Latest Cybersecurity News and Articles


Pakistani Entities Targeted in Sophisticated Attack Deploying ShadowPad Malware

18 July 2023
An unidentified threat actor compromised an application used by multiple entities in Pakistan to deliver ShadowPad, a successor to the PlugX backdoor that's commonly associated with Chinese hacking crews. Targets included a Pakistan government entity, a public sector bank, and a telecommunications provider, according to Trend Micro. The infections took place between mid-February 2022 and

BlotchyQuasar RAT Targets Users in LATAM Region

18 July 2023
A series of phishing emails is directing recipients to packed executable files containing the BlotchyQuasar malware variant, allegedly developed by a threat group known as Hive0129. Several features of it were found to overlap with a malware called ProyectoRAT. IOCs associated with the attack campaign will help organizations in eliminating or blocking the threat.

Netcraft Raises $100M, Hires New CEO for Global Expansion

18 July 2023
The British company known for its anti-phishing and cybercrime disruption tools said the $100 million financing was led by Spectrum Equity, a growth equity firm focused on internet-enabled software and data services companies.

FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware

18 July 2023
The Syssphinx cybercrime group, known for financially motivated attacks, has diversified its tactics by deploying ransomware in addition to its traditional point-of-sale attacks.

President Xi Wants to Make the Great Firewall of China Even Greater

18 July 2023
Chinese President Xi Jinping has directed officials to build a Beijing-controlled "security barrier" around the country's internet, emphasizing the Party's leadership and the need to govern cyberspace according to the law.

VirusTotal Data Leak Exposes Some Registered Customers' Details

18 July 2023
Data associated with a subset of registered customers of VirusTotal, including their names and email addresses, have leaked on the internet. The security incident, which comprises a database of 5,600 names in a 313KB file, was first disclosed by Der Spiegel and Der Standard yesterday. Launched in 2004, VirusTotal is a popular service that analyzes suspicious files and URLs to detect types of

Go Beyond the Headlines for Deeper Dives into the Cybercriminal Underground

18 July 2023
Discover stories about threat actors’ latest tactics, techniques, and procedures from Cybersixgill’s threat experts each month. Each story brings you details on emerging underground threats, the threat actors involved, and how you can take action to mitigate risks. Learn about the top vulnerabilities and review the latest ransomware and malware trends from the deep and dark web. Stolen ChatGPT

Data Compromises on Track to Set a New Record

18 July 2023
The number of data compromises reported in the U.S. in the H1 of 2023 is higher than the total compromises reported every year between 2005 and 2020, except for 2017, according to Identity Theft Resource Center.

Meet NoEscape: Avaddon Ransomware Gang’s Likely Successor

18 July 2023
NoEscape launched in June 2023 when it began targeting the enterprise in double-extortion attacks. As part of these attacks, the threat actors steal data and encrypt files on Windows, Linux, and VMware ESXi servers.

FIN8 Group Using Modified Sardonic Backdoor for BlackCat Ransomware Attacks

18 July 2023
The financially motivated threat actor known as FIN8 has been observed using a "revamped" version of a backdoor called Sardonic to deliver the BlackCat ransomware. According to the Symantec Threat Hunter Team, part of Broadcom, the development is an attempt on the part of the e-crime group to diversify its focus and maximize profits from infected entities. The intrusion attempt took place in

CISA Provides Factsheet with Free Tools for Cloud Environments

18 July 2023
CISA has published a factsheet called "Free Tools for Cloud Environments" to assist businesses in identifying and utilizing open-source tools and techniques for protecting critical assets and data security in cloud environments.

BreachForums administrator facing 30-year sentence after pleading guilty to three charges

18 July 2023
Conor Brian Fitzpatrick was arrested at his home in Peekskill, New York in March by the FBI for his role in running BreachForums – one of the most visited cybercrime forums available to those looking to sell or purchase stolen data.

Cybercriminals Exploiting WooCommerce Payments Plugin Flaw to Hijack Websites

18 July 2023
"Large-scale attacks against the vulnerability, assigned CVE-2023-28121, began on Thursday, July 14, 2023, and continued over the weekend, peaking at 1.3 million attacks against 157,000 sites on Saturday, July 16, 2023," Wordfence researchers said.

Owner of BreachForums Pleads Guilty to Cybercrime and Child Pornography Charges

18 July 2023
Conor Brian Fitzpatrick, the owner of the now-defunct BreachForums website, has pleaded guilty to charges related to his operation of the cybercrime forum as well as having child pornography images. The development, first reported by DataBreaches.net last week, comes nearly four months after Fitzpatrick (aka pompompurin) was formally charged in the U.S. with conspiracy to commit access device

TeamTNT Steals to Azure and Google Cloud Credentials

18 July 2023
Researchers have uncovered a new cloud credential stealing campaign that specifically targets Azure and Google Cloud Platform (GCP) services. They discovered up to eight new versions of the credential harvesting script, indicating an actively evolving campaign. Notably, this campaign exhibits resemblances to the tactics used by the TeamTNT cryptojacking group.

Cybercriminals Exploiting WooCommerce Payments Plugin Flaw to Hijack Websites

18 July 2023
Threat actors are actively exploiting a recently disclosed critical security flaw in the WooCommerce Payments WordPress plugin as part of a massive targeted campaign. The flaw, tracked as CVE-2023-28121 (CVSS score: 9.8), is a case of authentication bypass that enables unauthenticated attackers to impersonate arbitrary users and perform some actions as the impersonated user, including an

JumpCloud Blames 'Sophisticated Nation-State' Actor for Security Breach

17 July 2023
A little over a week after JumpCloud reset API keys of customers impacted by a security incident, the company said the intrusion was the work of a sophisticated nation-state actor. The adversary "gained unauthorized access to our systems to target a small and specific set of our customers," Bob Phan, chief information security officer (CISO) at JumpCloud, said in a post-mortem report. "The

Digital maturity is a growing factor in cybersecurity practices

17 July 2023
A report finds that the U.S. security landscape changed significantly in 2022, with breaches declining in number but increasing in size.

Hackers Exploit WebAPK to Deceive Android Users into Installing Malicious Apps

17 July 2023
Threat actors are taking advantage of Android's WebAPK technology to trick unsuspecting users into installing malicious web apps on Android phones that are designed to capture sensitive personal information.

Update: JumpCloud Discloses Breach by State-Backed APT Hacking Group

17 July 2023
US-based enterprise software firm JumpCloud says a state-backed hacking group breached its systems almost one month ago as part of a highly targeted attack focused on a limited set of customers.