Latest Cybersecurity News and Articles
27 July 2023
The legal industry's response to artificial intelligence (AI) was analyzed in a recent report by Litify, finding that there were privacy concerns.
27 July 2023
Elizabeth Davies has been hired as Chief Privacy Officer at Verkada. Davies will oversee Verkada's privacy and government affairs programs.
27 July 2023
More than half of all cyberattacks on government agencies, critical infrastructure organizations, and state-level government bodies involved the use of valid accounts, according to a new report from the CISA.
27 July 2023
The attack, the company says, impacted its production server environments and has an impact on its business operations. Visitors to the company’s website are informed that CardioComm services are currently offline.
27 July 2023
According to Maximus, the attackers stole files containing personal information and protected health information, including Social Security numbers, “of at least 8 to 11 million individuals”.
27 July 2023
New research dives into the Akira ransomware group, including the group’s recent victim focuses, tactics and affiliation with Conti.
27 July 2023
Australian researchers have found evidence that China is using fake social media accounts linked to transnational criminal groups to spread online propaganda and disinformation.
27 July 2023
Misconfigured and poorly secured Apache Tomcat servers are being targeted as part of a new campaign designed to deliver the Mirai botnet malware and cryptocurrency miners.
27 July 2023
In the wake of WormGPT's success, threat actors have now introduced another AI-powered cybercrime tool called FraudGPT. This AI bot is being promoted on numerous dark web marketplaces and Telegram channels, and is capable of designing spear-phishing emails, generating cracking tools, and facilitating carding activities.
27 July 2023
The alliance argued that, while these vendors and their peers work hard to make their products as secure as possible, end-customer patching and vulnerability management is often sub-par.
27 July 2023
An unidentified nation-state appears to be preparing for a new hacking campaign, according to researchers at Infoblox. The campaign uses the relatively new Decoy Dog malware toolkit. Decoy Dog has undergone a major upgrade from Pupy, an open-source remote access tool, to disguise its activities and ensure long-term access to compromised devices.
27 July 2023
Cybersecurity company CloudSEK analyzed the leaked data and found that it comprises 845MB of files, 8,000 rows of user-related sensitive information, unclassified documents, and user account access details.
27 July 2023
Cybersecurity researchers have disclosed two high-severity security flaws in the Ubuntu kernel that could pave the way for local privilege escalation attacks.
Cloud security firm Wiz, in a report shared with The Hacker News, said the easy-to-exploit shortcomings have the potential to impact 40% of Ubuntu users.
"The impacted Ubuntu versions are prevalent in the cloud as they serve as the default
27 July 2023
The U.S. Justice Department is merging its National Cryptocurrency Enforcement Team with its Crime and Intellectual Property Section to strengthen its capabilities in investigating cryptocurrency-related criminal cases and cybercrime.
27 July 2023
A new malvertising campaign has been observed leveraging ads on Google Search and Bing to target users seeking IT tools like AnyDesk, Cisco AnyConnect VPN, and WinSCP, and trick them into downloading trojanized installers with an aim to breach enterprise networks and likely carry out future ransomware attacks.
Dubbed Nitrogen, the "opportunistic" activity is designed to deploy second-stage
27 July 2023
Sophos X-Ops researchers have discovered a new malware campaign called Nitrogen. The campaign uses malicious advertising and impersonates legitimate software to compromise business networks.
27 July 2023
According to a new report published by cybersecurity firm Abnormal Security earlier today, VEC attacks – a variant of business email compromise (BEC) – pose a significant risk to organizations worldwide.
27 July 2023
Akira commonly infiltrates targeted Windows and Linux systems through VPN services, especially where users haven't enabled multi-factor authentication. To gain access, attackers use compromised credentials, which are likely acquired on the dark web.
27 July 2023
Zero trust is here to stay, with 82% of experts currently working on implementing zero trust, and 16% planning to begin within 18 months, according to a study by Beyond Identity.
27 July 2023
Blockchain analysts blame the North Korean Lazarus hacking group for a recent attack on payment processing platform Alphapo where the attackers stole almost $60 million in crypto.