Latest Cybersecurity News and Articles


Be Aware of Exposure of Sensitive Data on Wi-Fi Settings for Canon Inkjet Printers

01 August 2023
Canon warns that sensitive information on the Wi-Fi connection settings stored in the memories of home and office/large format inkjet printers may not be deleted by the usual initialization process.

Enterprises Should Layer-up Security to Avoid Legal Repercussions

01 August 2023
Implementing a nimble incident response process and establishing repeatable procedures for investigations are crucial for reducing the impact of data breaches and minimizing legal repercussions.

White House Unveils ‘Whole of Society’ Push To Expand Cybersecurity Workforce

01 August 2023
A sweeping partnership comprising nine government agencies and over 200 nonprofits, corporations, colleges, and universities will together build an organized “whole of society” approach to expanding the cybersecurity workforce, the ONCD announced.

New WikiLoader Malware Employs Sophisticated Evasion

01 August 2023
WikiLoader is a sophisticated downloader malware that evades detection and is likely available for sale to multiple cybercriminal groups. It has been observed in multiple campaigns targeting Italian organizations.

Cybercriminals Renting WikiLoader to Target Italian Organizations with Banking Trojan

01 August 2023
Organizations in Italy are the target of a new phishing campaign that leverages a new strain of malware called WikiLoader with an ultimate aim to install a banking trojan, stealer, and spyware called Ursnif (aka Gozi). "It is a sophisticated downloader with the objective of installing a second malware payload," Proofpoint said in a technical report. "The malware uses multiple mechanisms to evade

Hackers Exploit Bleedingpipe RCE Flaw to Target Minecraft Servers, Players

31 July 2023
BleedingPipe is a vulnerability found in many Minecraft mods caused by the incorrect use of deserialization in the 'ObjectInputStream' class in Java to exchange network packets between servers and clients.

White House Unveils National Cyber Workforce Strategy

31 July 2023
"Cyber education and workforce development have not kept pace with demand and the rapid pace of technological change," says the strategy document. "Moreover, skills in demand in the cyber workforce are evolving."

Fredrick Lee named Reddit’s Chief Information Security Officer

31 July 2023
Fredrick “Flee” Lee has been named Reddit’s new Chief Information Security Officer (CISO).

Between 80- and 95% of cyberattacks begin with phishing

31 July 2023
A recent Comcast Business report pulls data from 23.5 billion cybersecurity attacks and found that attacks come from internal and external sources.

Blocking Access to ChatGPT is a Short Term Solution to Mitigate Risk

31 July 2023
For every 10,000 enterprise users, an enterprise organization is experiencing approximately 183 incidents of sensitive data being posted to ChatGPT per month, according to Netskope.

Ztna can be More Than a VPN Replacement for Application Access

31 July 2023
Zero Trust Network Access (ZTNA) should leverage contextual information, implement continuous authentication mechanisms, and be application-aware to make access decisions and reduce the risk of unauthorized access.

School Accreditation Organization Exposed Sensitive Information on Students, Parents, and Teachers Online

31 July 2023
An unprotected database belonging to the Southern Association of Independent Schools (SAIS) was found exposing sensitive data on students, parents, and teachers, including health records, social security numbers, and confidential security reports.

FTC seeks comment over parental consent guidelines for COPPA

31 July 2023
The Federal Trade Commission (FTC) has requested commentary following an application for new methods of obtaining parental consent using biometrics.

New Jersey Supreme Court to Hear Merck Insurance Dispute Over NotPetya Attack

31 July 2023
The New Jersey Supreme Court agreed to review the legal fight between Merck and several of the world’s top insurance providers involving $1.4 billion in claims stemming from the 2017 NotPetya cyberattack.

Patchwork Hackers Target Chinese Research Organizations Using EyeShell Backdoor

31 July 2023
EyeShell is a .NET-based modular backdoor that can contact a remote C2 server and execute commands to enumerate files and directories, download and upload files to and from the host, execute a specified file, delete files, and capture screenshots.

New P2PInfect Worm Targets Redis Servers with Undocumented Breach Methods

31 July 2023
The P2PInfect peer-to-peer (P2) worm has been observed employing previously undocumented initial access methods to breach susceptible Redis servers and rope them into a botnet. "The malware compromises exposed instances of the Redis data store by exploiting the replication feature," Cado Security researchers Nate Bill and Matt Muir said in a report shared with The Hacker News. "A common attack

Marshall Erwin hired as Chief Information Security Officer at Fastly

31 July 2023
Marshall Erwin has been hired as Chief Information Security Officer at Fastly. Erwin was previously Chief Security Officer at Mozilla. 

Apple Sets New Rules for Developers to Prevent Fingerprinting and Data Misuse

31 July 2023
Apple has announced plans to require developers to submit reasons to use certain APIs in their apps starting later this year with the release of iOS 17, iPadOS 17, macOS Sonoma, tvOS 17, and watchOS 10 to prevent their abuse for data collection.

Fruity Trojan Relies on Deceptive Software Installers to Spread Remcos RAT

31 July 2023
Threat actors are creating fake websites hosting trojanized software installers to trick unsuspecting users into downloading a downloader malware called Fruity with the goal of installing remote trojans tools like Remcos RAT.

VMware ESXi Servers Face New Threat from Abyss Locker

31 July 2023
MalwareHunterTeam reported a new variant of the Abyss Locker ransomware designed to target Linux-based VMware ESXi servers. It employs SSH brute force attacks to gain unauthorized access to servers. The ransomware has claimed data theft ranging from 35GB to 700GB. Researchers also suspect a connection with HelloKitty ransomware due to similar code elements.