Latest Cybersecurity News and Articles
21 July 2023
The U.S. Justice Department and the Federal Trade Commission (FTC) announced that Amazon has agreed to pay a $25 million fine to settle alleged children's privacy laws violations related to the company's Alexa voice assistant service.
21 July 2023
A new malware strain known as BundleBot has been stealthily operating under the radar by taking advantage of .NET single-file deployment techniques, enabling threat actors to capture sensitive information from compromised hosts.
21 July 2023
Sophisticated DDoS attacks worldwide reached 5.4 trillion in Q2 2023. This represents a 15% increase compared to the number of attacks observed in Q1 2023. One of the factors associated with the pro-Russia hacker groups REvil, Killnet, and Anonymous Sudan targeting Western websites amid the war in Ukraine. Enabling firewalls, and having good internet security solutions are recommended to ensure safer internet browsing.
21 July 2023
A Chinese cyber-espionage campaign revealed by Microsoft last week compromised the government email account of the US ambassador to China and other officials, a new report has claimed.
21 July 2023
The exposed data included passwords, secret tokens, and credentials, which could have been used by malicious actors to carry out attacks such as phishing campaigns and website manipulation.
21 July 2023
A new malware strain known as BundleBot has been stealthily operating under the radar by taking advantage of .NET single-file deployment techniques, enabling threat actors to capture sensitive information from compromised hosts.
"BundleBot is abusing the dotnet bundle (single-file), self-contained format that results in very low or no static detection at all," Check Point said in a report
21 July 2023
The US Cybersecurity and Infrastructure Security Agency (CISA) revealed on Thursday that the recently disclosed Citrix zero-day vulnerability tracked as CVE-2023-3519 has been exploited against a critical infrastructure organization.
21 July 2023
The Chinese nation-state group APT41 has been associated with two new Android spyware strains, named WyrmSpy and DragonEgg. The initial infection vector for the mobile surveillanceware campaign remains uncertain, but social engineering is suspected. Users should avoid downloading apps from untrusted third-party sources or download apps with credibility.
21 July 2023
The number of successful ransomware attacks and data breach attempts fell by 30% over the last year, the number of reported security incident types at organizations increased, according to the 2023 Cybersecurity Perspectives Survey by Scale.
21 July 2023
Regardless of the country, local government is essential in most citizens' lives. It provides many day-to-day services and handles various issues. Therefore, their effects can be far-reaching and deeply felt when security failures occur.
In early 2023, Oakland, California, fell victim to a ransomware attack. Although city officials have not disclosed how the attack occurred, experts suspect a
21 July 2023
Mallox ransomware is a strain of ransomware that targets Microsoft Windows systems. It has been active since June 2021 and has recently seen an increase in activity, with a 174% rise in attacks compared to the previous year.
21 July 2023
As modern software trends toward distributed architectures, microservices, and extensive use of third-party and open-source components, dependency management only gets harder, according to Endor Labs.
21 July 2023
The new vulnerabilities disclosed by Eclypsium on Thursday are CVE-2023-34329, a critical authentication bypass issue that can be exploited by spoofing HTTP headers, and CVE-2023-34330, a code injection flaw.
21 July 2023
According to the new data presented in Salt Security's 2023 State of API Security for Financial Services and Insurance report, nearly 70% of financial services and insurance companies have encountered rollout delays due to API security issues.
21 July 2023
On average, SOC teams receive 4,484 alerts daily and spend nearly three hours a day manually triaging alerts, according to a study by Vectra AI. Security analysts are unable to deal with 67% of the daily alerts received.
21 July 2023
Cybersecurity researchers discovered a new P2P worm named P2PInfect that targets vulnerable Redis instances for exploitation. The worm is notable for its use of the critical Lua sandbox escape flaw, identified as CVE-2022-0543, to infect systems. Written in Rust, its attacks are more scalable than other worms. Organizations must use IOCs around the worm's modus operandi and implement robust security measures.
21 July 2023
On July 19, Adobe issued another ColdFusion update to fix three new CVEs. One of them, CVE-2023-38205, is the bypass for CVE-2023-29298. The software giant warned in its advisory that CVE-2023-38205 has been exploited in the wild in limited attacks.
21 July 2023
Several distributed denial-of-service (DDoS) botnets have been observed exploiting a critical flaw in Zyxel devices that came to light in April 2023 to gain remote control of vulnerable systems.
"Through the capture of exploit traffic, the attacker's IP address was identified, and it was determined that the attacks were occurring in multiple regions, including Central America, North America,
21 July 2023
Over eight in 10 (83%) of the UK’s critical national infrastructure (CNI) firms believe new technologies designed to enhance sustainability will become a significant vector for cyberattacks, according to Bridewell.
21 July 2023
GitHub attributed the attacks to a group known at Microsoft (which owns GitHub) by the name “Jade Sleet” and called TraderTraitor by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).