Latest Cybersecurity News and Articles
11 August 2023
The most serious of the patched flaws, based on their CVSS score, are 18 high-severity issues allowing privilege escalation or, in a few cases, denial-of-service (DoS) attacks.
11 August 2023
Tampa General Hospital is facing at least three proposed federal class action lawsuits filed in recent days following the nonprofit Florida healthcare provider's disclosure late last month of a data theft incident that affected 1.3 million people.
11 August 2023
FortiGuard Labs has discovered a new injector written in the programming language Rust, which injects shellcode and introduces a malware called XWorm into a victim's system.
11 August 2023
The $17.7 million insider funding round brings the total raised by the data security company to more than $35 million. ForgePoint Capital, Prefix Capital, W11 Capital Management, and TSG (The Syndicate Group) participated in the latest funding round.
11 August 2023
German software giant SAP has fixed more than a dozen new vulnerabilities with its August 2023 Patch Tuesday updates, including a critical flaw affecting the company’s PowerDesigner data modeling and enterprise architecture product.
11 August 2023
Ransomware groups are shifting their tactics from relying on phishing methods and are now prioritizing the exploitation of vulnerabilities to exfiltrate data from victims' systems. Additionally, these groups have adopted a more assertive strategy to extort and capitalize on vulnerabilities. They even invest in various avenues for financial profit, such as collaborating with other hackers to identify weaknesses in their ransomware code or leveraging Initial Access Brokers (IABs) to gain entry to their target victims.
11 August 2023
A set of 15 high-severity security flaws have been disclosed in the CODESYS V3 software development kit (SDK) that could result in remote code execution and denial-of-service under specific conditions, posing risks to operational technology (OT) environments.
The flaws, tracked from CVE-2022-47379 through CVE-2022-47393 and dubbed CoDe16, carry a CVSS score of 8.8 with the exception of
10 August 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched security flaw in Microsoft's .NET and Visual Studio products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
Tracked as CVE-2023-38180 (CVSS score: 7.5), the high-severity flaw relates to a case denial-of-service (DoS) impacting .NET and Visual Studio.
It
10 August 2023
Cyberattacks against financial organizations were analyzed in a recent report, finding that 77% saw an increase in cyberattack frequency.
10 August 2023
In an effort to protect sensitive technology, President Biden signed an executive order on regulating U.S. security technology investments.
10 August 2023

The police’s error is hard to forgive, but ministers must treat Northern Ireland’s wider human safety needs as a priority tooA new documentary film recounts a grim story from the Northern Ireland Troubles. Half a century ago, Thomas Niedermayer was a German businessman living in Belfast. At Christmas in 1973, he was kidnapped from his home by the IRA, possibly to be traded for imprisoned bombers, and murdered. His body was found in a shallow grave in 1980. Ten years on, his widow, Ingeborg, took her own life. A year after that, the Niedermayers’ younger daughter, Renate, killed herself. Another two years later, their elder daughter, Gabriella, did the same.The Niedermayer murder, as detailed in the Face Down documentary, was vicious. For the family, the damage lasted for generations, creating new victims and further tragedies. The lesson is frighteningly timely. This week, the Police Service of Northern Ireland mistakenly published an online spreadsheet detailing the surnames, initials, ranks or grades, locations and departments of all current PSNI officers and civilian staff members. The spreadsheet was not taken down for three hours. Approximately 10,000 people were listed. The consequences could endure for decades. Continue reading...
10 August 2023
The $12 million seed round was led by Glilot Capital Partners, with participation from CyberArk Ventures and a number of angel investors including Gerhard Eschelbeck, a former CISO at Google, and Travis McPeak, who led product security at Databricks.
10 August 2023
The findings come from the University of Toronto's Citizen Lab, which carried out an analysis of the encryption mechanism used in Tencent's Sogou Input Method, an app that has over 455 million monthly active users across Windows, Android, and iOS.
10 August 2023
“Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform. We encourage all users to update to the latest version of Android where possible,” Google noted in its security bulletin.
10 August 2023
A popular bulletproof hosting platform was taken down by authorities in the U.S. and Poland this week, marking the latest effort to limit the anonymous access cybercriminals have to critical tools.
10 August 2023
Adobe on Tuesday rolled out a big batch of security updates for its flagship Acrobat and Reader software, patching at least 30 vulnerabilities affecting Windows and macOS installations.
10 August 2023
According to a fraud report, while the overall volume of spam calls declined from Q1, data collected showed that the rate of fraud calls increased.
10 August 2023
The mass exploit of a zero-day vulnerability in MOVEit has compromised more than 600 organizations and 40 million individuals to date, but the numbers mask a more disastrous outcome that’s still unfolding.
10 August 2023
Malicious actors are using a legitimate Rust-based injector called Freeze[.]rs to deploy a commodity malware called XWorm in victim environments.
The novel attack chain, detected by Fortinet FortiGuard Labs on July 13, 2023, is initiated via a phishing email containing a booby-trapped PDF file. It has also been used to introduce Remcos RAT by means of a crypter called SYK Crypter, which was
10 August 2023
A new information malware strain called Statc Stealer has been found infecting devices running Microsoft Windows to siphon sensitive personal and payment information.
"Statc Stealer exhibits a broad range of stealing capabilities, making it a significant threat," Zscaler ThreatLabz researchers Shivam Sharma and Amandeep Kumar said in a technical report published this week.
"It can steal