Latest Cybersecurity News and Articles


Supply Chain, Open Source Pose Major Challenge to AI Systems

26 July 2023
Supply chain compromise, open source technology, and rapid advances in artificial intelligence capabilities pose significant challenges to safeguarding AI, experts told a Senate panel Tuesday.

New Realst Info-stealer Targets MacOS, Empties Crypto Wallets

26 July 2023
In the ever-evolving information-stealer landscape, a new malware dubbed Realst has emerged. Realst is designed to target macOS systems and is capable of emptying crypto wallets and stealing stored passwords and browser data. Attackers are using tricks to lure gamers with money, which is a red flag against downloading these games.

90% of SOC analysts believe current threat detection tools are effective

26 July 2023
The new 2023 State of Threat Detection Research Report provides insight into the “spiral of more” that prevents security operations center (SOC) teams from effectively securing their organizations from cyberattacks.

Super Admin Elevation Bug Puts 900,000 Mikrotik Devices at Risk

26 July 2023
The critical flaw, tracked as CVE-2023-30799, allows remote attackers with an existing admin account to elevate their privileges to "super-admin" via the device's Winbox or HTTP interface.

UK Government Report Finds Cybersecurity Skills Gap Stagnant

26 July 2023
The UK Government’s Cyber Security Skills in the UK Labour Market 2023 report shows a staggering 50% of all UK businesses have a basic cybersecurity skills gap, showing little improvement from the 2022 report.

New Realst macOS Malware Steals Your Cryptocurrency Wallets

26 July 2023
A new Mac malware named "Realst" is being used in a massive campaign targeting Apple computers, with some of its latest variants including support for macOS 14 Sonoma, which is still in development.

New York State Cyber Lead Warns of What States Face in Critical Infrastructure Defense

26 July 2023
Critical infrastructure providers are under more frequent and sophisticated cyberthreats as more nation-state adversaries work with criminal hackers to target the U.S., according to Colin Ahern, chief cyber officer for New York State.

Decoy Dog: New Breed of Malware Posing Serious Threats to Enterprise Networks

26 July 2023
A deeper analysis of a recently discovered malware called Decoy Dog has revealed that it's a significant upgrade over the Pupy RAT, an open-source remote access trojan it's modeled on. "Decoy Dog has a full suite of powerful, previously unknown capabilities – including the ability to move victims to another controller, allowing them to maintain communication with compromised machines and remain

Decoy Dog Malware Evolves to Use New Command-and-Control and Persistence Methods

26 July 2023
Initially discovered and disclosed in April 2023, Decoy Dog has proven to be more sophisticated than previously thought, using DNS for command-and-control (C2) and is suspected to be employed in ongoing nation-state cyberattacks.

Average cost of healthcare data breach reaches $11M, report finds

26 July 2023
Healthcare continues to be the most expensive industry for data breaches, beating out other sectors for the 13th year in a row, according to research conducted by the Ponemon Institute and published by IBM Security.

Fenix Cybercrime Group Poses as Tax Authorities to Target Latin American Users

26 July 2023
The goal of Fenix, according to the cybersecurity firm Metabase Q, is to act as an initial access broker and get a foothold into different companies in the region, and sell the access to ransomware affiliates for further monetization.

Companies are rushing into generative AI without a cohesive, secure strategy

26 July 2023
Despite mass adoption of generative AI, most companies don’t have a coordinated strategy for deploying it or know how to assess its security—exposing them to risks and disadvantages if they don’t change their approach, according to Grammarly.

ALPHV Ransomware Adds Data Leak API in New Extortion Strategy

26 July 2023
The ALPHV ransomware gang, also referred to as BlackCat, is trying to put more pressure on their victims to pay a ransom by providing an API for their leak site to increase visibility for their attacks.

Consumers Demand More From Businesses When It Comes to Security

26 July 2023
Incorporating machine learning into fraud prevention strategies is crucial for businesses to effectively identify and prevent fraud, as well as meet growing fraud risks and consumer expectations.

The Alarming Rise of Infostealers: How to Detect this Silent Threat

26 July 2023
A new study conducted by Uptycs has uncovered a stark increase in the distribution of information stealing (a.k.a. infostealer or stealer) malware. Incidents have more than doubled in Q1 2023, indicating an alarming trend that threatens global organizations. According to the new Uptycs' whitepaper, Stealers are Organization Killers, a variety of new info stealers have emerged this year, preying

Fenix Cybercrime Group Poses as Tax Authorities to Target Latin American Users

26 July 2023
Tax-paying individuals in Mexico and Chile have been targeted by a Mexico-based cybercrime group that goes by the name Fenix to breach targeted networks and steal valuable data. A key hallmark of the operation entails cloning official portals of the Servicio de Administración Tributaria (SAT) in Mexico and the Servicio de Impuestos Internos (SII) in Chile and redirecting potential victims to

Former NSA Insider Coker is White House Pick for National Cyber Director

26 July 2023
President Joe Biden on Tuesday announced he intends to nominate Harry Coker, a former executive director of the National Security Agency, to be the country’s national cyber director.

VMware Fixes Bug Exposing Cloud Foundry API Admin Credentials in Audit Logs

26 July 2023
Tracked as CVE-2023-20891, the security flaw addressed today by Vmware would allow remote attackers with low privileges to access Cloud Foundry API admin credentials on unpatched systems in low-complexity attacks that don't require user interaction.

New AI Tool 'FraudGPT' Emerges, Tailored for Sophisticated Attacks

26 July 2023
Following the footsteps of WormGPT, threat actors are advertising yet another cybercrime generative artificial intelligence (AI) tool dubbed FraudGPT on various dark web marketplaces and Telegram channels. "This is an AI bot, exclusively targeted for offensive purposes, such as crafting spear phishing emails, creating cracking tools, carding, etc.," Netenrich security researcher Rakesh Krishnan 

EU Governments Reject Requiring Manufacturers to Report Vulnerabilities to Central Cyber Agency

26 July 2023
European Union governments have pushed back on the central role initially suggested for the bloc’s cybersecurity agency, rejecting a proposal requiring manufacturers to report actively exploited vulnerabilities to the ENISA.