Latest Cybersecurity News and Articles


EU Governments Reject Requiring Manufacturers to Report Vulnerabilities to Central Cyber Agency

26 July 2023
European Union governments have pushed back on the central role initially suggested for the bloc’s cybersecurity agency, rejecting a proposal requiring manufacturers to report actively exploited vulnerabilities to the ENISA.

Critical Flaws Found in Microsoft Message Queuing Service

26 July 2023
Three vulnerabilities have been discovered within the Microsoft Message Queuing (MSMQ) service – a proprietary messaging protocol designed to enable secure communication between applications running on separate computers.

Australian Government Exposed Personal Information via Security Report

26 July 2023
The Guardian Australia revealed yesterday that around 50 business owners and employees got more than they bargained for when they took part in the Understanding Small Business and Cyber Security study.

Update: Norway Says Ivanti Zero-Day Was Used to Hack Government IT Systems

26 July 2023
The Norwegian National Security Authority (NSM) has confirmed that attackers used a zero-day vulnerability in Ivanti's Endpoint Manager Mobile (EPMM) solution to breach a software platform used by 12 ministries in the country.

Over 400,000 Corporate Credentials Stolen by Info-Stealing Malware

26 July 2023
The analysis of nearly 20 million information-stealing malware logs sold on the dark web and Telegram channels revealed that they had achieved significant infiltration into business environments.

Cybersecurity Public-Private Partnership: Where Do We Go Next?

26 July 2023
Sharing threat information and cooperating with other threat intelligence groups helps to strengthen customer safeguards and boosts the effectiveness of the cybersecurity sector overall.

Rust-based Realst Infostealer Targeting Apple macOS Users' Cryptocurrency Wallets

26 July 2023
A new malware family called Realst has become the latest to target Apple macOS systems, with a third of the samples already designed to infect macOS 14 Sonoma, the upcoming major release of the operating system. Written in the Rust programming language, the malware is distributed in the form of bogus blockchain games and is capable of "emptying crypto wallets and stealing stored password and

Critical MikroTik RouterOS Vulnerability Exposes Over Half a Million Devices to Hacking

26 July 2023
A severe privilege escalation issue impacting MikroTik RouterOS could be weaponized by remote malicious actors to execute arbitrary code and seize full control of vulnerable devices. Cataloged as CVE-2023-30799 (CVSS score: 9.1), the shortcoming is expected to put approximately 500,000 and 900,000 RouterOS systems at risk of exploitation via their web and/or Winbox interfaces, respectively,

Who and What is Behind the Malware Proxy Service SocksEscort?

25 July 2023
Researchers this month uncovered a two-year-old Linux-based remote access trojan dubbed AVrecon that enslaves Internet routers into botnet that bilks online advertisers and performs password-spraying attacks. Now new findings reveal that AVrecon is the malware engine behind a 12-year-old service called SocksEscort, which rents hacked residential and small business devices to cybercriminals looking to hide their true location online.

Travel and tourism sector ranked third in cyberattack incidents

25 July 2023
With increased digitalization comes greater vulnerability to cyber threats, making cybersecurity a top priority for lodging and aviation companies.

Spyhide Stalkerware is Spying on Tens of Thousands of Phones

25 July 2023
Spyhide is secretly collecting private data from tens of thousands of Android devices worldwide. The app is often installed on a victim's phone by someone who knows their passcode, and it remains hidden on the home screen.

Casbaneiro Banking Malware Goes Under the Radar with UAC Bypass Technique

25 July 2023
"They are still heavily focused on Latin American financial institutions, but the changes in their techniques represent a significant risk to multi-regional financial organizations as well," Sygnia said in a statement shared with The Hacker News.

Update: North Korean Cyber Group Suspected in JumpCloud Breach

25 July 2023
Mandiant’s investigation into the attack now revealed that the intrusions were attributed to UNC4899, a hacking group associated with the Democratic People’s Republic of Korea (DPRK).

Hacker Claims to Have Stolen Sensitive Medical Records from Egypt's Ministry of Health

25 July 2023
The allegation, made on the hacker forum Popürler, was observed by cyber threat intelligence provider SOCRadar and dark web monitoring firm Falcon Feeds on July 25, 2023.

Thales Acquiring Imperva From Thoma Bravo for $3.6 Billion

25 July 2023
Thales will buy Imperva for an enterprise value of $3.6 billion ($3.7 billion gross value minus $0.1 billion tax benefits). The transaction is expected to close by the beginning of 2024.

Chinese Cyberespionage Group APT31 Targets Eastern European Entities

25 July 2023
A China-linked group APT31 (aka Zirconium) has been linked to a cyberespionage campaign targeting industrial organizations in Eastern Europe. The attackers abused DLL hijacking vulnerabilities in cloud-based data storage systems such as Dropbox or Yandex, as well as a temporary file-sharing service, to deliver next-stage malware.

67% of organizations not confident in cyberattack recovery

25 July 2023
According to a survey by Cohesity, 45% of respondents confirmed their business had been the victim of a ransomware attack in the prior six months.

Five New 'TETRA:BURST' Vulnerabilities Exposed in Widely Used Radio Communication System

25 July 2023
The issues, discovered by Midnight Blue in 2021 and held back until now, have been collectively called TETRA:BURST. There is no conclusive evidence to determine that the vulnerabilities have been exploited in the wild to date.

North Korean Nation-State Actors Exposed in JumpCloud Hack After OPSEC Blunder

25 July 2023
North Korean nation-state actors affiliated with the Reconnaissance General Bureau (RGB) have been attributed to the JumpCloud hack following an operational security (OPSEC) blunder that exposed their actual IP address. Google-owned threat intelligence firm Mandiant attributed the activity to a threat actor it tracks under the name UNC4899, which likely shares overlaps with clusters already

RaaS proliferation: 14 new ransomware groups target organizations worldwide

25 July 2023
In the second quarter of 2023, GuidePoint Research and Intelligence Team (GRIT) tracked 1,177 total publicly posted ransomware victims claimed by 41 different threat groups.