Latest Cybersecurity News and Articles


FortiGuard Labs Warns of .ZIP Domains Fueling Phishing Attacks

19 July 2023
Threat actors are now exploiting the .ZIP top-level domain as a tool for phishing attacks, using the familiar file extension to deceive users into downloading malicious files.

Chinese APT41 Hackers Target Mobile Devices with New WyrmSpy and DragonEgg Spyware

19 July 2023
The prolific China-linked nation-state actor known as APT41 has been linked to two previously undocumented strains of Android spyware called WyrmSpy and DragonEgg. "Known for its exploitation of web-facing applications and infiltration of traditional endpoint devices, an established threat actor like APT 41 including mobile in its arsenal of malware shows how mobile endpoints are high-value

Exploring the Dark Side: OSINT Tools and Techniques for Unmasking Dark Web Operations

19 July 2023
On April 5, 2023, the FBI and Dutch National Police announced the takedown of Genesis Market, one of the largest dark web marketplaces. The operation, dubbed "Operation Cookie Monster," resulted in the arrest of 119 people and the seizure of over $1M in cryptocurrency. You can read the FBI's warrant here for details specific to this case. In light of these events, I'd like to discuss how OSINT

Variants of BPFDoor Deployed in Linux Kernel

19 July 2023
Trend Micro uncovered a cyber operation by the Red Menshen APT group wherein it utilizes various versions of the BPFDoor backdoor to target Linux and cloud servers. A six-fold increase has been observed in the addition of instructions to BPF as those found in samples from 2022. Security teams across organizations should leverage provided IOCs to detect anomalies in their network.

Google Fixes ‘Bad.Build’ Vulnerability Affecting Cloud Build Service

19 July 2023
Orca Security, which reported the bug to Google, said that attackers could impersonate the accounts and manipulate the build, injecting malicious code or taking other actions.

Bad.Build Flaw in Google Cloud Build Raises Concerns of Privilege Escalation

19 July 2023
Cybersecurity researchers have uncovered a privilege escalation vulnerability in Google Cloud that could enable malicious actors tamper with application images and infect users, leading to supply chain attacks. The issue, dubbed Bad.Build, is rooted in the Google Cloud Build service, according to cloud security firm Orca, which discovered and reported the issue. "By abusing the flaw and enabling

Bureau raises $16.5 million to help users prevent fraud

19 July 2023
Bureau announced an additional $4.5 million from GMO VenturePartners, GMO Payment Gateway, and existing investors to complete its Series A funding round at $16.5 million. With this, total funding for the startup has reached $20.5 million to date.

Germany’s new cyber chief to ‘intensify and focus’ work shaping European rules

19 July 2023
Claudia Plattner, the new president of Germany’s BSI, told journalists she aimed to “intensify and focus” the agency’s work on using the levers of the European Union to improve cybersecurity in Germany and across the continent.

Called a Bogus Airline Customer Support Number? Google is Hustling to Fix That

19 July 2023
The company noted that it filed a lawsuit last month against a scammer who was posting fake reviews on Google Maps and attempting to manipulate other Google services for small businesses.

Medical Device Maker Flags Eight Flaws in Drug Infusion Products

19 July 2023
CISA said the BD product vulnerabilities have a "low attack complexity" and that successful exploitation could allow a malicious actor to compromise sensitive data, hijack a session, modify firmware, and make changes to system configurations.

Zero-Day Attacks Exploited Critical Vulnerability in Citrix ADC and Gateway

19 July 2023
Citrix today is alerting customers of a critical-severity vulnerability (CVE-2023-3519) in NetScaler ADC and NetScaler Gateway that already has exploits in the wild, and “strongly urges” to install updated versions without delay.

Defunct Avaddon Rebranded as NoEscape Ransomware

19 July 2023
A strong argument for a connection has been established between the NoEscape ransomware and the obsolete Avaddon group. The encryption algorithms used by NoEscape and Avaddon ransomware are nearly identical, except that NoEscape switched to using the Salsa20 algorithm. Furthermore, sources have confirmed that multiple key members of Avaddon have joined the new ransomware operation.

WormGPT: Emerging AI Tool Raises Concerns over Advanced Cyber Threats

19 July 2023
A new malicious tool dubbed WormGPT is doing rounds in underground forums as a new generative AI cybercrime tool. Attackers could be preparing to execute sophisticated phishing attacks by crafting highly convincing fake emails, said security experts.

U.S. Government Blacklists Cytrox and Intellexa Spyware Vendors for Cyber Espionage

19 July 2023
The U.S. government on Tuesday added two foreign commercial spyware vendors, Cytrox and Intellexa, to an economic blocklist for weaponizing cyber exploits to gain unauthorized access to devices and "threatening the privacy and security of individuals and organizations worldwide." This includes the companies' corporate holdings in Hungary (Cytrox Holdings Crt), North Macedonia (Cytrox AD), Greece

Zero-Day Attacks Exploited Critical Vulnerability in Citrix ADC and Gateway

18 July 2023
Citrix is alerting users of a critical security flaw in NetScaler Application Delivery Controller (ADC) and Gateway that it said is being actively exploited in the wild. Tracked as CVE-2023-3519 (CVSS score: 9.8), the issue relates to a case of code injection that could result in unauthenticated remote code execution. It impacts the following versions - NetScaler ADC and NetScaler Gateway 13.1

Gamaredon APT Steals Data Within an Hour

18 July 2023
Once again, the Gamaredon APT is carrying out a new wave of phishing attacks targeting Ukrainian government agencies, stealing data within an hour of the attack. The campaign is aimed at entities in Ukraine, including security services, military, and government organizations. It is advised that organizations must adopt real-time threat alerting and threat insight-sharing solutions to stay updated real-time about new tactics and techniques adopted by threat actors.

UK: IT Worker Jailed for Impersonating Ransomware Gang to Extort Employer

18 July 2023
To deceive the company, he impersonated the ransomware gang extorting them. He tried to redirect the ransomware payments by switching the cybercriminals' cryptocurrency wallet to one under his control.

Update: UKG Agrees to Pay Up to $6M in Lawsuit Tied to 2021 Breach

18 July 2023
The ransomware attack, which impacted multiple UKG customers such as Tesla, PepsiCo, Whole Foods, and New York City’s Metropolitan Transportation Authority, hindered some customers’ ability to process payroll.

Black Hat Hacker Exposes Real Identity After Infecting Own Computer With Malware

18 July 2023
Using the online moniker ‘La_Citrix’, the threat actor has been active on Russian-speaking cybercrime forums since 2020, offering access to hacked companies and info-stealer logs from active infections.

White House Unveils Consumer Labeling Program to Strengthen IoT Security

18 July 2023
The Biden administration has considered an Energy Star type of consumer labeling program a key part of an effort to strengthen the nation’s cyber infrastructure following the SolarWinds and Colonial Pipeline attacks.