Latest Cybersecurity News and Articles


New Threat Actor Targets Bulgaria, China, Vietnam, and Other Countries With Customized Yashma Ransomware

08 August 2023
The threat actor behind this operation uses an uncommon technique of downloading the ransom note from a GitHub repository, evading detection by embedding it in an embedded batch file.

Report: Two-Thirds of UK Sites Vulnerable to Bad Bots

08 August 2023
The majority (66%) of UK websites are unable to block simple bot attacks, exposing their businesses to fraud, account compromise, and much more, according to a report by DataDome.

QakBot Malware Operators Expand C2 Network with 15 New Servers

08 August 2023
The operators associated with the QakBot (aka QBot) malware have set up 15 new command-and-control (C2) servers as of late June 2023. The findings are a continuation of the malware's infrastructure analysis from Team Cymru, and arrive a little over two months after Lumen Black Lotus Labs revealed that 25% of its C2 servers are only active for a single day. "QakBot has a history of taking an

Invisible Ad Fraud Campaign Targets South Korean Android Users

08 August 2023
The discovery by McAfee’s Mobile Research Team shed light on a trend where certain apps distributed through Google Play discreetly load ads while the user’s device screen is turned off.

White House Pushes Cybersecurity Defense for K-12 Schools

08 August 2023
Typically understaffed and underfunded when it comes to cybersecurity, American K-12 schools have experienced a ramp-up in ransomware attacks, particularly after the pandemic forced the hasty adoption of remote tools for teaching.

HHS Warns Healthcare Sector of Attacks by Rhysida Ransomware Group

08 August 2023
Authorities are sounding the alarm about double-extortion attacks against healthcare and public health sector organizations by a relatively new ransomware-as-a-service group, Rhysida, which until recently had mainly focused on other industries.

CISA Unveils Cybersecurity Strategic Plan for Next Three Years

08 August 2023
The Cybersecurity Strategic Plan for fiscal years 2024-2026 outlines the agency’s plans for achieving a future where damaging cyberattacks are rare, organizations are resilient, and technology is secure by design.

Hackers Abusing Cloudflare Tunnels for Covert Communications

08 August 2023
New research has revealed that threat actors are abusing Cloudflare Tunnels to establish covert communication channels from compromised hosts and retain persistent access. "Cloudflared is functionally very similar to ngrok," Nic Finn, a senior threat intelligence analyst at GuidePoint Security, said. "However, Cloudflared differs from ngrok in that it provides a lot more usability for free,

Massive Phishing Campaign Impersonates 340 Companies Using Over 800 Scam Domains

08 August 2023
The phishing operation, originating from Russia but pretending to be Ukrainian, utilized a high-quality single-page application to create convincing websites and steal credit card and bank details.

UK electoral registers hacked by ‘hostile actors’, elections watchdog reveals

08 August 2023
UK electoral registers hacked by ‘hostile actors’, elections watchdog reveals Elections watchdog says it is unable to say conclusively what information was accessed in cyber-attackThe UK’s elections watchdog has been targeted by a cyber-attack that enabled “hostile actors” to access electoral registers.The Electoral Commission revealed it had been hacked but was “not able to know conclusively” what information had been accessed and said it apologised to people whose information was accessible to the hackers. Continue reading...

Study: Higher education leaders see security as top priority

08 August 2023
A new study found that top institutional leaders are increasingly focused on improving both physical and network security.

UK: Over 200 Million Brits Have Data Compromised in Four Years

08 August 2023
Interestingly, the analysis also revealed that malicious attacks such as malware, phishing, and ransomware accounted for just a third (33%) of breaches reported to the ICO, versus 40% of incidents caused by insider threats.

CISA joins partners to warn of routinely exploited vulnerabilities   

08 August 2023
A joint advisory urges organizations to implement secure by design practices and prioritize patching known exploited vulnerabilities to reduce risk of compromise.

North Korean Hackers Compromise Sanctioned Russian Missile Engineering Company

08 August 2023
A recent investigation by cybersecurity firm SentinelLabs has revealed that North Korean hackers have targeted a Russian missile engineering organization called NPO Mashinostroyeniya.

DHS Grants $375 Million to State and Local Government Cyber-Resilience Efforts

08 August 2023
The State and Local Cybersecurity Grant Program (SLCGP), now in its second year, is a $1 billion fund with allocations spanning four years and specifically targeting state, local, and territorial government cyber resilience efforts.

Points.com Vulnerabilities Allowed Customer Data Theft, Rewards Program Hacking

08 August 2023
Multiple vulnerabilities in the popular airline and hotel rewards platform points.com could have allowed attackers to access users’ personal information, security researchers warn.

Stealthy npm Malware Exposes Developer Data

08 August 2023
Upon analyzing the attack code, Phylum uncovered that it utilized a combination of post-install hooks and pre-install scripts to trigger the execution of malicious code once the packages were installed.

Budget Constraints Threaten Cybersecurity in Government Bodies

08 August 2023
Government organizations and public services are increasingly targeted by cyberattacks from both nation-states and cybercriminals, necessitating the need for stronger cybersecurity measures.

Understanding Active Directory Attack Paths to Improve Security

08 August 2023
Introduced in 1999, Microsoft Active Directory is the default identity and access management service in Windows networks, responsible for assigning and enforcing security policies for all network endpoints. With it, users can access various resources across networks. As things tend to do, times, they are a'changin' – and a few years back, Microsoft introduced Azure Active Directory, the

Update: All Versions of Ivanti Product Affected by Vulnerability Used in Norway Government Attack

08 August 2023
“Since originally reporting CVE-2023-35082… Ivanti has continued its investigation and has found that this vulnerability impacts all versions of Ivanti Endpoint Manager Mobile 11.10, 11.9, and 11.8 and MobileIron Core 11.7 and below,” Ivanti said.