Latest Cybersecurity News and Articles


Researchers Uncover AWS SSM Agent Misuse as a Covert Remote Access Trojan

02 August 2023
Cybersecurity researchers have discovered a new post-exploitation technique in Amazon Web Services (AWS) that allows the AWS Systems Manager Agent (SSM Agent) to be run as a remote access trojan on Windows and Linux environments.

OT/IoT Malware Surges Tenfold in First Half of the Year

02 August 2023
Malware-related cyber-threats in operational technology (OT) and Internet of Things (IoT) environments jumped tenfold year-on-year in the first six months of 2023, according to Nozomi Networks.

Millions Stolen From Crypto Platforms Through Exploited ‘Vyper’ Vulnerability

02 August 2023
Millions of dollars worth of cryptocurrency were stolen from several platforms over the weekend after hackers exploited a vulnerability in a programming language used widely in the cryptocurrency world.

The Gap in Users’ Identity Security Knowledge Gives Cybercriminals an Opening

02 August 2023
With exponential growth in the number of human and machine actors on the network and more sophisticated technology in more places, identity in this new era is rapidly becoming a super-human problem, according to RSA.

Nile, Which Offers Enterprise Networks as a Service, Raises $175M

02 August 2023
Nile, a networking-as-a-service (NaaS) provider founded by former Cisco executive Pankaj Patel, has raised $175 million in a Series C funding round. The funding will be used for go-to-market growth and expanding the company's workforce.

Business email compromise attacks outpace malware

02 August 2023
A recent Abnormal report analyzed the increase in third-party application usage and increase in email attacks in the first half of 2023.

Firefox Fixes a Flurry of Flaws in the First of Two Releases This Month

02 August 2023
Mozilla has released a new version of Firefox, marking the first of two upgrades for the month. The patched flaws are tracked as CVE-2023-4045, CVE-2023-4047, CVE-2023-4048, CVE-2023-4050, CVE-2023-4051, CVE-2023-4057, and CVE-2023-4058.

Lawsuit Alleges Bytedance’s Capcut App Secretly Reaps Massive Amounts of User Data

02 August 2023
CapCut and sister company TikTok are owned by the Chinese company ByteDance Ltd., which has long been under scrutiny by American officials concerned with how it collects and leverages American users’ personal data, allegedly including biometric data.

Russian Cyber Adversary BlueCharlie Alters Infrastructure in Response to Disclosures

02 August 2023
A Russa-nexus adversary has been linked to 94 new domains, suggesting that the group is actively modifying its infrastructure in response to public disclosures about its activities. Cybersecurity firm Recorded Future linked the new infrastructure to a threat actor it tracks under the name BlueCharlie, a hacking crew that's broadly known by the names Blue Callisto, Callisto (or Calisto),

Report finds governments, public services facing 40% more cyberattacks

02 August 2023
A new report highlights a 40% increase in cyberattacks targeting government agencies and the public services sector.

Cyberattack on Montclair Township Led to $450K Settlement

02 August 2023
The Garden State Joint Insurance Fund made the deal as law enforcement began investigations into possible criminal charges, Joseph Hartnett, interim township manager, said Thursday.

Possible Chinese Malware in US Systems a ‘Ticking Time Bomb’: Report

02 August 2023
The Biden administration believes China has implanted malware in key US power and communications networks in a “ticking time bomb” that could disrupt the military in event of a conflict, The New York Times reported Saturday.

Cloudzy With a Chance of Global Cybercrime

02 August 2023
Halcyon Research uncovers C2P entities enabling ransomware attacks, identifies new affiliates, and links them to the ISP Cloudzy, facilitating anonymous RDP VPS services with cryptocurrencies. Experts confidently concluded that Cloudzy is highly likely to be a front for abrNOC, the actual hosting company operating from Iran.

Retail Chain Hot Topic Discloses Wave of Credential-Stuffing Attacks

02 August 2023
In a data breach notification today, the company explained that hackers used stolen account credentials and accessed the Rewards platform multiple times, potentially stealing customer data, too.

Phishers Exploit Salesforce's Email Services Zero-Day in Targeted Facebook Campaign

02 August 2023
A sophisticated Facebook phishing campaign has been observed exploiting a zero-day flaw in Salesforce's email services, allowing threat actors to craft targeted phishing messages using the company's domain and infrastructure. "Those phishing campaigns cleverly evade conventional detection methods by chaining the Salesforce vulnerability and legacy quirks in Facebook's Web Games platform,"

Industrial Control Systems Vulnerabilities Soar: Over One-Third Unpatched in 2023

02 August 2023
About 34% of security vulnerabilities impacting industrial control systems (ICSs) that were reported in the first half of 2023 have no patch or remediation, registering a significant increase from 13% the previous year. According to data compiled by SynSaber, a total of 670 ICS product flaws were reported via the U.S. Cybersecurity and Infrastructure Security Agency (CISA) in the first half of

Kazakhstan Refuses to Extradite Detained Russian Cyber Expert to Us

02 August 2023
At the same time, a Moscow court also issued an arrest warrant for Kislitsin, charging him with unauthorized access to protected computer information. Russia said it will also seek his extradition from Kazakhstan.

Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack

02 August 2023
The research was conducted by a group of eight researchers representing the Graz University of Technology in Austria and the CISPA Helmholtz Center for Information Security in Germany.

Study Downplays Cyber Insurance as Incentive to Pay Ransom

02 August 2023
Fears that cyber insurance coverage drives companies into paying ransomware demands more easily than otherwise appear unfounded, concludes a British think tank study that suggests insurers should do more to enact corporate discipline.

Top Industries Significantly Impacted by Illicit Telegram Networks

02 August 2023
In recent years the rise of illicit activities conducted within online messaging platforms has become a growing concern for countless industries. One of the most notable platforms that has been host to many malicious actors and nefarious activities has been Telegram. Thanks to its accessibility, popularity, and user anonymity, Telegram has attracted a large number of threat actors driven by