Latest Cybersecurity News and Articles


Israeli Hospital Redirects New Patients Following Ransomware Attack

10 August 2023
An Israeli hospital near the city of Tel Aviv was hacked on Tuesday by a group of unknown cybercriminals, prompting it to stop admitting new patients and redirecting people to nearby hospitals.

Northern Ireland police chief urged to consider position over data breach

10 August 2023
Northern Ireland police chief urged to consider position over data breach DUP MP Sammy Wilson says serious questions must be asked at highest level of PSNI amid fears over safety of officersThe head of policing in Northern Ireland has been urged to consider his position over the mass breach of officers’ data amid warnings that terrorists could use the information to carry out attacks.Sammy Wilson, a Democratic Unionist party MP, suggested Simon Byrne’s future as chief constable might not be sustainable. Continue reading...

High-Severity Access Control Vulnerability Found in Spring WebFlux

10 August 2023
An advisory on the vulnerability published by JFrog shed light on the exact nature of the flaw, its potential victims, and a proof-of-concept (POC) illustrating the scenarios in which this flaw could be triggered for unauthorized access.

AWS Pledges $20M to K-12 Cyber Training, Incident Response

10 August 2023
The company is participating in a larger collaboration between government agencies and private sector partners to help target rich, resource-poor organizations like local schools combat malicious attacks.

Malicious Campaigns Exploit Weak Kubernetes Clusters for Crypto Mining

10 August 2023
In total, Kubernetes clusters belonging to more than 350 organizations, open-source projects, and individuals were discovered, 60% of which were the target of an active crypto-mining campaign.

New Report Exposes Vice Society's Collaboration with Rhysida Ransomware

10 August 2023
Tactical similarities have been unearthed between the double extortion ransomware group known as Rhysida and Vice Society, including in their targeting of education and healthcare sectors.

Interpol Busts Phishing-as-a-Service Platform '16Shop,' Leading to 3 Arrests

10 August 2023
Interpol has announced the takedown of a phishing-as-a-service (PhaaS) platform called 16Shop, in addition to the arrests of three individuals in Indonesia and Japan. 16Shop specialized in the sales of phishing kits that other cybercriminals can purchase to mount phishing attacks on a large scale, ultimately facilitating the theft of credentials and payment details from users of popular services

OpenBullet Campaign: Cybercriminals Target Script Kiddies

10 August 2023
Experienced cybercriminals are taking on script kiddies in a new malware campaign through malicious OpenBullet configuration files. Malicious configurations are shared on platforms like Telegram to deliver a Rust-based dropper and a Python-based RAT named Patent. Adversaries have made a profit in crypto worth $1,703.15 over the past two months.

Building digital trust in an organization

10 August 2023
The importance of digital trust.

Horizon3 AI Raises $40 Million to Expand Automated Pentesting Platform

09 August 2023
The additional funding will help the San Francisco-based company integrate pentesting, SOAR, and detection engineering into its platform and expand its channel and partner presence to fuel global growth.

PSNI apologies to police officers after unprecedented data breach – video

09 August 2023
PSNI apologies to police officers after unprecedented data breach – video The UK Information Commissioner’s Office has launched an investigation into an unprecedented data breach that disclosed details of more than 10,000 police officers and staff in Northern Ireland. The agency, which regulates data privacy laws, is working with the Police Service of Northern Ireland to establish the level of risk amid warnings that the leak may compel officers to leave the force or move their home address. The PSNI blamed human error for releasing an Excel spreadsheet that was published on an FoI website and removed two hours later once police discovered the mistake. Chris Todd, a PSNI assistant chief constable, apologised and said the error was unacceptableICO to investigate risk to police officers after Northern Ireland data breach Continue reading...

Hacked UK voter data could be used to target disinformation, warn experts

09 August 2023
Hacked UK voter data could be used to target disinformation, warn experts Data from Electoral Commission breach could allow rogue actors to create AI-generated messages in effort to manipulate electionsData accessed in the Electoral Commission hack could help state-backed actors target voters with AI-generated disinformation, experts have warned.The UK elections watchdog revealed on Tuesday that a hostile cyber-attack had been able to access the names and addresses of all voters registered between 2014 and 2022. Continue reading...

Data Exfiltration is Now the Go-to Cyber Extortion Strategy

09 August 2023
The abuse of zero-day and one-day vulnerabilities in the past six months led to a 143% increase in victims when comparing Q1 2022 with Q1 2023, according to a report by Akamai.

Large-user applications vulnerable to dependency confusion attacks

09 August 2023
A OX Security report found applications with more than 1 billion users are using dependencies which are vulnerable to dependency confusion attacks.

Hackers Prepare to Take on a Satellite at DEF CON

09 August 2023
The annual Hack-A-Sat CTF competition held at Aerospace Village at the DEF CON in Las Vegas is the first time an on-orbit satellite will test contestants' mettle while bringing together hackers who don’t typically work on space systems.

Social media for research and threat intelligence

09 August 2023
Learn about threat intelligence on this episode of The Security Podcasts with Igal Lytzki, Incident Response team leader at Perception Point.

The Ransomware Rollercoaster Continues as Criminals Advance Their Business Models

09 August 2023
Ransomware shows no signs of slowing, with ransomware activity ending 13 times higher than at the start of 2023 as a proportion of all malware detections, according to Fortinet.

Collide+Power, Downfall, and Inception: New Side-Channel Attacks Affecting Modern CPUs

09 August 2023
Cybersecurity researchers have disclosed details of a trio of side-channel attacks that could be exploited to leak sensitive data from modern CPUs. Called Collide+Power (CVE-2023-20583), Downfall (CVE-2022-40982), and Inception (CVE-2023-20569), the novel methods follow the disclosure of another newly discovered security vulnerability affecting AMD's Zen 2 architecture-based processors known as 

Microsoft Office Update Breaks Actively Exploited RCE Attack Chain

09 August 2023
Microsoft today released a defense-in-depth update for Microsoft Office that prevents exploitation of a remote code execution (RCE) vulnerability tracked as CVE-2023-36884 that threat actors have already leveraged in attacks.

Rubrik Buys Startup Laminar to Unify Cyber Posture, Recovery

09 August 2023
Rubrik purchased a data security posture management startup backed by Salesforce and SentinelOne to provide visibility into where a company's data lives and who has access.