Latest Cybersecurity News and Articles


Researchers Uncover New High-Severity Vulnerability in PaperCut Software

05 August 2023
Cybersecurity researchers have discovered a new high-severity security flaw in PaperCut print management software for Windows that could result in remote code execution under specific circumstances. Tracked as CVE-2023-39143 (CVSS score: 8.4), the flaw impacts PaperCut NG/MF prior to version 22.1.3. It has been described as a combination of a path traversal and file upload vulnerability. "

On average shareholder value drops 9% year after major cyber incident

04 August 2023
A recent report reveals on average, a major cyber incident resulted in a 9 percent decrease in shareholder value in the year following the event. 

Malicious Apps Use Sneaky Versioning Technique to Bypass Google Play Store Scanners

04 August 2023
"Campaigns using versioning commonly target users' credentials, data, and finances," Google Cybersecurity Action Team (GCAT) said in its August 2023 Threat Horizons Report shared with The Hacker News.

Report: 97% of executives access work accounts on personal devices

04 August 2023
The majority of executives are using their personal devices for work, creating a “backdoor” for cyber criminals to access large enterprise organizations.

Mondee Security Lapse Exposed Flight Itineraries and Unencrypted Credit Card Numbers

04 August 2023
The database, hosted on Oracle’s cloud and more than 1.7 terabytes in size at the time it was exposed, contained customer’s personal information, including names, gender, dates of birth, home addresses, flight information and passport numbers.

US Government Contractor Serco Discloses Data Breach After MOVEit Transfer Attacks

04 August 2023
The personal information compromised in the attack includes any combination of the following: name, U.S. Social Security Number, date of birth, home mailing address, Serco and/or personal e-mail address, and selected health benefits for the year.

Teach a Man to Phish and He’s Set for Life

04 August 2023
One frustrating aspect of email phishing is the frequency with which scammers fall back on tried-and-true methods that really have no business working these days. Like attaching a phishing email to a traditional, clean email message, or leveraging link redirects on LinkedIn, or abusing an encoding method that makes it easy to disguise booby-trapped Microsoft Windows files as relatively harmless documents.

Hawai’I’s Gemini North Observatory Suspends Operations Following Cyberattack

04 August 2023
The National Science Foundation’s NOIRLab did not respond to requests for comment but published a notice on Tuesday night explaining that the lab had discovered an attempted cyberattack on its systems that morning.

Rilide Stealer Evolves to Target Chrome Extension Manifest V3

04 August 2023
A rather sophisticated version of the Rilide malware was identified targeting Chromium-based web browsers to steal sensitive data and cryptocurrency.  Experts identified over 1,300 phishing websites distributing the new version of Rilide Stealer along with other harmful malware such as Bumblebee, IcedID, and Phorpiex. Organizations need to leverage the IOCs to understand the nature and attack scope of the latest version

Burger King Forgets to put a Password on Their Systems, Again

04 August 2023
On June 1st, 2023, the Cybernews research team discovered a publicly accessible environment file (.env) belonging to Burger King’s French website, containing various credentials. The file was hosted on the subdomain used for posting job offers.

NYC Couple Pleads Guilty to Money Laundering in $3.6 Billion Bitfinex Hack

04 August 2023
A married couple from New York City has pleaded guilty to money laundering charges in connection with the 2016 hack of cryptocurrency stock exchange Bitfinex, resulting in the theft of about 120,000 bitcoin. The development comes more than a year after Ilya Lichtenstein, 35, and his wife, Heather Morgan, 33, were arrested in February 2022, following the seizure of roughly 95,000 of the stolen

Hackers can Abuse Microsoft Office Executables to Download Malware

04 August 2023
The list of LOLBAS files - legitimate binaries and scripts present in Windows that can be abused for malicious purposes, will soon include the main executables for Microsoft’s Outlook email client and Access database management system.

SCARF Cipher Sets New Standards in Protecting Sensitive Data

04 August 2023
The cipher, designed by Assistant Professor Rei Ueno from the Research Institute of Electrical Communication at Tohoku University, addresses the threat of cache side-channel attacks, offering enhanced security and exceptional performance.

Webinar - Making PAM Great Again: Solving the Top 5 Identity Team PAM Challenges

04 August 2023
Privileged Access Management (PAM) solutions are widely acknowledged as the gold standard for securing critical privileged accounts. However, many security and identity teams face inherent obstacles during the PAM journey, hindering these solutions from reaching their full potential. These challenges deprive organizations of the resilience they seek, making it essential to address them

New Version of Rilide Data Theft Malware Adapts to Chrome Extension Manifest V3

04 August 2023
Rilide was first documented by the cybersecurity company in April 2023, uncovering two different attack chains that made use of Ekipa RAT and Aurora Stealer to deploy rogue browser extensions capable of data and crypto theft.

Malicious npm Packages Found Exfiltrating Sensitive Data from Developers

04 August 2023
Cybersecurity researchers have discovered a new bunch of malicious packages on the npm package registry that are designed to exfiltrate sensitive developer information. Software supply chain firm Phylum, which first identified the "test" packages on July 31, 2023, said they "demonstrated increasing functionality and refinement," hours after which they were removed and re-uploaded under different

These Are the Top Five Cloud Security Risks, Qualys Says

04 August 2023
The five key risk areas are misconfigurations, external-facing vulnerabilities, weaponized vulnerabilities, malware inside a cloud environment, and remediation lag (that is, delays in patching).

FBI, CISA, and NSA Reveal Top Exploited Vulnerabilities of 2022

04 August 2023
While the Common Vulnerabilities and Exposures (CVE) Program published over 25,000 new security vulnerabilities until the end of 2022, only five vulnerabilities made it to the list of the top 12 flaws exploited in attacks the same year.

Fake FlipperZero Site Used to Phish Users

04 August 2023
Scammers were found impersonating Flipper Devices and offering free FlipperZero gadgets in exchange for completing an offer. However, the website directs users to insecure browser extensions and fraudulent sites. The real Flipper Devices warns users to be cautious, as they have no affiliation with the fake site. The scam website is still active, so users have been advised to shop via a legitimate store and avoid falling victim to such campaigns.

Poor access management besets most cloud compromises, Google says

04 August 2023
About 55% of all cloud compromises analyzed by Google Cloud’s incident response teams during the quarter were the result of weak or nonexistent passwords, the company said in its Threat Horizons Report.