Latest Cybersecurity News and Articles


SCARLETEEL Campaign Exploiting AWS Fargate in Ongoing Cryptojacking Attacks

11 July 2023
Cloud environments continue to be at the receiving end of an ongoing advanced attack campaign dubbed SCARLETEEL, with the threat actors now setting their sights on Amazon Web Services (AWS) Fargate.

Cybercriminals Evolve Antidetect Tooling for Mobile OS-Based Fraud

11 July 2023
The tools cost between $700-$1000 and are currently designed for Android-based devices. The authors behind both tools recommend using OnePlus devices to deploy mobile anti-detect or may ship ready-to-use devices with pre-configured packages.

Staff and Patients at the UK's Barts Health NHS Trust Hit With Extortion Threat

11 July 2023
Staff at one of the UK's largest hospital groups have spent a nervous week wondering if private data, stolen from their employer's IT systems by a ransomware gang, is going to be splurged online after a deadline to prevent publication passed.

Trinidad and Tobago Facing Servie Outages After Cyberattack

11 July 2023
The island nation of over 1.4 million people announced on Friday that its Ministry of Digital Transformation discovered a cyberattack targeting the country’s Office of the Attorney General and Ministry of Legal Affairs (AGLA) in recent days.

Law firms under cyberattack

11 July 2023
In April 2023, Australian law firm HWL Ebsworth was hit by a cyberattack that possibly resulted in data of hundreds of its clients and dozens of government agencies being compromised. The attack was claimed by the Russian-linked Blackcat ransomware.

Gaming Firm Razer Probing Potential Hack After Data Offered for US$100,000 Worth of Crypto

11 July 2023
According to a Twitter post by threat intelligence platform FalconFeeds.io, a seller had advertised the sale of source codes, encryption keys, database and backend access logins for Razer and its products in a hackers’ forum on Saturday.

New disturbing ransomware trend threatens organizations

11 July 2023
Ransomware attacks increased by over 37% in 2023 compared to the previous year, with the average enterprise ransom payment exceeding $100,000, with a $5.3 million average demand, according to Zscaler.

Hackers Steal Over $20 Million by Exploiting Flaw in Revolut's Payment Systems

11 July 2023
The problem was first detected in late 2021. But before it could be closed, the report said organized criminal groups leveraged the loophole by "encouraging individuals to try to make expensive purchases that would go on to be declined."

How to Apply MITRE ATT&CK to Your Organization

11 July 2023
Discover all the ways MITRE ATT&CK can help you defend your organization. Build your security strategy and policies by making the most of this important framework. What is the MITRE ATT&CK Framework? MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a widely adopted framework and knowledge base that outlines and categorizes the tactics, techniques, and procedures (TTPs)

Triada Malware Infects Android Devices via Fake Telegram App

11 July 2023
Check Point Software Technologies’ recent research highlights a concerning trend: a circulating fake Telegram messenger app that infects Android devices with Triada malware upon installation.

New Big Head Ransomware Propagates via Malvertising

11 July 2023
A newly discovered ransomware strain dubbed Big Head is spreading through malvertising, which involves the promotion of fake Windows updates and Microsoft Word installers, warned Trend Micro. Designed as a .NET binary, the ransomware deploys three AES-encrypted files on the targeted system: one for spreading the malware, another for facilitating communication with a Telegram bot, and the third for encrypting files.

Archive of Our Own Website Suffering Massive DDoS Attacks

11 July 2023
The popular fanfiction platform Archive of Our Own (AO3) is currently grappling with a wave of DDoS attacks. Since early Monday morning, the AO3 website has been experiencing intermittent periods of outage, leaving users frustrated.

SCARLETEEL Cryptojacking Campaign Exploiting AWS Fargate in Ongoing Campaign

11 July 2023
Cloud environments continue to be at the receiving end of an ongoing advanced attack campaign dubbed SCARLETEEL, with the threat actors now setting their sights on Amazon Web Services (AWS) Fargate. "Cloud environments are still their primary target, but the tools and techniques used have adapted to bypass new security measures, along with a more resilient and stealthy command and control

TPG to Buy Forcepoint’s Public Sector Cybersecurity Business for $2.45 Billion

11 July 2023
The sale, which is under a definitive agreement, is expected to close before the end of 2023. Forcepoint is separating out its Global Governments and Critical Infrastructure business, known as G2CI, in the sale to TPG, creating an independent entity.

Number of email-based phishing attacks surges 464%

11 July 2023
The evolving cyberattack landscape reveals the increasing utilization of generative AI systems, like ChatGPT, by cybercriminals for crafting malicious content and executing sophisticated attacks, according to Acronis.

Apple Issues Urgent Patch for Zero-Day Flaw Targeting iOS, iPadOS, macOS, and Safari

11 July 2023
The WebKit bug, cataloged as CVE-2023-37450, could allow threat actors to achieve arbitrary code execution when processing specially crafted web content. The iPhone maker said it addressed the issue with improved checks.

Beware of Big Head Ransomware: Spreading Through Fake Windows Updates

11 July 2023
A developing piece of ransomware called Big Head is being distributed as part of a malvertising campaign that takes the form of bogus Microsoft Windows updates and Word installers. Big Head was first documented by Fortinet FortiGuard Labs last month, when it discovered multiple variants of the ransomware that are designed to encrypt files on victims' machines in exchange for a cryptocurrency

EU Adopts More Robust Data Privacy Agreement With US

11 July 2023
Three years after a European court invalidated a transatlantic data transfer agreement, the EU now adopted a new agreement with the U.S. meant to better ensure privacy protections for data moving between American tech companies and users overseas.

VMware Warns of Exploit Available for Critical vRealize RCE Bug

11 July 2023
VMware warned customers today that exploit code is now available for a critical vulnerability in the VMware Aria Operations for Logs analysis tool, which helps admins manage terabytes worth of app and infrastructure logs in large-scale environments.

‘LetsCall’ Multi-Stage Vishing Attack Found Targeting Korean Android Users

11 July 2023
A cautionary alert has been issued by researchers regarding an advanced voice phishing (vishing) campaign referred to as "Letscall," presently targeting Android users in South Korea. The attackers pose as banking employees and use social engineering tactics to extract sensitive information from unsuspecting users.