Latest Cybersecurity News and Articles


Spanish Police Arrest Three Behind Payment Card Fraud

08 August 2023
The group mainly targeted ATMs of Spanish national banks using cloned payment cards. Spanish police estimated the group had fraudulently pocketed nearly 196,000 euros (~$215,000).

Report: Manufacturing Sector Lost $46 Billion to Ransomware Attacks

08 August 2023
Ransomware attacks on manufacturing organizations have surged annually, resulting in substantial financial losses, with a recent report by Comparitech revealing that the sector suffered $46 billion in downtime since 2018. So far 56 manufacturing organizations have been targeted in ransomware attacks, this year. 

TargetCompany Ransomware Abuses FUD Obfuscator Packers

08 August 2023
The TargetCompany ransomware is using fully undetectable (FUD) packers and Metasploit to infect vulnerable systems, making it difficult for current security solutions to detect and prevent.

New Yashma Ransomware Variant Targets Multiple English-Speaking Countries

08 August 2023
An unknown threat actor is using a variant of the Yashma ransomware to target various entities in English-speaking countries, Bulgaria, China, and Vietnam at least since June 4, 2023. Cisco Talos, in a new write-up, attributed the operation with moderate confidence to an adversary of likely Vietnamese origin. "The threat actor uses an uncommon technique to deliver the ransom note," security

Nigerian Man Admits to $1.3M Business Email Compromise Scam

08 August 2023
A Nigerian national pleaded guilty to participating in a BEC scheme to steal $1.25m from a Boston investment firm. The scam involved using malware and a spoofed domain name to trick the firm into transferring money to attacker-controlled accounts.

Teach a Man to Phish and He’s Set for Life – Krebs on Security

08 August 2023
A recent phishing scam has been using an old trick to fool Microsoft Windows users. The scam involves sending an email with an attachment that appears to be a PDF file, but is actually an .eml file disguised as a .pdf.

Cyberinsurance Firm Resilience Raises $100 Million to Expand Its Cyber Risk Platform

08 August 2023
The Series D round was led by Intact Ventures, an affiliate of Resilience’s primary capacity provider, Intact Insurance’s underwriting companies, with participation by Lightspeed Venture Partners, as well as General Catalyst and Founders Fund.

Latest Batloader Campaigns Use Pyarmor Pro for Evasion

08 August 2023
The Batloader initial access malware, used by the group Water Minyades, has upgraded its evasion techniques by utilizing Pyarmor Pro to obfuscate its malicious Python scripts.

LOLBAS in the Wild: 11 Living-Off-The-Land Binaries Used for Malicious Purposes

08 August 2023
Cybersecurity researchers have discovered a set of 11 living-off-the-land binaries-and-scripts (LOLBAS) that could be maliciously abused by threat actors to conduct post-exploitation activities.  "LOLBAS is an attack method that uses binaries and scripts that are already part of the system for malicious purposes," Pentera security researcher Nir Chako said. "This makes it hard for security teams

Extended warranty robocallers fined $300 million after 5 billion scam calls

08 August 2023
The Federal Communications Commission (FCC) has announced a record-breaking $299,997,000 fine imposed on an international network of companies for placing five billion robocalls to more than 500 million phone numbers over three months in 2021.

New Microsoft Azure AD CTS Feature can be Abused for Lateral Movement

08 August 2023
Microsoft's new Azure Active Directory Cross-Tenant Synchronization (CTS) feature, introduced in June 2023, has created a new potential attack surface that might allow threat actors to more easily spread laterally to other Azure tenants.

Rise of AI leads to free training sources

07 August 2023
The rise of technology such as artificial intelligence (AI) has led to security leaders looking for ways to educate themselves on its uses and risks. 

Cl0p Ransomware Gang Revises its Extortion Strategy

07 August 2023
MOVEit-hijacker Cl0p ransomware gang has changed its extortion tactics and is now using torrents to distribute data stolen in the MOVEit Transfer breaches. Previously, the group utilized Tor data leak sites, but this method was slow and easier to shut down. Through torrents, criminals are expecting faster transfer speeds making the leak more impactful. As torrents are decentralized, it becomes challenging for law enforcement to shut them down.

New Malware Campaign Targets Inexperienced Cyber Criminals with OpenBullet Configs

07 August 2023
A new malware campaign has been observed making use of malicious OpenBullet configuration files to target inexperienced cyber criminals with the goal of delivering a remote access trojan (RAT) capable of stealing sensitive information. Bot mitigation company Kasada said the activity is designed to "exploit trusted criminal networks," describing it as an instance of advanced threat actors "

White House announces K-12 cybersecurity plans

07 August 2023
 The White House has announced steps for providing various resources for K-12 schools to update their cybersecurity practices and report incidents.

Spyware Maker Letmespy Shuts Down After Hacker Deletes Server Data

07 August 2023
In a notice on its website in both English and Polish, LetMeSpy confirmed the “permanent shutdown” of the spyware service and that it would cease operations by the end of August.

C-Suite, Rank-And-File at Odds Over Security’s Role

07 August 2023
A disconnect is brewing between how C-suite executives and cybersecurity workers perceive security’s role, according to a Cloud Security Alliance report released last week. The study by Expel surveyed 1,000 IT and security professionals in May.

North Korean Hackers Targets Russian Missile Engineering Firm

07 August 2023
Two different North Korean nation-state actors have been linked to a cyber intrusion against the major Russian missile engineering company NPO Mashinostroyeniya. Cybersecurity firm SentinelOne said it identified "two instances of North Korea related compromise of sensitive internal IT infrastructure," including a case of an email server compromise and the deployment of a Windows backdoor dubbed

Clop Ransomware Now Uses Torrents to Leak Data and Evade Takedowns

07 August 2023
According to security researcher Dominic Alvieri, who first spotted this new tactic, torrents have been created for twenty victims, including Aon, K & L Gates, Putnam, Delaware Life, Zurich Brazil, and Heidelberg.

US ‘Lagging Behind’ on Border Gateway Protocol Security Practices, CISA and FCC Chiefs Say

07 August 2023
The U.S. government is lagging behind other countries in instituting more stringent cybersecurity measures governing the Border Gateway Protocol (BGP) – a set of technical rules responsible for routing data efficiently.