Latest Cybersecurity News and Articles


70% financial services, insurance companies suffer API security delays

24 July 2023
A new report reveals nearly 70% of financial services and insurance companies have suffered rollout delays due to API security.

Atlassian Patches Remote Code Execution Vulnerabilities in Confluence, Bamboo

24 July 2023
The most severe of these issues, tracked as CVE-2023-22508 (CVSS score of 8.5), was introduced in Confluence version 7.4.0. The second bug, tracked as CVE-2023-22505 (CVSS score of 8.0), was introduced in Confluence version 8.0.0.

Lazarus Targets Windows IIS Web Servers for Malware Distribution

24 July 2023
ASEC discovered that the North Korean state-sponsored Lazarus APT group is attacking Windows Internet Information Service (IIS) web servers and using them to distribute malware. It is imperative for organizations to adopt stringent measures, including attack surface management, to identify exposed assets and continuously apply the latest security patches.

Over 20,000 Citrix Appliances Vulnerable to New Exploit

24 July 2023
A new exploit technique targeting a recent Citrix Application Delivery Controller (ADC) and Gateway vulnerability can be used against thousands of unpatched devices, cybersecurity firm Bishop Fox claims.

Home affairs cyber survey exposed personal data of participating firms

24 July 2023
Home affairs cyber survey exposed personal data of participating firms Minister admits leak of ‘sensitive’ information after research into the Optus and Medibank hacks was ‘deeply ironic’Get our morning and afternoon news emails, free app or daily news podcastThe home affairs department exposed the personal information of more than 50 small business survey participants who were sought for their views on cybersecurity, Guardian Australia can reveal.The names, business names, phone numbers and emails of the participants in the survey were published on the parliament website in response to a question on notice from May’s Budget estimates hearing. Continue reading...

Banking Sector Witnesses First-Ever OSS Supply Chain Attack

24 July 2023
For the first time, the banking sector has been explicitly targeted by two distinct Open-Source Software (OSS) supply chain attacks that enabled attackers to stealthily overlay the banking sites. Organizations must equip themselves with the best early threat alerting and sharing platforms that can enable them to promptly identify the risks and perform threat assessment in real-time.

Critical Zero-Days in Atera Windows Installers Expose Users to Privilege Escalation Attacks

24 July 2023
The flaws, discovered by Mandiant on February 28, have been assigned the identifiers CVE-2023-26077 and CVE-2023-26078, with the issues remediated in versions 1.8.3.7 and 1.8.4.9 released by Atera on April 17, and June 26, respectively.

Report: US and UK executives grapple with evolving data privacy laws

24 July 2023
As global data privacy compliance increases in scope and complexity, only about half of executives feel “very prepared” to meet regulatory requirements in the United States, United Kingdom and European Union. 

Norwegian Government Security and Service Organisation Hit by Cyberattack

24 July 2023
Twelve Norwegian government ministries have been hit by a cyberattack, the Norwegian government said on Monday, the latest attack to hit the public sector of Europe's largest gas supplier and NATO's northernmost member.

Critical Zero-Days in Atera Windows Installers Expose Users to Privilege Escalation Attacks

24 July 2023
Zero-day vulnerabilities in Windows Installers for the Atera remote monitoring and management software could act as a springboard to launch privilege escalation attacks. The flaws, discovered by Mandiant on February 28, 2023, have been assigned the identifiers CVE-2023-26077 and CVE-2023-26078, with the issues remediated in versions 1.8.3.7 and 1.8.4.9 released by Atera on April 17, 2023, and

New OpenSSH Vulnerability Exposes Linux Systems to Remote Command Injection

24 July 2023
Details have emerged about a now-patched flaw in OpenSSH that could be exploited to run arbitrary commands remotely. The vulnerability is being tracked under the CVE identifier CVE-2023-38408. It impacts all versions of OpenSSH before 9.3p2.

Google Messages Getting Cross-Platform End-to-End Encryption with MLS Protocol

24 July 2023
Google has announced that it intends to add support for Message Layer Security (MLS) to its Messages service for Android and open source implementation of the specification. "Most modern consumer messaging platforms (including Google Messages) support end-to-end encryption, but users today are limited to communicating with contacts who use the same platform," Giles Hogben, privacy engineering

Perimeter81 Vulnerability Disclosed After Botched Disclosure Process

24 July 2023
Cybersecurity researcher Erhad Husovic published a blog post in late June to disclose the details of a local privilege escalation vulnerability discovered in Perimeter81’s macOS application.

How to Protect Patients and Their Privacy in Your SaaS Apps

24 July 2023
The healthcare industry is under a constant barrage of cyberattacks. It has traditionally been one of the most frequently targeted industries, and things haven’t changed in 2023. The U.S. Government’s Office for Civil Rights reported 145 data breaches in the United States during the first quarter of this year. That follows 707 incidents a year ago, during which over 50 million records were

CISOs are making cybersecurity a business problem

24 July 2023
U.S. enterprises are responding to growing cybersecurity threats by working to make the best use of tools and services to ensure business resilience, according to an ISG report.

First Known Targeted OSS Supply Chain Attacks Against the Banking Sector

24 July 2023
The attackers employed deceptive tactics such as creating fake LinkedIn profiles to appear credible and using customized command and control (C2) centers for each target, exploiting legitimate services for illicit activities.

Attackers intensify DDoS attacks with new tactics

24 July 2023
As we entered 2023, the cybersecurity landscape witnessed an increase in sophisticated, high-volume attacks, according to Gcore. The maximum attack power rose from 600 to 800 Gbps.

CERT-In Cautions Internet Users Against Akira Ransomware Attack

24 July 2023
In its latest advisory, India's federal cybersecurity agency warned of a ransomware called 'Akira' that steals vital personal information and encrypts data leading to extortion of money from people.

Update: Virustotal Apologizes for Accidental Leak That Exposed Customer Data

24 July 2023
Google’s malware scanning platform VirusTotal published an apology on Friday after hundreds of individuals working for defense and intelligence agencies globally had their names and email addresses accidentally exposed by an employee.

Ransom Monetization Rates Fall to Record Low Despite Jump In Average Ransom Payments

24 July 2023
According to a Coveware report, in the second quarter of 2023, the percentage of ransomware attacks resulting in payment decreased to a record low of 34%. This is attributed to companies investing in security measures and incident response training.