Latest Cybersecurity News and Articles
13 July 2023
About 39% of businesses experienced a data breach in their cloud environment last year, an increase from the 35% reported in 2022, according to Thales. Human error was reported as the leading cause of cloud data breaches by 55% of those surveyed.
13 July 2023
FortiGuard Labs recently uncovered a concerning discovery in their investigation, revealing a series of malicious Microsoft Office documents designed to take advantage of well-known vulnerabilities.
13 July 2023
The White House has released a cybersecurity plan that outlines over 60 federal initiatives including cybercrime and building a cyber workforce.
13 July 2023
During its operation from 2011 until 2013, Silk Road was used by thousands of drug dealers to distribute narcotics and other illicit goods and services to more than 100,000 buyers and to launder hundreds of millions from those unlawful transactions.
13 July 2023
A notorious Russian state-affiliated cyber gang has leveraged a legitimate sale of a BMW car to target diplomats in Kyiv, Ukraine, a new analysis by Palo Alto Network’s Unit 42 researchers has observed.
13 July 2023
While 75% of organizations have made significant strides to upgrade their infrastructure in the past year, and 78% have increased their security budgets, only 2% of industry experts are confident in their security strategies, according to OPSWAT.
13 July 2023
“There was no disruption of critical County services, such as 911 dispatch. Kent County's Information Technology team responded immediately and have received strong support from the State of Delaware and local governments,” county officials said.
13 July 2023
In a sign that cybersecurity researchers continue to be under the radar of malicious actors, a proof-of-concept (PoC) has been discovered on GitHub, concealing a backdoor with a "crafty" persistence method.
"In this instance, the PoC is a wolf in sheep's clothing, harboring malicious intent under the guise of a harmless learning tool," Uptycs researchers Nischay Hegde and Siddartha Malladi said.
13 July 2023
Wiz uncovered a fileless malware called PyLoose, specifically targeting cloud workloads. This attack involves Python code that utilizes the memfd technique to load an XMRig miner directly into memory. Around 200 instances of this technique were spotted being used for cryptomining. PyLoose was first detected on June 22, after it gained initial access through a publicly accessible Jupyter Notebook service.
13 July 2023
TikTok executives were unable to answer Liberal senator and chair of the committee James Paterson when he questioned them on how many times Australian user data had been accessed by TikTok staff in China, but the executives admitted it had happened.
13 July 2023
With at least 75% of organizations upgrading infrastructure and 78% increasing security budgets, a new report highlights disparity between infrastructure upgrades, spending and security improvements.
13 July 2023
According to the researchers, if these flaws are exploited, threat actors can easily access user databases of countless applications, putting millions of user records at risk of exposure and exploitation.
13 July 2023
The financially-motivated threat actor, known as Scarleteel, has been observed abusing Amazon Web Services (AWS) Fargate with the objective of stealing credentials and intellectual property. Additionally, it has expanded its arsenal to carry out distributed DDoS attacks and more. Organizations are advised to deploy multiple layers of defenses to stay safe.
13 July 2023
Nearly three-quarters (72%) of white hat hackers do not believe that generative AI can replace human creativity in security research and vulnerability management, according to Bugcrowd’s Inside the Mind of a Hacker – 2023 report.
13 July 2023
Microsoft and U.S. officials confirmed Wednesday that a threat actor based in China had hacked the Outlook email accounts of U.S. government agencies and at least 25 European governments for the purpose of espionage and data theft.
13 July 2023
Security leaders are concerned about attacks that leverage malware-exfiltrated authentication data, with 53% expressing extreme concern and less than 1% admitting they weren’t concerned at all, according to SpyCloud.
13 July 2023
SonicWall warned customers today to urgently patch multiple critical vulnerabilities impacting the company's Global Management System (GMS) firewall management and Analytics network reporting engine software suites.
13 July 2023
The Cyware Partner Advisory Marketplace provides a platform for security vendors to make intelligence feeds easily available to Cyware’s extensive network of direct customers, and members of ISACs, ISAOs, and other intelligence sharing communities.
13 July 2023
President Joe Biden has yet to officially nominate a new director to lead the Office of the National Cyber Director following Chris Inglis' retirement in February, leaving Acting Director Kemba Walden to fill the spot ever since.
13 July 2023
More than three-quarters of a million people may have had their social security numbers stolen in a data breach at Lansing Community College in late 2022 and early 2023, according to a law firm that says it's investigating the incident.