Latest Cybersecurity News and Articles


Defunct Avaddon Rebranded as NoEscape Ransomware

19 July 2023
A strong argument for a connection has been established between the NoEscape ransomware and the obsolete Avaddon group. The encryption algorithms used by NoEscape and Avaddon ransomware are nearly identical, except that NoEscape switched to using the Salsa20 algorithm. Furthermore, sources have confirmed that multiple key members of Avaddon have joined the new ransomware operation.

WormGPT: Emerging AI Tool Raises Concerns over Advanced Cyber Threats

19 July 2023
A new malicious tool dubbed WormGPT is doing rounds in underground forums as a new generative AI cybercrime tool. Attackers could be preparing to execute sophisticated phishing attacks by crafting highly convincing fake emails, said security experts.

U.S. Government Blacklists Cytrox and Intellexa Spyware Vendors for Cyber Espionage

19 July 2023
The U.S. government on Tuesday added two foreign commercial spyware vendors, Cytrox and Intellexa, to an economic blocklist for weaponizing cyber exploits to gain unauthorized access to devices and "threatening the privacy and security of individuals and organizations worldwide." This includes the companies' corporate holdings in Hungary (Cytrox Holdings Crt), North Macedonia (Cytrox AD), Greece

Zero-Day Attacks Exploited Critical Vulnerability in Citrix ADC and Gateway

18 July 2023
Citrix is alerting users of a critical security flaw in NetScaler Application Delivery Controller (ADC) and Gateway that it said is being actively exploited in the wild. Tracked as CVE-2023-3519 (CVSS score: 9.8), the issue relates to a case of code injection that could result in unauthenticated remote code execution. It impacts the following versions - NetScaler ADC and NetScaler Gateway 13.1

Gamaredon APT Steals Data Within an Hour

18 July 2023
Once again, the Gamaredon APT is carrying out a new wave of phishing attacks targeting Ukrainian government agencies, stealing data within an hour of the attack. The campaign is aimed at entities in Ukraine, including security services, military, and government organizations. It is advised that organizations must adopt real-time threat alerting and threat insight-sharing solutions to stay updated real-time about new tactics and techniques adopted by threat actors.

UK: IT Worker Jailed for Impersonating Ransomware Gang to Extort Employer

18 July 2023
To deceive the company, he impersonated the ransomware gang extorting them. He tried to redirect the ransomware payments by switching the cybercriminals' cryptocurrency wallet to one under his control.

Update: UKG Agrees to Pay Up to $6M in Lawsuit Tied to 2021 Breach

18 July 2023
The ransomware attack, which impacted multiple UKG customers such as Tesla, PepsiCo, Whole Foods, and New York City’s Metropolitan Transportation Authority, hindered some customers’ ability to process payroll.

Black Hat Hacker Exposes Real Identity After Infecting Own Computer With Malware

18 July 2023
Using the online moniker ‘La_Citrix’, the threat actor has been active on Russian-speaking cybercrime forums since 2020, offering access to hacked companies and info-stealer logs from active infections.

White House Unveils Consumer Labeling Program to Strengthen IoT Security

18 July 2023
The Biden administration has considered an Energy Star type of consumer labeling program a key part of an effort to strengthen the nation’s cyber infrastructure following the SolarWinds and Colonial Pipeline attacks.

drIBAN Fraud Operations Target Corporate Banking Customers

18 July 2023
Operating as part of a Man-in-the-Browser (MITB) attack, the web injects allow cybercriminals to manipulate the content of legitimate web pages in real time, bypassing the TLS protocol.

70% of life sciences see a rise in insider data loss incidents

18 July 2023
Cybersecurity, risk management and insider risks within the life sciences industry were analyzed in a recent report by Code42 Software. 

Phoenician Medical Center Cyberattack Affects Up to 162,500 Patients

18 July 2023
The forensic investigation confirmed that there had been unauthorized access to files containing the protected health information of patients, some of which may have been obtained by the hackers.

LeakedSource Owner Quit Ashley Madison a Month Before 2015 Hack

18 July 2023
[This is Part III in a series on research conducted for a recent Hulu documentary on the 2015 hack of marital infidelity website AshleyMadison.com.] In 2019, a Canadian company called Defiant Tech Inc. pleaded guilty to running LeakedSource[.]com, a service that sold access to billions of passwords and other data exposed in countless data breaches. KrebsOnSecurity has learned that the owner of Defiant Tech, a 32-year-old Ontario man named Jordan Evan Bloom, was hired in late 2014 as a developer for the marital infidelity site AshleyMadison.com. Bloom resigned from AshleyMadison citing health reasons in June 2015 -- less than one month before unidentified hackers stole data on 37 million users -- and launched LeakedSource three months later.

'Millions of emails' for US military sent to .ml addresses

18 July 2023
For the past decade, millions of emails destined for .mil US military addresses were actually directed at .ml addresses, that being the top-level domain for the African nation of Mali, it's claimed.

Financial services industry sees rise in public cloud storage

18 July 2023
A report highlights how financial services organizations have embraced the cloud in response to the pandemic-fueled movement toward remote work.

Growing Scam Activity Linked to Social Media and Automation

18 July 2023
The average number of scam resources per brand across all regions and industries more than doubled year-on-year in 2022, up 162%, according to Group-IB. Additionally, the total number of scam pages detected in 2022 was more than thrice in 2021.

Dating App That Claims 50 Million Users Suffered a Data Breach

18 July 2023
Cybersecurity researcher Jeremiah Fowler discovered a non-password-protected database containing approximately 2.3 million records associated with multiple dating applications.

GoTo names Attila Török as new Chief Information Security Officer

18 July 2023
GoTo recently announced the appointment of Attila Török as Chief Information Security Officer (CISO).

Suspected Scareware Fraudster Arrested After Decade on the Run

18 July 2023
The fraudster was apprehended at Barcelona airport after managing to evade capture for over a decade, according to Spanish police. They were apparently supported by the FBI and Interpol, which had issued a red notice for the individual’s capture.

VirusTotal Data Leak Exposes Some Registered Customers' Details

18 July 2023
Data associated with a subset of registered customers of VirusTotal, including their names and email addresses, were exposed after an employee inadvertently uploaded the information to the malware scanning platform.