Latest Cybersecurity News and Articles


New OpenSSH Vulnerability Exposes Linux Systems to Remote Command Injection

24 July 2023
Details have emerged about a now-patched flaw in OpenSSH that could be potentially exploited to run arbitrary commands remotely on compromised hosts under specific conditions. "This vulnerability allows a remote attacker to potentially execute arbitrary commands on vulnerable OpenSSH's forwarded ssh-agent," Saeed Abbasi, manager of vulnerability research at Qualys, said in an analysis last week.

White House Secures Safety Commitments From Seven AI Companies

24 July 2023
Seven leading AI companies, including Amazon, Anthropic, Google, Meta, Microsoft, OpenAI, and Inflection, have committed to building secure systems and increasing transparency regarding model behavior, The White House announced Friday.

Phishers Exploiting Google Docs to Harvest Crypto Credentials

24 July 2023
Researchers at Check Point Software have discovered a new phishing scam campaign that exploits Google Docs to distribute illegitimate URLs and steal cryptocurrency credentials.

Update: Microsoft Attackers May Have Data Access Beyond Outlook, Researchers Warn

24 July 2023
The China-linked threat actors behind the theft of U.S. State Department and other Microsoft customer emails may have gained access to applications beyond Exchange Online and Outlook.com, according to a report released Friday by Wiz.

Clop Now Leaks Data Stolen in Moveit Attacks on Clearweb Sites

24 July 2023
The Clop ransomware gang is copying an ALPHV ransomware gang extortion tactic by creating Internet-accessible websites dedicated to specific victims, making it easier to leak stolen data and further pressuring victims into paying a ransom.

Banking Sector Targeted in Open-Source Software Supply Chain Attacks

24 July 2023
Cybersecurity researchers said they have discovered what they say is the first open-source software supply chain attacks specifically targeting the banking sector. "These attacks showcased advanced techniques, including targeting specific components in web assets of the victim bank by attaching malicious functionalities to it," Checkmarx said in a report published last week. "The attackers

Cl0p Gang to Earn Over $75 Million From MOVEit Extortion Attacks

22 July 2023
In a new report released today, Coveware explains that the number of victims paying ransoms has fallen to a record low of 34%, causing ransomware gangs to switch strategies to make their attacks more profitable.

Global CDN Service ‘jsdelivr’ Exposed Users to Phishing Attacks

22 July 2023
The malicious NPM package, which masqueraded as a legitimate alternative to a popular package, downloaded a phishing HTML code from the jsdelivr CDN service to steal users' credentials.

DHL Investigating MOVEit Breach as Number of Victims Surpasses 20 Million

22 July 2023
The United Kingdom arm of shipping giant DHL said it is investigating a data breach sourced back to its use of the MOVEit software, which has been exploited by a Russia-based ransomware group for nearly two months.

Coastal Mississippi County Recovering From Ransomware Attack

22 July 2023
The local government in George County, Mississippi, was thrown into chaos this weekend when ransomware actors used a discrete phishing email to gain deep access to the county’s systems.

Apple Threatens to Pull iMessage and FaceTime from U.K. Amid Surveillance Demands

22 July 2023
Apple has warned that it would rather stop offering iMessage and FaceTime services in the U.K. than bowing down to government pressure in response to new proposals that seek to expand digital surveillance powers available to state intelligence agencies. The development, first reported by BBC News, makes the iPhone maker the latest to join the chorus of voices protesting against forthcoming

Few Fortune 100 Firms List Security Pros in Their Executive Ranks

21 July 2023
Many things have changed since 2018, such as the names of the companies in the Fortune 100 list. But one aspect of that vaunted list that hasn't shifted much since is that very few of these companies list any security professionals within their top executive ranks. The next time you receive a breach notification letter that invariably says a company you trusted places a top priority on customer security and privacy, consider this: Only four of the Fortune 100 companies currently list a security professional in the executive leadership pages of their websites. This is actually down from five of the Fortune 100 in 2018, the last time KrebsOnSecurity performed this analysis.

HotRat as Hidden Script in Cracked Software

21 July 2023
In a recent encounter, security researchers stumbled across a HotRat malware distribution campaign that cybercriminals were offering bundled as cracked programs and games. HotRat is an offshoot of the open-source AsyncRAT framework. Implement strict software policies, regularly update and patch systems, and educate users about the risks of using cracked software.

HotRat: New Variant of AsyncRAT Malware Spreading Through Pirated Software

21 July 2023
A new variant of AsyncRAT malware dubbed HotRat is being distributed via free, pirated versions of popular software and utilities such as video games, image and sound editing software, and Microsoft Office.

FI$Cal names Benson as new Chief of Information Security

21 July 2023
The Department of Financial Information System for California (FISCal) has hired Jennifer Benson as the new Chief of the Information Security Office.

Azure AD Token Forging Technique in Microsoft Attack Extends Beyond Outlook, Wiz Reports

21 July 2023
The recent attack against Microsoft's email infrastructure by a Chinese nation-state actor referred to as Storm-0558 is said to have a broader scope than previously thought. According to cloud security company Wiz, the inactive Microsoft account (MSA) consumer signing key used to forge Azure Active Directory (Azure AD or AAD) tokens to gain illicit access to Outlook Web Access (OWA) and

HotRat: New Variant of AsyncRAT Malware Spreading Through Pirated Software

21 July 2023
A new variant of AsyncRAT malware dubbed HotRat is being distributed via free, pirated versions of popular software and utilities such as video games, image and sound editing software, and Microsoft Office. "HotRat malware equips attackers with a wide array of capabilities, such as stealing login credentials, cryptocurrency wallets, screen capturing, keylogging, installing more malware, and

Android SpyNote Attacks Electric and Water Public Utility Users in Japan

21 July 2023
A smishing campaign is targeting Japanese Android users by posing as a power and water infrastructure company and luring victims to a phishing website to download the SpyNote malware.

Apache OpenMeetings Web Conferencing Tool Exposed to Critical Vulnerabilities

21 July 2023
Multiple security flaws have been disclosed in Apache OpenMeetings, a web conferencing solution, that could be potentially exploited by malicious actors to seize control of admin accounts and run malicious code on susceptible servers.

Mallox Ransomware Activity Surges by 174%

21 July 2023
Mallox ransomware activity surged by nearly 174% in 2023, using the new variant Xollam, employing the double extortion tactic to demand ransom from victims. The development is also being perceived as more affiliate groups coming together in this mission. Organizations must remain vigilant and adapt security measures to stay one step ahead of such threats.