used by 30,000 organizations. The vulnerabilities, collectively tracked as CVE-2023-32560 (CVSS score: 9.8), are stack-based buffer overflows in Ivanti Avalanche WLAvanacheServer.exe v6.4.0.0. Cybersecurity company Tenable said the shortcomings are the result of buffer

Ivanti Avalanche Impacted by Critical Pre-Auth Stack Buffer Overflows

16 August 2023
Two stack-based buffer overflows collectively tracked as CVE-2023-32560 impact Ivanti Avalanche, an enterprise mobility management (EMM) solution designed to manage, monitor, and secure a wide range of mobile devices.

LinkedIn Accounts Hacked in Widespread Hijacking Campaign

16 August 2023
As reported today by Cyberint, many LinkedIn users have been complaining about account takeovers or lockouts and an inability to resolve the problems through LinkedIn support.

Knight Ransomware Used in a Spam Campaign Impersonating TripAdvisor

16 August 2023
Knight ransomware, a recycled version of Cyclops ransomware, is being used in an ongoing spam campaign impersonating TripAdvisor.

TIAA Hit With Class-Action Lawsuit Over MOVEit Data Breach

16 August 2023
The breach affected some 2.3 million TIAA clients, according to a lawsuit filed last week in U.S. District Court in New York. The suit alleges TIAA did not use “reasonable security procedures and practices” to protect clients’ sensitive information.

Cybercriminals Abusing Cloudflare R2 for Hosting Phishing Pages, Experts Warn

16 August 2023
The phishing campaigns identified by Netskope not only abuse Cloudflare R2 to distribute static phishing pages, but also leverage its Turnstile offering, a CAPTCHA replacement, to place such pages behind anti-bot barriers to evade detection.

Law Firm Facing Lawsuit in Aftermath of Its Own Big Breach

16 August 2023
The lawsuit complaint stems from a March hacking incident at San Francisco-based Orrick, Herrington & Sutcliffe that compromised the information of nearly 153,000 individuals, including victims of a client's data breach three years ago.