Latest Cybersecurity News and Articles


Open-Source Penetration Testing Tool BloodHound CE Released

03 August 2023
SpecterOps released BloodHound Community Edition (CE) v5.0, a free and open-source penetration testing solution that maps attack paths in Active Directory (AD) and Azure (including Azure AD/Entra ID) environments. It is available for free on GitHub.

91% IT leaders are better protected with PAM, seek affordable solutions

03 August 2023
A new report reveals 56% of IT leaders tried to deploy a PAM solution but did not fully implement it, and 92% cited overly-complex solutions as the main reason.

Hackers Exploited Salesforce Zero-Day in Facebook Phishing Attack

03 August 2023
The attackers chained a flaw dubbed "PhishForce," to bypass Salesforce's sender verification safeguards and quirks in Facebook's web games platform to mass-send phishing emails.

How Malicious Android Apps Slip Into Disguise

03 August 2023
Researchers say mobile malware purveyors have been abusing a bug in the Google Android platform that lets them sneak malicious code into benign mobile apps and evade security scanning tools. Google says it has updated its app malware detection mechanisms in response to the new research.

SpyNote Spyware Now Targets Financial Institutions

03 August 2023
Security experts have witnessed an increase in spyNote malware infections known for espionage campaigns and now, for bank fraud. The attack chain often starts with a fake SMS message, redirecting users to download a "certified banking app" that is actually SpyNote. Notably, TeamViewer has been exploited by threat actors in these fraud operations through social engineering attacks, where attackers impersonate bank operators to execute fraudulent transactions on victims' devices.

New hVNC macOS Malware Advertised on Cybercrime Forum

03 August 2023
Commonly used for technical support, Virtual Network Computing (VNC) supports the remote control of computers over the network, with the knowledge of the device’s user, who can watch on the screen the performed actions.

Marine Industry Giant Brunswick Corporation Lost $85 Million in Cyberattack, CEO Confirms

03 August 2023
A cybersecurity incident will cost the Brunswick Corporation as much as $85 million, the company’s CEO told investors last week. The boating manufacturing firm disclosed a cyberattack on June 13 that impacted their systems and some facilities.

Over 640 Citrix Servers Backdoored With Web Shells in Ongoing Attacks

03 August 2023
Hundreds of Citrix Netscaler ADC and Gateway servers have already been breached and backdoored in a series of attacks targeting a critical remote code execution (RCE) vulnerability tracked as CVE-2023-3519.

Software Supply Chain Startup Endor Labs Scores Massive $70M Series A Round

03 August 2023
Just ten months after securing an abnormally large seed-stage funding round, software supply chain startup Endor Labs has attracted renewed interest from venture capital investors.

Microsoft Flags Growing Cybersecurity Concerns for Major Sporting Events

03 August 2023
Microsoft is warning of the threat malicious cyber actors pose to stadium operations, warning that the cyber risk surface of live sporting events is "rapidly expanding." "Information on athletic performance, competitive advantage, and personal information is a lucrative target," the company said in a Cyber Signals report shared with The Hacker News. "Sports teams, major league and global

Researchers Discover Bypass for Recently Patched Critical Ivanti EPMM Vulnerability

03 August 2023
Tracked as CVE-2023-35082 (CVSS score: 10.0) and discovered by Rapid7, the issue "allows unauthenticated attackers to access the API in older unsupported versions of MobileIron Core (11.2 and below)."

"Mysterious Team Bangladesh" Targeting India with DDoS Attacks and Data Breaches

03 August 2023
A hacktivist group known as Mysterious Team Bangladesh has been linked to over 750 distributed denial-of-service (DDoS) attacks and 78 website defacements since June 2022. "The group most frequently attacks logistics, government, and financial sector organizations in India and Israel," Singapore-headquartered cybersecurity firm Group-IB said in a report shared with The Hacker News. "The group is

AI-Powered CryptoRom Scam Targets Mobile Users

03 August 2023
CryptoRom, a notorious scam that combines fake cryptocurrency trading and romance scams, has taken a new twist by utilizing generative artificial intelligence (AI) chat tools to lure and interact with victims.

Russia-Linked Cybercriminals Target UK School for Children With Learning Difficulties

03 August 2023
The LockBit ransomware group, potentially the world’s most prolific cybercrime organization, is attempting to extort a school for children with special educational needs.

New Variants of NodeStealer Found Infecting Facebook Business Accounts

03 August 2023
Unit 42 researchers discovered a previously unreported phishing campaign targeting Facebook business accounts. The campaign distributed new variants of NodeStealer malware that could fully take over these accounts, steal cryptocurrency, and download further payloads. This type of attack can cause both financial and reputational damage to individuals and organizations.

Microsoft Exposes Russian Hackers' Sneaky Phishing Tactics via Microsoft Teams Chats

03 August 2023
Microsoft on Wednesday disclosed that it identified a set of highly targeted social engineering attacks mounted by a Russian nation-state threat actor using credential theft phishing lures sent as Microsoft Teams chats. The tech giant attributed the attacks to a group it tracks as Midnight Blizzard (previously Nobelium). It's also called APT29, BlueBravo, Cozy Bear, Iron Hemlock, and The Dukes.

Researchers Discover Bypass for Recently Patched Critical Ivanti EPMM Vulnerability

03 August 2023
Cybersecurity researchers have discovered a bypass for a recently fixed actively exploited vulnerability in some versions of Ivanti Endpoint Manager Mobile (EPMM), prompting Ivanti to urge users to update to the latest version of the software. Tracked as CVE-2023-35082 (CVSS score: 10.0) and discovered by Rapid7, the issue "allows unauthenticated attackers to access the API in older unsupported

NCSC and allies reveal most common cyber vulnerabilities exploited in 2022

02 August 2023
New advisory highlights how threat actors exploited a larger number of older software vulnerabilities rather than more recently disclosed flaws last year.

Cyberattack response times are accelerating

02 August 2023
According to a recent Immersive Labs report, organizations saw an accelerated cyberattack response time, from 29 days to 19 days from 2021 to 2022.

Cyber attack response times are accelerating

02 August 2023
According to a recent Immersive Labs report, organizations saw an accelerated cyberattack response time, from 29 days to 19 days from 2021 to 2022.