Latest Cybersecurity News and Articles


Teach a Man to Phish and He’s Set for Life

04 August 2023
One frustrating aspect of email phishing is the frequency with which scammers fall back on tried-and-true methods that really have no business working these days. Like attaching a phishing email to a traditional, clean email message, or leveraging link redirects on LinkedIn, or abusing an encoding method that makes it easy to disguise booby-trapped Microsoft Windows files as relatively harmless documents.

Hawai’I’s Gemini North Observatory Suspends Operations Following Cyberattack

04 August 2023
The National Science Foundation’s NOIRLab did not respond to requests for comment but published a notice on Tuesday night explaining that the lab had discovered an attempted cyberattack on its systems that morning.

Rilide Stealer Evolves to Target Chrome Extension Manifest V3

04 August 2023
A rather sophisticated version of the Rilide malware was identified targeting Chromium-based web browsers to steal sensitive data and cryptocurrency.  Experts identified over 1,300 phishing websites distributing the new version of Rilide Stealer along with other harmful malware such as Bumblebee, IcedID, and Phorpiex. Organizations need to leverage the IOCs to understand the nature and attack scope of the latest version

Burger King Forgets to put a Password on Their Systems, Again

04 August 2023
On June 1st, 2023, the Cybernews research team discovered a publicly accessible environment file (.env) belonging to Burger King’s French website, containing various credentials. The file was hosted on the subdomain used for posting job offers.

NYC Couple Pleads Guilty to Money Laundering in $3.6 Billion Bitfinex Hack

04 August 2023
A married couple from New York City has pleaded guilty to money laundering charges in connection with the 2016 hack of cryptocurrency stock exchange Bitfinex, resulting in the theft of about 120,000 bitcoin. The development comes more than a year after Ilya Lichtenstein, 35, and his wife, Heather Morgan, 33, were arrested in February 2022, following the seizure of roughly 95,000 of the stolen

Hackers can Abuse Microsoft Office Executables to Download Malware

04 August 2023
The list of LOLBAS files - legitimate binaries and scripts present in Windows that can be abused for malicious purposes, will soon include the main executables for Microsoft’s Outlook email client and Access database management system.

SCARF Cipher Sets New Standards in Protecting Sensitive Data

04 August 2023
The cipher, designed by Assistant Professor Rei Ueno from the Research Institute of Electrical Communication at Tohoku University, addresses the threat of cache side-channel attacks, offering enhanced security and exceptional performance.

Webinar - Making PAM Great Again: Solving the Top 5 Identity Team PAM Challenges

04 August 2023
Privileged Access Management (PAM) solutions are widely acknowledged as the gold standard for securing critical privileged accounts. However, many security and identity teams face inherent obstacles during the PAM journey, hindering these solutions from reaching their full potential. These challenges deprive organizations of the resilience they seek, making it essential to address them

New Version of Rilide Data Theft Malware Adapts to Chrome Extension Manifest V3

04 August 2023
Rilide was first documented by the cybersecurity company in April 2023, uncovering two different attack chains that made use of Ekipa RAT and Aurora Stealer to deploy rogue browser extensions capable of data and crypto theft.

Malicious npm Packages Found Exfiltrating Sensitive Data from Developers

04 August 2023
Cybersecurity researchers have discovered a new bunch of malicious packages on the npm package registry that are designed to exfiltrate sensitive developer information. Software supply chain firm Phylum, which first identified the "test" packages on July 31, 2023, said they "demonstrated increasing functionality and refinement," hours after which they were removed and re-uploaded under different

These Are the Top Five Cloud Security Risks, Qualys Says

04 August 2023
The five key risk areas are misconfigurations, external-facing vulnerabilities, weaponized vulnerabilities, malware inside a cloud environment, and remediation lag (that is, delays in patching).

FBI, CISA, and NSA Reveal Top Exploited Vulnerabilities of 2022

04 August 2023
While the Common Vulnerabilities and Exposures (CVE) Program published over 25,000 new security vulnerabilities until the end of 2022, only five vulnerabilities made it to the list of the top 12 flaws exploited in attacks the same year.

Fake FlipperZero Site Used to Phish Users

04 August 2023
Scammers were found impersonating Flipper Devices and offering free FlipperZero gadgets in exchange for completing an offer. However, the website directs users to insecure browser extensions and fraudulent sites. The real Flipper Devices warns users to be cautious, as they have no affiliation with the fake site. The scam website is still active, so users have been advised to shop via a legitimate store and avoid falling victim to such campaigns.

Poor access management besets most cloud compromises, Google says

04 August 2023
About 55% of all cloud compromises analyzed by Google Cloud’s incident response teams during the quarter were the result of weak or nonexistent passwords, the company said in its Threat Horizons Report.

Decommissioned Medical Infusion Pumps Expose Wi-Fi Configuration Data

04 August 2023
Most medical infusion pumps sold via secondary market sources still contain Wi-Fi configuration settings from the original organization that deployed them, cybersecurity firm Rapid7 has discovered.

670 ICS Vulnerabilities Disclosed by CISA in First Half of 2023: Analysis

04 August 2023
SynSaber’s analysis, conducted in collaboration with the ICS Advisory Project, shows that CISA published 185 ICS advisories in the first half of 2023, down from 205 in the first half of 2022.

Dozens of RCE Vulnerabilities Impact Milesight Industrial Router

04 August 2023
Dozens of vulnerabilities impacting the Milesight UR32L industrial router could be exploited to execute arbitrary code or commands, Cisco’s Talos security researchers warn.

New hVNC Malware Targets macOS Devices

04 August 2023
Researchers warned of a new hVNC malware targeting macOS devices. The malware, advertised on a Russian hacker forum, has been available since April 2023. It provides threat actors with stealthy remote control over infected machines with reverse shell, file management, and browser detection capabilities. to protect your systems, updating to the versions above 13.2 is suggested.

Major Cybersecurity Agencies Collaborate to Unveil 2022's Most Exploited Vulnerabilities

04 August 2023
A four-year-old critical security flaw impacting Fortinet FortiOS SSL has emerged as one of the most routinely and frequently exploited vulnerabilities in 2022. "In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems," cybersecurity and intelligence agencies from the Five

97% of execs expect firms will be highly impacted by AI in a year

03 August 2023
A new report shows that three in four business leaders find generative AI will be a top three emerging technology over the next 12-18 months.