Latest Cybersecurity News and Articles


Security leaders discuss CISA advisory of IDOR web app vulnerabilities

31 July 2023
Security leaders talk about a new advisory released by CISA which warns of web applications about insecure direct object reference (IDOR) vulnerabilities.

Senate opens path for a cyber-focused military branch

31 July 2023
The possibility of a U.S. Cyber Force moved one step closer to reality on Thursday after the Senate approved its version of a massive defense policy bill. The $886 billion National Defense Authorization Act passed in an 86-11 vote.

Patchwork Hackers Target Chinese Research Organizations Using EyeShell Backdoor

31 July 2023
Threat actors associated with the hacking crew known as Patchwork have been spotted targeting universities and research organizations in China as part of a recently observed campaign. The activity, according to KnownSec 404 Team, entailed the use of a backdoor codenamed EyeShell. Patchwork, also known by the names Operation Hangover and Zinc Emerson, is suspected to be a threat group that

A Year in Review of Zero-Days Exploited In-the-Wild in 2022

31 July 2023
The shift towards zero-click exploits and new browser mitigations has led to a decrease in browser zero-days, but attackers are still finding ways to exploit vulnerabilities in other components.

Danny Rittman named CISO at Avant Technologies, Inc.

31 July 2023
Avant Technologies, Inc. announced the appointment of Dr. Danny Rittman as Chief Information Security Officer (CISO).

Webinar: Riding the vCISO Wave: How to Provide vCISO Services

31 July 2023
Demand for Virtual CISO services is soaring. According to Gartner, the use of vCISO services among small and mid-size businesses and non-regulated enterprises was expected to grow by a whopping 1900% in just one year, from only 1% in 2021 to 20% in 2022! Offering vCISO services can be especially attractive for MSPs and MSSPs. By addressing their customers’ needs for proactive cyber resilience,

New Study Reveals Forged Certificate Attack Risks

31 July 2023
New research has highlighted the severe risks posed by forged certificate attacks, which can lead to unauthorized access to important company resources. These attacks are driven by the Shadow Credentials technique.

Israel’s Largest Oil Refinery Website Offline After DDoS Attack

31 July 2023
The Iranian hacktivist group, Cyber Avengers, has taken responsibility for breaching BAZAN's network and leaked screenshots of the company's SCADA systems on its Telegram channel.

Study Reveals Silent Python Package Security Fixes

31 July 2023
Python security fixes often happen through "silent" code commits, without an associated Common Vulnerabilities and Exposures (CVE) identifier, according to a group of computer security researchers.

Linux Version of Abyss Locker Ransomware Targets VMware ESXi Servers

31 July 2023
Abyss Locker is a relatively new ransomware operation that is believed to have launched in March 2023. Like other ransomware operations, the threat actors breach corporate networks, steal data for double-extortion, and encrypt devices on the network.

'Call of Duty: Modern Warfare 2' Game Servers Taken Offline Due to Malware Concerns

31 July 2023
The Call of Duty: Modern Warfare 2 servers were taken offline due to the presence of a self-spreading worm virus targeting PC gamers. Hackers used hacked lobbies to spread the malware, infecting multiple players' devices with the virus.

AVRecon Botnet Leveraging Compromised Routers to Fuel Illegal Proxy Service

31 July 2023
More details have emerged about a botnet called AVRecon, which has been observed making use of compromised small office/home office (SOHO) routers as part of a multi-year campaign active since at least May 2021. AVRecon was first disclosed by Lumen Black Lotus Labs earlier this month as malware capable of executing additional commands and stealing victim's bandwidth for what appears to be an

Canada: University of Guelph Students Notified of Benefits Data Breach Four Months Later

31 July 2023
The provider of health, dental, and wellness benefits at the University of Guelph (U of G) has begun notifying students of a data breach which included access to personal information.

Fruity Trojan Uses Deceptive Software Installers to Spread Remcos RAT

31 July 2023
Threat actors are creating fake websites hosting trojanized software installers to trick unsuspecting users into downloading a downloader malware called Fruity with the goal of installing remote trojans tools like Remcos RAT. "Among the software in question are various instruments for fine-tuning CPUs, graphic cards, and BIOS; PC hardware-monitoring tools; and some other apps," cybersecurity

Hackers Deploy "SUBMARINE" Backdoor in Barracuda Email Security Gateway Attacks

31 July 2023
"SUBMARINE comprises multiple artifacts — including a SQL trigger, shell scripts, and a loaded library for a Linux daemon — that together enable execution with root privileges, persistence, command and control, and cleanup," the agency said.

Dark Power Ransomware Abusing Vulnerable Dynamic-Link Libraries in Resolved API Flow

31 July 2023
The Dark Power ransomware exploits vulnerabilities in kernel-related APIs to quickly propagate through the cyber-kill chain. It also leverages DLLs such as kernel32.dll, bcrypt.dll, and ole32.dll to carry out its malicious activities.

Multiple Flaws Found in Ninja Forms Plugin Leave 800,000 Sites Vulnerable

31 July 2023
Multiple security vulnerabilities have been disclosed in the Ninja Forms plugin for WordPress that could be exploited by threat actors to escalate privileges and steal sensitive data. The flaws, tracked as CVE-2023-37979, CVE-2023-38386, and CVE-2023-38393, impact versions 3.6.25 and below, Patchstack said in a report last week. Ninja Forms is installed on over 800,000 sites. A brief description

Exploitation of Recent Citrix ShareFile RCE Vulnerability Begins

29 July 2023
The vulnerability, tracked as CVE-2023-24489 (CVSS score of 9.1), was the result of errors leading to unauthenticated file upload, which could then be exploited to obtain RCE, says security firm Assetnote, which identified and reported the bug.

UK NCSC Publishes New Guidance on Shadow IT

29 July 2023
Given the potentially serious repercussions of shadow IT, technical teams should focus on finding where it exists in the organization and addressing the underlying causes of it, the NCSC argued.

New Android Malware CherryBlos Utilizing OCR to Steal Sensitive Data

29 July 2023
A new Android malware strain called CherryBlos has been observed making use of optical character recognition (OCR) techniques to gather sensitive data stored in pictures. CherryBlos, per Trend Micro, is distributed via bogus posts on social media platforms and comes with capabilities to steal cryptocurrency wallet-related credentials and act as a clipper to substitute wallet addresses when a