Latest Cybersecurity News and Articles


Only 45% of Cloud Data is Currently Encrypted

13 July 2023
About 39% of businesses experienced a data breach in their cloud environment last year, an increase from the 35% reported in 2022, according to Thales. Human error was reported as the leading cause of cloud data breaches by 55% of those surveyed.

New Attack Drops LokiBot Malware via Malicious Macros in Word Documents

13 July 2023
FortiGuard Labs recently uncovered a concerning discovery in their investigation, revealing a series of malicious Microsoft Office documents designed to take advantage of well-known vulnerabilities.

White House announces cybersecurity implementation plan

13 July 2023
The White House has released a cybersecurity plan that outlines over 60 federal initiatives including cybercrime and building a cyber workforce. 

Silk Road Drug Market’s ‘Mentor’ Sentenced to 20 Years in Prison

13 July 2023
During its operation from 2011 until 2013, Silk Road was used by thousands of drug dealers to distribute narcotics and other illicit goods and services to more than 100,000 buyers and to launder hundreds of millions from those unlawful transactions.

Diplomats in Ukraine Hit by Staggering BMW Phishing Campaign From APT29

13 July 2023
A notorious Russian state-affiliated cyber gang has leveraged a legitimate sale of a BMW car to target diplomats in Kyiv, Ukraine, a new analysis by Palo Alto Network’s Unit 42 researchers has observed.

Infrastructure upgrades alone won’t guarantee strong security

13 July 2023
While 75% of organizations have made significant strides to upgrade their infrastructure in the past year, and 78% have increased their security budgets, only 2% of industry experts are confident in their security strategies, according to OPSWAT.

Delaware’s Kent County Suffers Days-Long Municipal Services Outage

13 July 2023
“There was no disruption of critical County services, such as 911 dispatch. Kent County's Information Technology team responded immediately and have received strong support from the State of Delaware and local governments,” county officials said.

Fake PoC for Linux Kernel Vulnerability on GitHub Exposes Researchers to Malware

13 July 2023
In a sign that cybersecurity researchers continue to be under the radar of malicious actors, a proof-of-concept (PoC) has been discovered on GitHub, concealing a backdoor with a "crafty" persistence method. "In this instance, the PoC is a wolf in sheep's clothing, harboring malicious intent under the guise of a harmless learning tool," Uptycs researchers Nischay Hegde and Siddartha Malladi said.

New PyLoose Fileless Malware Targets Cloud Environment

13 July 2023
Wiz uncovered a fileless malware called PyLoose, specifically targeting cloud workloads. This attack involves Python code that utilizes the memfd technique to load an XMRig miner directly into memory. Around 200 instances of this technique were spotted being used for cryptomining. PyLoose was first detected on June 22, after it gained initial access through a publicly accessible Jupyter Notebook service.

Australian Users' Data Accessible in China, TikTok Exec Says

13 July 2023
TikTok executives were unable to answer Liberal senator and chair of the committee James Paterson when he questioned them on how many times Australian user data had been accessed by TikTok staff in China, but the executives admitted it had happened.

2% of organizations feel confident with current security strategies

13 July 2023
With at least 75% of organizations upgrading infrastructure and 78% increasing security budgets, a new report highlights disparity between infrastructure upgrades, spending and security improvements.

Exploitable Flaws in QuickBlox Framework Expose Millions of User Records

13 July 2023
According to the researchers, if these flaws are exploited, threat actors can easily access user databases of countless applications, putting millions of user records at risk of exposure and exploitation.

Scarleteel Evolves to Target AWS Fargate Environment

13 July 2023
The financially-motivated threat actor, known as Scarleteel, has been observed abusing Amazon Web Services (AWS) Fargate with the objective of stealing credentials and intellectual property. Additionally, it has expanded its arsenal to carry out distributed DDoS attacks and more. Organizations are advised to deploy multiple layers of defenses to stay safe. 

Ethical Hackers Reveal How They Use Generative AI

13 July 2023
Nearly three-quarters (72%) of white hat hackers do not believe that generative AI can replace human creativity in security research and vulnerability management, according to Bugcrowd’s Inside the Mind of a Hacker – 2023 report.

Chinese Hackers Hijacked Emails From US, European Government Agencies

13 July 2023
Microsoft and U.S. officials confirmed Wednesday that a threat actor based in China had hacked the Outlook email accounts of U.S. government agencies and at least 25 European governments for the purpose of espionage and data theft.

20% of malware attacks bypass antivirus protection

13 July 2023
Security leaders are concerned about attacks that leverage malware-exfiltrated authentication data, with 53% expressing extreme concern and less than 1% admitting they weren’t concerned at all, according to SpyCloud.

Sonicwall Warns Admins to Patch Critical Authentication Bypass Bugs Immediately

13 July 2023
SonicWall warned customers today to urgently patch multiple critical vulnerabilities impacting the company's Global Management System (GMS) firewall management and Analytics network reporting engine software suites.

Cyware Expands Partnership with ZeroFox Through Inclusion in the Partner Advisory Marketplace

13 July 2023
The Cyware Partner Advisory Marketplace provides a platform for security vendors to make intelligence feeds easily available to Cyware’s extensive network of direct customers, and members of ISACs, ISAOs, and other intelligence sharing communities.

Trade Groups Press White House for National Cyber Director Nomination

13 July 2023
President Joe Biden has yet to officially nominate a new director to lead the Office of the National Cyber Director following Chris Inglis' retirement in February, leaving Acting Director Kemba Walden to fill the spot ever since.

SSNs, Other Data May Have Been Stolen in Lansing Community College Data Breach

13 July 2023
More than three-quarters of a million people may have had their social security numbers stolen in a data breach at Lansing Community College in late 2022 and early 2023, according to a law firm that says it's investigating the incident.