Latest Cybersecurity News and Articles


NIST Releases Draft Overhaul of Its Core Cybersecurity Framework

10 August 2023
The National Institute of Standards and Technology released a long-anticipated draft version of the Cybersecurity Framework 2.0 Tuesday, the first major update of the agency’s risk guidance since 2014.

Pro-Russian Hacker Group Claims Attacks on French, Dutch Websites

10 August 2023
The latest attacks come a week after the group, NoName057(16), hit Spanish and Italian government and private sector organizations with distributed denial-of-service (DDoS) attacks.

Report: 37% Of Third-Party Applications Have High-Risk Permissions

10 August 2023
Examining data since 2013, Abnormal identified a massive increase in third-party apps integrated with email, underscoring the proliferation of an emerging threat vector that cybercriminals are exploiting as they continue to shift their tactics.

China-Linked Hackers Strike 17 Nations in Three-Year-Long Cyber Campaign

10 August 2023
Hackers associated with China's Ministry of State Security (MSS) have been linked to attacks in 17 different countries in Asia, Europe, and North America from 2021 to 2023.

Private network adoption grows as enterprises seek greater control and security

10 August 2023
A market survey of prospective enterprises by Spirent reveals that security and network resiliency are key drivers motivating enterprises to consider private networking, fuelling a market forecast to reach $7.7 billion by 2027.

C-Level Executives at Over 100 Firms Targeted in Massive Cloud Account Takeover Scheme Using EvilProxy

10 August 2023
Most of the attacks targeted high-ranking executives. The researchers estimated that the campaign targeted over 100 organizations globally, collectively representing 1.5 million employees.

Security leaders chime in on new SEC disclosure rules

10 August 2023
Security leaders discuss the recent vote by Securities and Exchange Commission (SEC) to adopt final rules on cybersecurity disclosure.

White House Launches AI Cyber Challenge to Make Software More Secure

10 August 2023
The Biden-Harris Administration has launched a major two-year competition using AI to protect the United States’ most important software, such as code that helps run the internet and critical infrastructure.

Breach Connected to MOVEit Flaw Affects Missouri Medicaid Recipients

10 August 2023
The Missouri Department of Social Services (DSS) has issued an alert urging residents to safeguard their personal information following a cyberattack originating from a data security breach at IBM Consulting in May 2023.

Encryption Flaws in Popular Chinese Language App Put Users' Typed Data at Risk

10 August 2023
A widely used Chinese language input app for Windows and Android has been found vulnerable to serious security flaws that could allow a malicious interloper to decipher the text typed by users. The findings from the University of Toronto's Citizen Lab, which carried out an analysis of the encryption mechanism used in Tencent's Sogou Input Method, an app that has over 455 million monthly active

Emerging Attacker Exploit: Microsoft Cross-Tenant Synchronization

10 August 2023
Attackers continue to target Microsoft identities to gain access to connected Microsoft applications and federated SaaS applications. Additionally, attackers continue to progress their attacks in these environments, not by exploiting vulnerabilities, but by abusing native Microsoft functionality to achieve their objective. The attacker group Nobelium, linked with the SolarWinds attacks, has been

Data of All Serving Police Officers Police Service of Northern Ireland Mistakenly Published Online

10 August 2023
The Police Service of Northern Ireland (PSNI) has mistakenly shared sensitive data of all 10,000 serving police officers in response to a Freedom of Information (FOI) request. The request aimed at determining the number of PSNI officers.

Ukraine Says It Thwarted Attempt to Breach Military Tablets

10 August 2023
Ukraine’s security service, the SBU, attributed the attack to the infamous hacking group known as Sandworm, working on behalf of GRU, the Russian military intelligence agency. The SBU said it was able to stop the operation during the planning phase.

New Zero-Day Vulnerabilities Could Instantly Drain Crypto Wallets

10 August 2023
Multiple zero-day vulnerabilities have been discovered in some of the most used cryptographic multi-party computation (MPC) protocols, putting consumers’ cryptocurrency funds at risk of theft.

Google to fight hackers with weekly Chrome security updates

10 August 2023
Google has changed the Google Chrome security updates schedule from bi-weekly to weekly to address the growing patch gap problem that allows threat actors extra time to exploit published n-day and zero-day flaws.

Newly Discovered Inception Attack Exposes Data from AMD Zen CPUs

10 August 2023
A recent disclosure highlights a fresh wave of vulnerabilities, with a major focus on AMD's 'Inception.' This vulnerability enables data leakage through a novel attack approach. Any system with an affected CPU can potentially be the target of the attack. AMD has released microcode in “Zen 3” and “Zen 4” CPU architectures to fully mitigate the attack.

Balada Injector Still at Large – New Domains Discovered

10 August 2023
The Balada Injector malware continues to evade security software by using new domain names and obfuscation techniques, posing a persistent threat to vulnerable WordPress websites.

Cybercriminals Increasingly Using EvilProxy Phishing Kit to Target Executives

10 August 2023
Threat actors are increasingly using a phishing-as-a-service (PhaaS) toolkit dubbed EvilProxy to pull off account takeover attacks aimed at high-ranking executives at prominent companies. According to Proofpoint, an ongoing hybrid campaign has leveraged the service to target thousands of Microsoft 365 user accounts, sending approximately 120,000 phishing emails to hundreds of organizations

Report: Threat Actors Abuse Valid Accounts Using Manual Tactics

10 August 2023
Threat actors are spurning the rise of automation and using manual tactics to intrude organizations’ networks and rapidly access sensitive data, according to CrowdStrike’s 2023 Threat Hunting Report released Tuesday.

Open Source Tool Used to Target Ukrainian Government Agencies

10 August 2023
Ukrainian government agencies were targeted by hackers in a phishing campaign that utilized the open-source program MerlinAgent. The campaign was conducted by UAC-0154 and involved sending malicious emails to the targets. As attackers adapt their techniques, vigilance becomes paramount.