Latest Cybersecurity News and Articles


NATO Allies’ New Cyber Pledges To Remain Classified — But Here’s What We Know

14 July 2023
During this week’s NATO summit in Vilnius, Lithuania, allies agreed to a number of new cybersecurity pledges. The substance of these commitments has not been detailed — the documents themselves are classified — but here’s what we do know.

Lokibot Exploits Word Document Vulnerabilities to Propagate

14 July 2023
FortiGuard Labs claimed to have found several Office maldocs purposed to exploit known vulnerabilities, specifically CVE-2021-40444 and CVE-2022-30190 (Follina). Researchers noted that the version of Lokibot used in the campaign includes MD5 hash. This version of Lokibot info-stealer seems to have appeared first in March.

Fake PoC for Linux Kernel Vulnerability on GitHub Exposes Researchers to Malware

14 July 2023
In a sign that cybersecurity researchers continue to be under the radar of malicious actors, a proof-of-concept (PoC) has been discovered on GitHub, concealing a backdoor with a "crafty" persistence method.

New SOHO Router Botnet AVrecon Spreads to 70,000 Devices Across 20 Countries

14 July 2023
A new malware strain has been found covertly targeting small office/home office (SOHO) routers for more than two years, infiltrating over 70,000 devices and creating a botnet with 40,000 nodes spanning 20 countries. Lumen Black Lotus Labs has dubbed the malware AVrecon, making it the third such strain to focus on SOHO routers after ZuoRAT and HiatusRAT over the past year. "This makes AVrecon one

Zimbra Warns of Critical Zero-Day Flaw in Email Software Amid Active Exploitation

14 July 2023
Zimbra has warned of a critical zero-day security flaw in its email software that has come under active exploitation in the wild. "A security vulnerability in Zimbra Collaboration Suite Version 8.8.15 that could potentially impact the confidentiality and integrity of your data has surfaced," the company said in an advisory. It also said that the issue has been addressed and that it's expected to

Scam Page Volumes Witness a 304% Annual Surge, Finds Group-IB

14 July 2023
Security researchers published its Digital Risk Trends 2023 report and noted a significant rise in phishing websites, with a 62% year-on-year growth, and a surge of 304% in scam pages. Scammers exhibited a particular interest in brands from the APAC and MEA regions. Organizations must implement robust security measures and foster a proactive cybersecurity culture among employees.

Protecting the Cloud

14 July 2023
One of the technologies that has been instrumental in facilitating smart buildings has been the emergence of “the cloud.”

HWL Ebsworth hack: sensitive Victorian government documents released by criminals

13 July 2023
HWL Ebsworth hack: sensitive Victorian government documents released by criminals State’s chief information security officer says information from Victorian departments and agencies was accessedFollow our Australia news live blog for the latest updatesGet our morning and afternoon news emails, free app or daily news podcastHighly sensitive legal documents from the Victorian government’s departments and agencies have been published on the dark web by cybercriminals.The breach is connected to data that was stolen from the law firm HWL Ebsworth in April by a Russian-linked ransomware gang and posted online.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...

SEO Expert Hired and Fired By Ashley Madison Turned on Company, Promising Revenge

13 July 2023
[This is Part II of a story published here last week on reporting that went into a new Hulu documentary series on the 2015 Ashley Madison hack.] It was around 9 p.m. on Sunday, July 19, when I received a message through the contact form on KrebsOnSecurity.com that the marital infidelity website AshleyMadison.com had been hacked. The message contained links to confidential Ashley Madison documents, and included a manifesto that said a hacker group calling itself the Impact Team was prepared to leak data on all 37 million users unless Ashley Madison and a sister property voluntarily closed down within 30 days.

Critical RCE found in popular Ghostscript open-source PDF library

13 July 2023
The flaw is tracked as CVE-2023-36664, having a CVSS v3 rating of 9.8, and impacts all versions of Ghostscript before 10.01.2, which is the latest available version released three weeks ago.

Juniper Networks Patches High-Severity Vulnerabilities in Junos OS

13 July 2023
The company published 17 advisories detailing roughly a dozen Junos OS-specific security defects, and nearly three times as many issues in third-party components used in its products.

Tampa Bay Zoo Targeted in Cyberattack by Apparent Offshoot of Royal Ransomware

13 July 2023
One of the U.S.’s most popular zoos has been hit with a cyberattack involving the theft of employee and vendor information, and a likely offshoot of the Royal ransomware gang is taking credit.

Criminals Target Businesses With Malicious Extension for Meta’s Ads Manager and Accidentally Leak Stolen Accounts

13 July 2023
The Vietnamese threat actors are using malicious Chrome extensions to steal Facebook account credentials, with over 800 victims worldwide and $180K in compromised ad budget.

Ransomware Crypto Payments Poised to Set New Record in 2023

13 July 2023
While overall crypto proceeds, including from crimes such as scams, fell dramatically over the past year, ransomware funds are expected to hit $899 million in 2023, according to Chainalysis.

APT Exploit Targeting Rockwell Automation Flaws Threatens Critical Infrastructure

13 July 2023
The 1756 EN2 and 1756 EN3 products are impacted by CVE-2023-3595, a critical flaw that can allow attackers to achieve remote code execution with persistence on targeted systems by using specially crafted Common Industrial Protocol (CIP) messages.

12% of organizations experienced a breach while using new solutions

13 July 2023
According to a survey of RSA and InfoSec attendants, 63% of the 219 respondents now use cloud-native security tools to monitor and protect data.

PicassoLoader Malware Used in Ongoing Attacks on Ukraine and Poland

13 July 2023
Government entities, military organizations, and civilian users in Ukraine and Poland have been targeted as part of a series of campaigns designed to steal sensitive data and gain persistent remote access to the infected systems. The intrusion set, which stretches from April 2022 to July 2023, leverages phishing lures and decoy documents to deploy a downloader malware called PicassoLoader, which

TeamTNT's Silentbob Botnet Infecting 196 Hosts in Cloud Attack Campaign

13 July 2023
As many as 196 hosts have been infected as part of an aggressive cloud campaign mounted by the TeamTNT group called Silentbob. "The botnet run by TeamTNT has set its sights on Docker and Kubernetes environments, Redis servers, Postgres databases, Hadoop clusters, Tomcat and Nginx servers, Weave Scope, SSH, and Jupyter applications," Aqua security researchers Ofek Itach and Assaf Morag said in a

Software supply chain compromise was fourth most frequent attack

13 July 2023
A recent security threats and trends survey measured responses of senior cybersecurity leaders, CISOs, CIOs, VPs, directors and IT managers.

Unpatched Office Zero-Day CVE-2023-36884 Actively Exploited in Targeted Attacks

13 July 2023
“An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim," reads the advisory published by Microsoft.