Latest Cybersecurity News and Articles


Legal industry expresses AI concerns

27 July 2023
The legal industry's response to artificial intelligence (AI) was analyzed in a recent report by Litify, finding that there were privacy concerns. 

Elizabeth Davies joins Verkada as Chief Privacy Officer

27 July 2023
Elizabeth Davies has been hired as Chief Privacy Officer at Verkada. Davies will oversee Verkada's privacy and government affairs programs.

CISA Analysis Shows Most Cyberattacks on Governments, Critical Infrastructure Involve Valid Credentials

27 July 2023
More than half of all cyberattacks on government agencies, critical infrastructure organizations, and state-level government bodies involved the use of valid accounts, according to a new report from the CISA.

CardioComm Takes Systems Offline Following Cyberattack

27 July 2023
The attack, the company says, impacted its production server environments and has an impact on its business operations. Visitors to the company’s website are informed that CardioComm services are currently offline.

Up to 11 Million People Hit by MOVEit Hack at Government Services Firm Maximus

27 July 2023
According to Maximus, the attackers stole files containing personal information and protected health information, including Social Security numbers, “of at least 8 to 11 million individuals”.

Report reveals new information about Akira Group connection to Conti

27 July 2023
New research dives into the Akira ransomware group, including the group’s recent victim focuses, tactics and affiliation with Conti.

China Allegedly Turns to Transnational Criminals to Spread Disinformation in Australia

27 July 2023
Australian researchers have found evidence that China is using fake social media accounts linked to transnational criminal groups to spread online propaganda and disinformation.

Hackers Target Apache Tomcat Servers for Mirai Botnet and Crypto Mining

27 July 2023
Misconfigured and poorly secured Apache Tomcat servers are being targeted as part of a new campaign designed to deliver the Mirai botnet malware and cryptocurrency miners.

Introducing FraudGPT: The Latest AI Cybercrime Tool in the Dark Web

27 July 2023
In the wake of WormGPT's success, threat actors have now introduced another AI-powered cybercrime tool called FraudGPT. This AI bot is being promoted on numerous dark web marketplaces and Telegram channels, and is capable of designing spear-phishing emails, generating cracking tools, and facilitating carding activities.

Industry Coalition Calls For Enhanced Network Resilience

27 July 2023
The alliance argued that, while these vendors and their peers work hard to make their products as secure as possible, end-customer patching and vulnerability management is often sub-par.

Decoy Dog Malware Evolves to Expand its Reach

27 July 2023
An unidentified nation-state appears to be preparing for a new hacking campaign, according to researchers at Infoblox. The campaign uses the relatively new Decoy Dog malware toolkit. Decoy Dog has undergone a major upgrade from Pupy, an open-source remote access tool, to disguise its activities and ensure long-term access to compromised devices.

NATO Investigates Alleged Data Theft by SiegedSec Hackers

27 July 2023
Cybersecurity company CloudSEK analyzed the leaked data and found that it comprises 845MB of files, 8,000 rows of user-related sensitive information, unclassified documents, and user account access details.

GameOver(lay): Two Severe Linux Vulnerabilities Impact 40% of Ubuntu Users

27 July 2023
Cybersecurity researchers have disclosed two high-severity security flaws in the Ubuntu kernel that could pave the way for local privilege escalation attacks. Cloud security firm Wiz, in a report shared with The Hacker News, said the easy-to-exploit shortcomings have the potential to impact 40% of Ubuntu users. "The impacted Ubuntu versions are prevalent in the cloud as they serve as the default

DOJ Reorganizes Units to Better Fight Ransomware

27 July 2023
The U.S. Justice Department is merging its National Cryptocurrency Enforcement Team with its Crime and Intellectual Property Section to strengthen its capabilities in investigating cryptocurrency-related criminal cases and cybercrime.

New Malvertising Campaign Distributing Trojanized IT Tools via Google and Bing Search Ads

27 July 2023
A new malvertising campaign has been observed leveraging ads on Google Search and Bing to target users seeking IT tools like AnyDesk, Cisco AnyConnect VPN, and WinSCP, and trick them into downloading trojanized installers with an aim to breach enterprise networks and likely carry out future ransomware attacks. Dubbed Nitrogen, the "opportunistic" activity is designed to deploy second-stage

New Nitrogen Malware Pushed via Google Ads for Ransomware Attacks

27 July 2023
Sophos X-Ops researchers have discovered a new malware campaign called Nitrogen. The campaign uses malicious advertising and impersonates legitimate software to compromise business networks.

Repeatable VEC Attacks Target Critical Infrastructure

27 July 2023
According to a new report published by cybersecurity firm Abnormal Security earlier today, VEC attacks – a variant of business email compromise (BEC) – pose a significant risk to organizations worldwide.

Akira Ransomware Compromised at Least 63 Victims Since March

27 July 2023
Akira commonly infiltrates targeted Windows and Linux systems through VPN services, especially where users haven't enabled multi-factor authentication. To gain access, attackers use compromised credentials, which are likely acquired on the dark web.

Zero Trust Rated as Highly Effective by Businesses Worldwide

27 July 2023
Zero trust is here to stay, with 82% of experts currently working on implementing zero trust, and 16% planning to begin within 18 months, according to a study by Beyond Identity.

Lazarus Hackers Linked to $60 Million Alphapo Cryptocurrency Theft

27 July 2023
Blockchain analysts blame the North Korean Lazarus hacking group for a recent attack on payment processing platform Alphapo where the attackers stole almost $60 million in crypto.