Latest Cybersecurity News and Articles


2022 ransomware attacks declined in number but grew in sophistication

19 July 2023
A recent report finds that state, local and educational organizations, despite having lower profiles, are still at risk of a cyberattack.

Trends in Ransomware-as-a-Service and Cryptocurrency to Monitor

19 July 2023
To defend against RaaS groups, organizations need a holistic, defense-in-depth approach that includes measures like multi-factor authentication, email security, patch management, and comprehensive asset management.

Cybersecurity Firm Sophos Impersonated by New SophosEncrypt Ransomware

19 July 2023
Discovered yesterday by MalwareHunterTeam, the ransomware was initially thought to be part of a red team exercise by Sophos. However, the Sophos X-Ops team tweeted that they did not create the encryptor and that they are investigating its launch.

Ukraine Police Bust Another Bot Farm Accused of Pro-Russia Propaganda, Internet Fraud

19 July 2023
Ukraine's Cyber Police shut down yet another bot farm that was reportedly spreading disinformation about the war in Ukraine on social media, just one month after a similar illicit operation was raided in west-central Ukraine.

How to Manage Your Attack Surface?

19 July 2023
Attack surfaces are growing faster than security teams can keep up. To stay ahead, you need to know what's exposed and where attackers are most likely to strike. With cloud migration dramatically increasing the number of internal and external targets, prioritizing threats and managing your attack surface from an attacker's perspective has never been more important. Let's look at why it's growing

CISA and NSA Issue New Guidance to Strengthen 5G Network Slicing Against Threats

19 July 2023
U.S. cybersecurity and intelligence agencies have released a set of recommendations to address security concerns with 5G standalone network slicing and harden them against possible threats. "The threat landscape in 5G is dynamic; due to this, advanced monitoring, auditing, and other analytical capabilities are required to meet certain levels of network slicing service level requirements over

FIA World Endurance Championship Driver Passports Left Unsecured

19 July 2023
On June 16th, Cybernews researchers came across two misconfigured, meaning publicly exposed, Google Cloud Storage buckets. Both combined, they contained over 1.1 million files.

Mario Movie Malware Might Maliciously Mess With Your Machine

19 July 2023
Downloading pirated movies from dubious sources can expose users to malware, putting personal and financial data at risk. Even visiting piracy websites or clicking on pop-ups and redirect links can lead to malware infections.

U.S. Blacklists Two Spyware Firms Run by an Israeli Former General

19 July 2023
The Biden administration added two Europe-based hacking firms controlled by an Israeli former general to a Commerce Department blacklist, marking its latest effort to try to rein in a spyware industry that has spiraled out of control in recent years.

FortiGuard Labs Warns of .ZIP Domains Fueling Phishing Attacks

19 July 2023
Threat actors are now exploiting the .ZIP top-level domain as a tool for phishing attacks, using the familiar file extension to deceive users into downloading malicious files.

Chinese APT41 Hackers Target Mobile Devices with New WyrmSpy and DragonEgg Spyware

19 July 2023
The prolific China-linked nation-state actor known as APT41 has been linked to two previously undocumented strains of Android spyware called WyrmSpy and DragonEgg. "Known for its exploitation of web-facing applications and infiltration of traditional endpoint devices, an established threat actor like APT 41 including mobile in its arsenal of malware shows how mobile endpoints are high-value

Exploring the Dark Side: OSINT Tools and Techniques for Unmasking Dark Web Operations

19 July 2023
On April 5, 2023, the FBI and Dutch National Police announced the takedown of Genesis Market, one of the largest dark web marketplaces. The operation, dubbed "Operation Cookie Monster," resulted in the arrest of 119 people and the seizure of over $1M in cryptocurrency. You can read the FBI's warrant here for details specific to this case. In light of these events, I'd like to discuss how OSINT

Variants of BPFDoor Deployed in Linux Kernel

19 July 2023
Trend Micro uncovered a cyber operation by the Red Menshen APT group wherein it utilizes various versions of the BPFDoor backdoor to target Linux and cloud servers. A six-fold increase has been observed in the addition of instructions to BPF as those found in samples from 2022. Security teams across organizations should leverage provided IOCs to detect anomalies in their network.

Google Fixes ‘Bad.Build’ Vulnerability Affecting Cloud Build Service

19 July 2023
Orca Security, which reported the bug to Google, said that attackers could impersonate the accounts and manipulate the build, injecting malicious code or taking other actions.

Bad.Build Flaw in Google Cloud Build Raises Concerns of Privilege Escalation

19 July 2023
Cybersecurity researchers have uncovered a privilege escalation vulnerability in Google Cloud that could enable malicious actors tamper with application images and infect users, leading to supply chain attacks. The issue, dubbed Bad.Build, is rooted in the Google Cloud Build service, according to cloud security firm Orca, which discovered and reported the issue. "By abusing the flaw and enabling

Bureau raises $16.5 million to help users prevent fraud

19 July 2023
Bureau announced an additional $4.5 million from GMO VenturePartners, GMO Payment Gateway, and existing investors to complete its Series A funding round at $16.5 million. With this, total funding for the startup has reached $20.5 million to date.

Germany’s new cyber chief to ‘intensify and focus’ work shaping European rules

19 July 2023
Claudia Plattner, the new president of Germany’s BSI, told journalists she aimed to “intensify and focus” the agency’s work on using the levers of the European Union to improve cybersecurity in Germany and across the continent.

Called a Bogus Airline Customer Support Number? Google is Hustling to Fix That

19 July 2023
The company noted that it filed a lawsuit last month against a scammer who was posting fake reviews on Google Maps and attempting to manipulate other Google services for small businesses.

Medical Device Maker Flags Eight Flaws in Drug Infusion Products

19 July 2023
CISA said the BD product vulnerabilities have a "low attack complexity" and that successful exploitation could allow a malicious actor to compromise sensitive data, hijack a session, modify firmware, and make changes to system configurations.

Zero-Day Attacks Exploited Critical Vulnerability in Citrix ADC and Gateway

19 July 2023
Citrix today is alerting customers of a critical-severity vulnerability (CVE-2023-3519) in NetScaler ADC and NetScaler Gateway that already has exploits in the wild, and “strongly urges” to install updated versions without delay.