Latest Cybersecurity News and Articles


Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack

02 August 2023
The research was conducted by a group of eight researchers representing the Graz University of Technology in Austria and the CISPA Helmholtz Center for Information Security in Germany.

Study Downplays Cyber Insurance as Incentive to Pay Ransom

02 August 2023
Fears that cyber insurance coverage drives companies into paying ransomware demands more easily than otherwise appear unfounded, concludes a British think tank study that suggests insurers should do more to enact corporate discipline.

Top Industries Significantly Impacted by Illicit Telegram Networks

02 August 2023
In recent years the rise of illicit activities conducted within online messaging platforms has become a growing concern for countless industries. One of the most notable platforms that has been host to many malicious actors and nefarious activities has been Telegram. Thanks to its accessibility, popularity, and user anonymity, Telegram has attracted a large number of threat actors driven by

Researchers Uncover AWS SSM Agent Misuse as a Covert Remote Access Trojan

02 August 2023
Cybersecurity researchers have discovered a new post-exploitation technique in Amazon Web Services (AWS) that allows the AWS Systems Manager Agent (SSM Agent) to be run as a remote access trojan on Windows and Linux environments "The SSM agent, a legitimate tool used by admins to manage their instances, can be re-purposed by an attacker who has achieved high privilege access on an endpoint with

Chattanooga Heart Institute Notifies 170,000 of Hacking, Data Breach

02 August 2023
In a report filed to Maine's attorney general on Friday, The Chattanooga Heart Institute said that on April 17 it saw indications of a cyberattack on its IT network. The incident affected 170,450 individuals in total, including five Maine residents.

Cloud Tech Debt Puts Millions of Apps at Risk, Says New Report

02 August 2023
According to new data by Qualys, over 60 million applications reached the end of support and end of life during the research period. Critical categories, such as databases, web servers, and security software, now lack security updates.

UK Military Embraces Security by Design

02 August 2023
The UK’s Ministry of Defence (MoD) has launched its Secure by Design initiative, which is to transform how cybersecurity is built into its systems and capabilities both internally and across its supply chain.

Silk Security Emerges from Stealth With $12.5 Million Seed Funding

02 August 2023
The seed funding round for the New York-based company was led by Insight Partners and Hetz Ventures, with the CrowdStrike Falcon Fund and angel investors including Shlomo Kramer, Mickey Boodaei, and Rakesh Loonkar also participating.

Data Breach Reported in Arizona’s School Voucher Program

02 August 2023
Arizona's Empowerment Scholarship Account program experienced a data breach where personal information of students, including names and disability categories, was viewable on the program's financial vendor's website.

Newly Discovered WikiLoader Malware Used to Install Ursnif Trojan

02 August 2023
Proofpoint discovered a new malware WikiLoader, a sophisticated malware downloader that targets Italian organizations to drop Ursnif trojan. It uses multiple evasion techniques to make detection and analysis difficult. Organizations and network defenders must leverage IOCs related to the malware to understand the current attack patterns and enhance the defense approaches to stay safe.

US Internet Hosting Company Appears to Facilitate Global Cybercrime, Researchers Say

02 August 2023
A little-known American internet hosting company appears to be partially enabling a “wide range” of cybercrime, nation-state hackers and a sanctioned spyware vendor, researchers alleged Tuesday.

Threat Actors Abuse Google AMP for Evasive Phishing Attacks

02 August 2023
The idea behind using Google AMP URLs embedded in phishing emails is to make sure that email protection technology does not flag messages as malicious or suspicious due to Google’s good reputation.

Socket Lands $20M Investment to Help Companies Secure Open Source Software

02 August 2023
The round was led by Andreessen Horowitz (a16z), along with participation from Abstract Ventures, Wndrco, Unusual Ventures, and a high-profile list of angel investors, including the co-founders of Box, Figma, Okta, Vercel, and Eventbrite.

New Infostealer Uncovered in Phishing Scam Targeting Facebook Business Accounts

02 August 2023
This novel campaign, believed to be perpetrated by a threat actor of Vietnamese origin, is part of a growing trend of attackers targeting Facebook business accounts for advertising fraud and other purposes in the past year.

Forgepoint Capital Places $15M Series A Bet on Converge Insurance

02 August 2023
“This funding will enable us to expand our outreach and grow our bench of in-house experts while accelerating the availability of the Converge platform worldwide,” the newly appointed CEO, Tom Kang, said.

Meow Attack Campaign Evolves to Target Jupyter Notebooks

02 August 2023
Aquasec researchers have discovered cybercriminals targeting unsecured Jupyter notebooks in the new Meow attack campaign, which is currently affecting hundreds of publicly accessible databases online. These criminals have wiped out data from over 4,000 databases, including Cassandra, CouchDB, Redis, Hadoop, Jenkins, and Apache ZooKeeper. Databases at organizations must be scrutinized to identify any security gaps.

Iranian Company Cloudzy Accused of Aiding Cybercriminals and Nation-State Hackers

02 August 2023
Services offered by an obscure Iranian company known as Cloudzy are being leveraged by multiple threat actors, including cybercrime groups and nation-state crews. "Although Cloudzy is incorporated in the United States, it almost certainly operates out of Tehran, Iran – in possible violation of U.S. sanctions – under the direction of someone  going by the name Hassan Nozari," Halcyon said in a

CISA and NCSC-NO Release Joint Cybersecurity Advisory on Threat Actors Exploiting Ivanti EPMM Vulnerabilities

02 August 2023
CISA and NCSC-NO recommend administrators use the CISA developed nuclei templates to determine if their system has these vulnerabilities and use the NCSC-NO developed checklist to identify signs of compromise.

UK: NHS Staff Reprimanded for WhatsApp Data Sharing

02 August 2023
Some 26 staff at NHS Lanarkshire accessed the WhatsApp group between April 2020 and April 2022, entering sensitive patient data including names, phone numbers, addresses, images, videos, screenshots, and clinical information, according to the UK ICO.

Norwegian Entities Targeted in Ongoing Attacks Exploiting Ivanti EPMM Vulnerability

01 August 2023
Advanced persistent threat (APT) actors exploited a recently disclosed critical flaw impacting Ivanti Endpoint Manager Mobile (EPMM) as a zero-day since at least April 2023 in attacks directed against Norwegian entities, including a government network. The disclosure comes as part of a new joint advisory released by the Cybersecurity and Infrastructure Security Agency (CISA) and the Norwegian