Latest Cybersecurity News and Articles


MacOS malware discovered on Russian dark web forum

01 August 2023
Hidden virtual network computing (hVNC) malware specifically targeting macOS was identified by Guardz on the Russian dark web forum Exploit.

New NodeStealer Targeting Facebook Business Accounts and Crypto Wallets

01 August 2023
Cybersecurity researchers have unearthed a Python variant of a stealer malware NodeStealer that's equipped to fully take over Facebook business accounts as well as siphon cryptocurrency. Palo Alto Network Unit 42 said it detected the previously undocumented strain as part of a campaign that commenced in December 2022. NodeStealer was first exposed by Meta in May 2023, describing it as a stealer

Dynatrace Acquires Cloud-Native Debugging Platform Rookout

01 August 2023
Observability and security platform Dynatrace today announced that it plans to acquire Rookout, a Tel Aviv-based observability startup that focuses on helping developers troubleshoot and debug their code in production.

10% of expired certificates on the internet pose a security threat

01 August 2023
A  survey found that nearly 80% of transport layer security (TLS) certificates on the Internet are vulnerable to Man in the Middle (MiM) attacks.

Hackers Steal Signal, Whatsapp User Data With Fake Android Chat App

01 August 2023
The Android spyware is suspected to be a variant of "Coverlm," which steals data from communication apps such as Telegram, Signal, WhatsApp, Viber, and Facebook Messenger.

Iranian Hackers Posed as Israelis in Targeted LinkedIn Phishing Attack

01 August 2023
During the conversation, the malicious actors would send seemingly harmless attachments, such as invitations to conferences or files related to the targets’ professional interests, such as studies or articles.

Researchers Expose Space Pirates' Cyber Campaign Across Russia and Serbia

01 August 2023
"The cybercriminals' main goals are still espionage and theft of confidential information, but the group has expanded its interests and the geography of its attacks," Positive Technologies said in a deep dive report published last week.

Stremio Vulnerability Exposes Millions to Attack

01 August 2023
CyFox researchers have discovered a DLL planting/hijacking vulnerability in popular media center application Stremio, which could be exploited by attackers to execute code on the victim’s system, steal information, and more.

Meow Campaign Reaches Misconfigured Jupyter Notebook Instances

01 August 2023
The "Meow" campaign, targeting unsecured databases, has resurfaced, with the threat actor using misconfigured Jupyter Notebook instances to gather information and delete databases.

Report finds 164% increase in cyber threats targeting brands

01 August 2023
A new report reveals an increase in key personnel and corporate social media impersonation accounts, among other threats targeting brands.

SpyNote Android Spyware Strikes Financial Institutions Through Smishing Campaigns

01 August 2023
The infection chain typically begins with a deceptive SMS message urging users to install a “new certified banking app,” followed by a redirect to a seemingly authentic TeamViewer app, which is used for technical remote support.

Mattress Giant Tempur Sealy Hit with Cyberattack Forcing System Shutdown

01 August 2023
The company’s chief financial officer Bhaskar Rao reported to the U.S. Securities and Exchange Commission on Monday morning that Tempur Sealy’s operations had been hindered by a cyberattack that began on July 23.

Spike in Ransomware Delivery via URLs, Reports Unit 42

01 August 2023
Ransomware delivered through URLs has become the leading method for distributing ransomware, accounting for over 77% of cases in 2022 - found Unit 42. This is followed by emails at 12%. Researchers observed attackers using different URLs/hostnames to host or deliver different malware, including ransomware strains. Vigilance, user education, advanced security solutions, regular backups, and efficient incident response are crucial to mitigating this emerging threat.

European Bank Customers Targeted in SpyNote Android Trojan Campaign

01 August 2023
Various European customers of different banks are being targeted by an Android banking trojan called SpyNote as part of an aggressive campaign detected in June and July 2023. "The spyware is distributed through email phishing or smishing campaigns and the fraudulent activities are executed with a combination of remote access trojan (RAT) capabilities and vishing attack," Italian cybersecurity

What is Data Security Posture Management (DSPM)?

01 August 2023
Data Security Posture Management is an approach to securing cloud data by ensuring that sensitive data always has the correct security posture - regardless of where it's been duplicated or moved to. So, what is DSPM? Here's a quick example: Let's say you've built an excellent security posture for your cloud data. For the sake of this example, your data is in production, it's protected behind a

Meta Subsidiaries Must Pay $14M Over Misleading Data Collection Disclosure

01 August 2023
Facebook's subsidiaries, including Onavo, have been ordered to pay $14 million in an Australian court case for undisclosed data collection through a now-discontinued VPN, highlighting the company's privacy issues.

Researchers Expose Space Pirates' Cyber Campaign Across Russia and Serbia

01 August 2023
The threat actor known as Space Pirates has been linked to attacks against at least 16 organizations in Russia and Serbia over the past year by employing novel tactics and adding new cyber weapons to its arsenal. "The cybercriminals' main goals are still espionage and theft of confidential information, but the group has expanded its interests and the geography of its attacks," Positive

The Race Against Time in Ransomware Attacks

01 August 2023
Despite both the rise in threats and the high percentage of respondents whose organizations suffered recent attacks, there hasn’t been a corresponding uptick in strategic measures to shore up cyber resilience, according to BigID.

China's APT31 Suspected in Attacks on Air-Gapped Systems in Eastern Europe

01 August 2023
A nation-state actor with links to China is suspected of being behind a series of attacks against industrial organizations in Eastern Europe that took place last year to siphon data stored on air-gapped systems. Cybersecurity company Kaspersky attributed the intrusions with medium to high confidence to a hacking crew called APT31, which is also tracked under the monikers Bronze Vinewood,

Web Browsing is the Primary Entry Vector for Ransomware Infections

01 August 2023
The attackers have been spotted rotating different URLs/hostnames to host the same ransomware or using the same URL to deliver different ransomware. Some attackers do both of these things.