Latest Cybersecurity News and Articles


2,000 Citrix NetScaler Instances Backdoored via Recent Vulnerability

16 August 2023
Tracked as CVE-2023-3519, the critical vulnerability was disclosed last month as a zero-day, being exploited since June 2023, including in attacks against critical infrastructure organizations.

Nearly 2,000 Citrix NetScaler Instances Hacked via Critical Vulnerability

16 August 2023
Nearly 2,000 Citrix NetScaler instances have been compromised with a backdoor by weaponizing a recently disclosed critical security vulnerability as part of a large-scale attack. "An adversary appears to have exploited CVE-2023-3519 in an automated fashion, placing web shells on vulnerable NetScalers to gain persistent access," NCC Group said in an advisory released Tuesday. "The adversary can

22% of BlackHat USA attendants believe AI takeover is already here

15 August 2023
BlackHat USA attendants were surveyed by Delinea, finding that of 100 attendees polled, 54% said that "passwordless" is a viable concept.

Cybercriminals Abusing Cloudflare R2 for Hosting Phishing Pages, Experts Warn

15 August 2023
Threat actors' use of Cloudflare R2 to host phishing pages has witnessed a 61-fold increase over the past six months. "The majority of the phishing campaigns target Microsoft login credentials, although there are some pages targeting Adobe, Dropbox, and other cloud apps," Netskope security researcher Jan Michael said. Cloudflare R2, analogous to Amazon Web Service S3, Google Cloud Storage, and

Multiple Flaws Found in ScrutisWeb Software Exposes ATMs to Remote Hacking

15 August 2023
Four security vulnerabilities in the ScrutisWeb ATM fleet monitoring software made by Iagona could be exploited to remotely break into ATMs, upload arbitrary files, and even reboot the terminals. The shortcomings were discovered by the Synack Red Team (SRT) following a client engagement. The issues have been addressed in ScrutisWeb version 2.1.38. "Successful exploitation of these

Georgia Healthcare System Notifies 180,000 People of Breach After Suffering Ransomware Attack

15 August 2023
The apparent Hive ransomware attack on the Tift Regional Health System involved hackers accessing and copying files containing patient information, including medical and banking account information.

Most DDoS Attacks Tied to Gaming, Business Disputes, FBI and Prosecutors Say

15 August 2023
The majority of distributed denial-of-service (DDoS) attacks are launched in response to disputes over business or gaming, according to federal officials investigating the incidents.

UK: Norfolk and Suffolk Police Admit Breach Involving Personal Data of 1,230 People

15 August 2023
Two police forces in England have admitted mishandling the sensitive data of victims, witnesses, and suspects in cases including domestic abuse incidents, sexual offenses, assaults, thefts, and hate crime.

Protect AI Purchases Huntr to Extend Bug Bounties to AI, ML

15 August 2023
The Seattle-based AI and ML security vendor said its acquisition of Seattle-based Huntr will allow customers to discover exploits in the artificial intelligence or machine learning supply chain weeks before they're publicly revealed.

67% of government agencies claim confidence in adopting zero trust

15 August 2023
A recent Swimlane report analyzed federal agencies' confidence level and adoption of zero trust requirements following a 2022 executive order.

FBI Warns of Mobile Beta-Testing Apps Harboring Crypto Investment Scams

15 August 2023
The apps are typically used in crypto investment scams, with victims directed to download them via other scams, the FBI said in a Public Service Announcement (PSA) yesterday.

Monti Ransomware Returns with New Linux Variant and Enhanced Evasion Tactics

15 August 2023
The threat actors behind the Monti ransomware have resurfaced after a two-month break with a new Linux version of the encryptor in its attacks targeting government and legal sectors. Monti emerged in June 2022, weeks after the Conti ransomware group shut down its operations, deliberately imitating the tactics and tools associated with the latter, including its leaked source code. Not anymore.

MaginotDNS Attacks Exploit Weak Checks for DNS Cache Poisoning

15 August 2023
A team of researchers from UC Irvine and Tsinghua University has developed a new powerful cache poisoning attack named 'MaginotDNS,' that targets Conditional DNS (CDNS) resolvers and can compromise entire TLDs top-level domains.

New Windows Malware QwixxRAT Appears in the Threat Landscape

15 August 2023
According to the experts, QwixxRAT is meticulously designed to steal a broad range of information, including data from browser histories, credit card details, screenshots, and keystrokes.

North Korean Hackers Suspected in New Wave of Malicious NPM Packages

15 August 2023
The npm package registry has emerged as the target of yet another highly targeted attack campaign that aims to entice developers into downloading malicious software modules.

Malware Unleashed: Public Sector Hit in Sudden Surge, Reveals New Report

15 August 2023
The just-released BlackBerry Global Threat Intelligence Report reveals a 40% increase in cyberattacks against government and public service organizations versus the previous quarter. This includes public transit, utilities, schools, and other government services we rely on daily. With limited resources and often immature cyber defense programs, these publicly funded organizations are struggling

Discord.io Custom Invite Service Confirms Breach After Hacker Steals Data of 760K Users

15 August 2023
The most sensitive information in the breach is a member's username, email address, billing address (small number of people), salted and hashed password (small number of people), and Discord ID.

Dallas to Pay Vendors $8.6m for Their Ransomware Recovery Services

15 August 2023
The bill covers invoices from “various vendors for emergency purchases of hardware, software, professional services, consultants and monitoring services,” the city said in a statement.

FBI Warns of Increasing Cryptocurrency Recovery Scams

15 August 2023
The FBI is warning of an increase in online scammers pretending to be recovery companies that can help victims of cryptocurrency investment scams recover their lost assets.

Norfolk and Suffolk police identify breach of personal data of 1,230 people

15 August 2023
Norfolk and Suffolk police identify breach of personal data of 1,230 people Personal information of people including victims of crime was included in freedom of information responses, forces sayThe personal data of more than 1,000 people, including victims of crime, was included in freedom of information (FoI) responses issued by Norfolk and Suffolk police, the forces have said.In a statement, the two East Anglian constabularies said a “technical issue” meant raw crime report data was included in a “very small percentage” of FoI responses issued between April 2021 and March 2022. Continue reading...