Latest Cybersecurity News and Articles


Report: DDoS Attacks, Growing More Sophisticated, Surged in Q2

21 July 2023
Among the most serious attacks during Q2 2023, researchers noted an ACK flood DDoS attack that originated from a Mirai-variant botnet comprising about 11,000 IP addresses. The attack targeted an ISP in the U.S. and peaked at 1.4 terabits per second.

Report: Microsoft the Most Phished Brand in Q2 2023

21 July 2023
Microsoft, Google, and Apple were the most frequently impersonated brands in phishing attacks during Q2 2023, highlighting the need for cybersecurity measures to protect against brand phishing.

Update: Attacker Infrastructure Links JumpCloud Intrusion to North Korean APT Activity

21 July 2023
Analysis of the infrastructure linked to the JumpCloud intrusion reveals patterns consistent with previous DPRK-linked campaigns, highlighting their unique tactics and techniques.

FakeSG: A SocGholish Competitor Delivers NetSupport RAT

21 July 2023
A new malicious campaign FakeSG has emerged, mirroring the tactics of the well-known SocGholish in delivering the NetSupport RAT through compromised WordPress websites. FakeSG imitates browser update templates based on the victim's browser and uses different layers of obfuscation and delivery techniques. It is recommended to patch any vulnerabilities in your WordPress site/s.

Citrix NetScaler ADC and Gateway Devices Under Attack: CISA Urges Immediate Action

21 July 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory on Thursday warning that the newly disclosed critical security flaw in Citrix NetScaler Application Delivery Controller (ADC) and Gateway devices is being abused to drop web shells on vulnerable systems. "In June 2023, threat actors exploited this vulnerability as a zero-day to drop a web shell on a critical

Update: Old Roblox Data Leak Resurfaces, 4000 Users' Personal Information Exposed

20 July 2023
The leak, which initially occurred in 2021 but gained more attention after being re-published on a public hacking forum, has led to high-profile users receiving malicious calls, texts, and emails.

Mallox Ransomware Exploits Weak MS-SQL Servers to Breach Networks

20 July 2023
Mallox ransomware activities in 2023 have witnessed a 174% increase when compared to the previous year, new findings from Palo Alto Networks Unit 42 reveal. "Mallox ransomware, like many other ransomware threat actors, follows the double extortion trend: stealing data before encrypting an organization's files, and then threatening to publish the stolen data on a leak site as leverage to convince

Critical Flaws in AMI MegaRAC BMC Software Expose Servers to Remote Attacks

20 July 2023
Two more security flaws have been disclosed in AMI MegaRAC Baseboard Management Controller (BMC) software that, if successfully exploited, could allow threat actors to remotely commandeer vulnerable servers and deploy malware. "These new vulnerabilities range in severity from High to Critical, including unauthenticated remote code execution and unauthorized device access with superuser

Q2 observed more ransomware events than Q1

20 July 2023
Ransomware attacks in Q2 was analyzed in a recent report by GuidePoint Security and shows a 38% increase in public ransomware victims compared to Q1.

Renewable technologies add risk to the US electric grid, experts warn

20 July 2023
Technologies that underpin solar and wind energy storage systems, which are central to transferring renewable power to the grid, are potential hacking risks, experts noted at a congressional hearing Tuesday.

Phishing via Google Ads

20 July 2023
Hackers are using URL redirects within Google ads to lead users to malicious sites, leveraging the trust and legitimacy of Google Ads. This technique, known as BEC 3.0, involves referencing legitimate sites instead of spoofed ones.

Zyxel Vulnerability Exploited by DDoS Botnets on Linux Systems

20 July 2023
Distributed Denial of Service (DDoS) botnets have been used to actively exploit a critical vulnerability found in Zyxel firewall models. The flaw, identified by Fortinet security researchers as CVE-2023-28771, explicitly affects Linux platforms.

Apache OpenMeetings Web Conferencing Tool Exposed to Critical Vulnerabilities

20 July 2023
Multiple security flaws have been disclosed in Apache OpenMeetings, a web conferencing solution, that could be potentially exploited by malicious actors to seize control of admin accounts and run malicious code on susceptible servers. "Attackers can bring the application into an unexpected state, which allows them to take over any user account, including the admin account," Sonar vulnerability

Tampa General Hospital Says Hackers Exfiltrated the Data of 1.2 Million Patients

20 July 2023
A security breach was detected on May 31, 2023, when suspicious activity was identified within its network. The affected systems were immediately taken offline to prevent further unauthorized access.

97% of organizations report plans to use generative AI by 2025

20 July 2023
A recent study from Grammarly and Forrester found that generative AI is being adopted across more organizations despite growing security concerns.

Turla's New DeliveryCheck Backdoor Breaches Ukrainian Defense Sector

20 July 2023
DeliveryCheck is distributed via email with malicious macros and can breach Microsoft Exchange servers to install a server-side component, turning a legitimate server into a malware C2 server.

CISA and Microsoft partner to expand access to logging capabilities

20 July 2023
 A collaboration between CISA and Microsoft, will now expanded cloud logging capabilities at no additional charge to customers, enhancing cyber defense and incident response.

CISA and NSA Issue New Guidance to Strengthen 5G Network Slicing Against Threats

20 July 2023
U.S. cybersecurity and intelligence agencies have released a set of recommendations to address security concerns with 5G standalone network slicing and harden them against possible threats.

North Korean State-Sponsored Hackers Suspected in JumpCloud Supply Chain Attack

20 July 2023
An analysis of the indicators of compromise (IoCs) associated with the JumpCloud hack has uncovered evidence pointing to the involvement of North Korean state-sponsored groups, in a style that's reminiscent of the supply chain attack targeting 3CX. The findings come from SentinelOne, which mapped out the infrastructure pertaining to the intrusion to uncover underlying patterns. It's worth noting

Russian Medical Lab Suspends Some Services After Ransomware Attack

20 July 2023
Customers of the Russian medical laboratory Helix have been unable to receive their test results for several days due to a “serious” cyberattack that crippled the company's systems over the weekend.