Latest Cybersecurity News and Articles


VA OIG Audit Uncovers Vulnerability Management Weaknesses

13 July 2023
Comparisons of vulnerability scans by the VA OIG inspectors showed that the VA Office of IT handling the Northern Arizona system did not identify all critical or high-risk vulnerabilities in the network or remediate flaws, the report said.

Legion Stealer Targeting PUBG players

13 July 2023
Gamers should be cautious of downloading cheats or hacks from untrusted sources as they may unknowingly install malware that compromises their personal information and gaming experience.

Update: Apple Re-Releases Zero-Day Patch After Fixing Browsing Issue

13 July 2023
Apple fixed and re-released emergency security updates addressing a WebKit zero-day vulnerability exploited in attacks. The initial patches had to be withdrawn on Monday due to browsing issues on certain websites.

Rockwell Automation ControlLogix Bugs Expose Industrial Systems to Remote Attacks

13 July 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has alerted of two security flaws impacting Rockwell Automation ControlLogix EtherNet/IP (ENIP) communication module models that could be exploited to achieve remote code execution and denial-of-service (DoS). "The results and impact of exploiting these vulnerabilities vary depending on the ControlLogix system configuration, but

Microsoft Thwarts Chinese Cyberattack Targeting Western European Governments

13 July 2023
The attacks, which commenced on May 15, 2023, entailed access to email accounts affecting approximately 25 entities and a small number of related individual consumer accounts.

Hackers Exploit Windows Policy to Load Malicious Kernel Drivers

13 July 2023
Kernel-mode drivers operate at the highest privilege level on Windows (Ring 0), allowing complete access to the target machine for stealthy persistence, undetectable data exfiltration, and the ability to terminate almost any process.

U.S. Government Agencies' Emails Compromised in China-Backed Cyber Attack

13 July 2023
An unnamed Federal Civilian Executive Branch (FCEB) agency in the U.S. detected anomalous email activity in mid-June 2023, leading to Microsoft's discovery of a new China-linked espionage campaign targeting two dozen organizations. The details come from a joint cybersecurity advisory released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation

New Vulnerabilities Disclosed in SonicWall and Fortinet Network Security Products

13 July 2023
SonicWall on Wednesday urged customers of Global Management System (GMS) firewall management and Analytics network reporting engine software to apply the latest fixes to secure against a set of 15 security flaws that could be exploited by a threat actor to circumvent authentication and access sensitive information. Of the 15 shortcomings (tracked from CVE-2023-34123 through CVE-2023-34137), four

British Prosecutors Say Teen Lapsus$ Member Was Behind Hacks on Uber, Rockstar

12 July 2023
A British Crown Court on Tuesday lifted a reporting restriction, allowing the naming of teenager Arion Kurtaj who is accused of hacking Uber, Revolut, and video game developer Rockstar Games in a short period of time last September.

Staying ahead of the “professionals”: The service-oriented ransomware crime industry

12 July 2023
The total amount of ransom paid since 2020 is estimated to be at least $2 billion, and this has both motivated and enabled the groups who are profiting from this activity to become more professional.

Python-Based PyLoose Fileless Attack Targets Cloud Workloads for Cryptocurrency Mining

12 July 2023
"The attack consists of Python code that loads an XMRig Miner directly into memory using memfd, a known Linux fileless technique," security researchers Avigayil Mechtinger, Oren Ofer, and Itamar Gilad said.

Small and home office router malware discovered by researchers

12 July 2023
A new malware that targets small and home office (SOHO) routers has been discovered by Lumen Technologies. The malware has been named "AVrecon".

Biden’s Cyber Command and NSA Nominee Seen as a Pick for Continuity

12 July 2023
At his first Senate confirmation hearing on Wednesday, Air Force Lt. Gen. Timothy Haugh, Cyber Command’s deputy chief, will explain how he plans to fill the shoes of Paul Nakasone.

Cl0p Crime Group Adds 62 Ernst & Young Clients to Leak Sites

12 July 2023
The growing list of MOVEit cyberattack victims has grown. Sixty-two clients of Big Four accounting firm Ernst & Young now appear on the Clop ransomware group's data leak sites.

Scam Page Volumes Surge 304% Annually

12 July 2023
In Group-IB’s new Digital Risk Trends 2023 report, security researchers have recorded a 62% year-on-year (YoY) increase in phishing websites and a 304% surge in scam pages in 2022.

54% of organizations struggle with shadow IT

12 July 2023
IT and security leaders were surveyed on malware readiness. The report found that security leaders are concerned about malware compromising data.  

Fortinet Patches Critical FortiOS Vulnerability Leading to Remote Code Execution

12 July 2023
The vulnerability impacts FortiOS and FortiProxy versions 7.2.x and 7.0.x and was resolved in FortiOS versions 7.4.0, 7.2.4, and 7.0.11, and FortiProxy versions 7.2.3 and 7.0.10.

DDoS Attacks Soar by 168% on Government Services, Report Warns

12 July 2023
According to StormWall’s Q2 2023 Report, the United States, India, and China remain the most heavily targeted countries, bearing the brunt of the escalating DDoS attacks.

AMA: CISO Edition — Diego Souza

12 July 2023
Diego Souza, Global Chief Information Security Officer (CISO) at Cummins, Inc., shares cybersecurity tactics and career advice in this AMA episode.

Report: Edge computing in healthcare is taking off

12 July 2023
In a new report, focused on the healthcare industry, found the primary use case was tele-emergency medical services.