Latest Cybersecurity News and Articles


Over 120,000 Computers Compromised by Info Stealers Linked to Users of Cybercrime Forums

15 August 2023
"Hackers around the world infect computers opportunistically by promoting results for fake software or through YouTube tutorials directing victims to download infected software," Hudson Rock CTO Alon Gal told The Hacker News.

Gigabud RAT Android Banking Malware Targets Institutions Across Countries

15 August 2023
Account holders of over numerous financial institutions in Thailand, Indonesia, Vietnam, the Philippines, and Peru are being targeted by an Android banking malware called Gigabud RAT. "One of Gigabud RAT's unique features is that it doesn't execute any malicious actions until the user is authorized into the malicious application by a fraudster, [...] which makes it harder to detect," Group-IB

Security Researchers Publish Gigabud Banking Malware Analysis

15 August 2023
According to an advisory published by Group-IB researchers, unlike conventional malware, Gigabud doesn’t execute its malicious actions immediately, but waits for user authorization, making it substantially harder to detect.

Researchers Discover Vulnerabilities in Moovit Software Allowing Free Subway Rides

15 August 2023
Cybersecurity researchers at the DEF CON security conference disclosed details this weekend on three vulnerabilities in popular transportation software that could allow people to obtain free public transit rides.

Over 12,000 Computers Compromised by Info Stealers Linked to Users of Cybercrime Forums

15 August 2023
A "staggering" 120,000 computers infected by stealer malware have credentials associated with cybercrime forums, many of them belonging to malicious actors. The findings come from Hudson Rock, which analyzed data collected from computers compromised between 2018 to 2023. "Hackers around the world infect computers opportunistically by promoting results for fake software or through YouTube

Catching the Catphish: Join the Expert Webinar on Combating Credential Phishing

15 August 2023
Is your organization constantly under threat from credential phishing? Even with comprehensive security awareness training, many employees still fall victim to credential phishing scams. The result? Cybercriminals gaining immediate and unhindered access to sensitive data, email accounts, and other applications. But what if you could outsmart these criminals and protect your organization? Join 

NSA, Viasat Say 2022 Hack Was Two Incidents; Russian Sanctions Resulted From Investigation

15 August 2023
Officials from the National Security Agency (NSA) and satellite internet provider Viasat provided new details on the headline-grabbing cyberattack on the company at the onset of Russia’s invasion of Ukraine.

Indian Government Alerts Mobile Users, Issues High Risk Warning for Android 13 and Other Versions

15 August 2023
These vulnerabilities, which have been classified as "high severity," could be exploited by attackers to gain control of vulnerable devices, steal sensitive information, or disrupt operations.

North Korean Hackers Suspected in New Wave of Malicious npm Packages

15 August 2023
The npm package registry has emerged as the target of yet another highly targeted attack campaign that aims to entice developers into downloading malevolent modules. Software supply chain security firm Phylum told The Hacker News the activity exhibits similar behaviors to that of a previous attack wave uncovered in June, which has since been linked to North Korean threat actors. As many as nine

NCSC Cyber Incident Response scheme now available to more organisations

14 August 2023
Help investigating and recovering from cyber attack now available from a larger pool of assured providers.

Diligere, Equity-Invest Are New Firms of U.K. Con Man

14 August 2023
John Clifton Davies, a convicted fraudster estimated to have bilked dozens of technology startups out of more than $30 million through phony investment schemes, has a brand new pair of scam companies that are busy dashing startup dreams: A fake investment firm called Equity-Invest[.]ch, and Diligere[.]co.uk, a scam due diligence company that Equity-Invest insists all investment partners use. A native of the United Kingdom, Mr. Davies absconded from justice before being convicted on multiple counts of fraud in 2015. Prior to his conviction, Davies served 16 months in jail before being cleared on suspicion of murdering his third wife on their honeymoon in India.

Ford Says Wi-Fi Vulnerability Not a Safety Risk to Vehicles

14 August 2023
The issue is described as a buffer overflow that could lead to remote code execution. An attacker within the wireless range of an impacted device can trigger the flaw using a specially crafted frame.

Nine Flaws in CyberPower and Dataprobe Solutions Expose Data Centers to Hacking

14 August 2023
Researchers from Trellix Advanced Research Center discovered multiple vulnerabilities impacting CyberPower’s PowerPanel Enterprise Data Center Infrastructure Management (DCIM) platform and Dataprobe’s iBoot Power Distribution Unit (PDU).

QwixxRAT: New Remote Access Trojan Emerges via Telegram and Discord

14 August 2023
A new remote access trojan (RAT) called QwixxRAT is being advertised for sale by its threat actor through Telegram and Discord platforms. "Once installed on the victim's Windows platform machines, the RAT stealthily collects sensitive data, which is then sent to the attacker's Telegram bot, providing them with unauthorized access to the victim's sensitive information," Uptycs said in a new

Knight Ransomware Distributed in Fake TripAdvisor Complaint Emails

14 August 2023
The Knight ransomware is being distributed in an ongoing spam campaign that pretends to be TripAdvisor complaints. Knight ransomware is a recent rebrand of the Cyclop Ransomware-as-a-Service, which switched its name at the end of July 2023.

The rise in e-commerce forces retailers to adjust IT procedures

14 August 2023
The pandemic-induced rise in e-commerce has led retailers to adjust their IT departments, according to a recent report by Information Services Group.

Iagona ScrutisWeb Vulnerabilities Could Expose ATMs to Remote Hacking

14 August 2023
Several vulnerabilities in the ScrutisWeb ATM could be exploited to remotely hack ATMs. The security holes were discovered by Synack Red Team members and they were patched by the vendor in July 2023 with the release of ScrutisWeb version 2.1.38.

Colorado Warns Four Million of Data Stolen in IBM Moveit Breach

14 August 2023
The Colorado Department of Health Care Policy & Financing (HCPF) is alerting more than four million individuals of a data breach that impacted their personal and health information.

Document ‘from PSNI data leak’ posted on Belfast wall alongside threat

14 August 2023
Document ‘from PSNI data leak’ posted on Belfast wall alongside threat Document with names of police officers redacted placed beside a Sinn Féin office on Falls RoadA document purportedly from the Police Service of Northern Ireland (PSNI) data leak has appeared on a wall in Belfast alongside a threatening message.The document, which had the names of police officers redacted, was posted overnight beside a Sinn Féin office on Falls Road, suggesting dissident republicans had obtained material from last week’s data breach, Gerry Kelly, the party’s policing spokesperson, said on Monday. Continue reading...

Ongoing Xurum Attacks on E-commerce Sites Exploiting Critical Magento 2 Vulnerability

14 August 2023
E-commerce sites using Adobe's Magento 2 software are the target of an ongoing campaign that has been active since at least January 2023. The attacks, dubbed Xurum by Akamai, leverage a now-patched critical security flaw (CVE-2022-24086, CVSS score: 9.8) in Adobe Commerce and Magento Open Source that, if successfully exploited, could lead to arbitrary code execution. "The attacker seems to be