Latest Cybersecurity News and Articles


Apple Issues Urgent Patch for Zero-Day Flaw Targeting iOS, iPadOS, macOS, and Safari

11 July 2023
Apple has released Rapid Security Response updates for iOS, iPadOS, macOS, and Safari web browser to address a zero-day flaw that it said has been actively exploited in the wild. The WebKit bug, cataloged as CVE-2023-37450, could allow threat actors to achieve arbitrary code execution when processing specially crafted web content. The iPhone maker said it addressed the issue with improved checks

Cyber Extortion Cases Surge 39% Annually

10 July 2023
Incidents of online extortion reported to the police increased by nearly two-fifths in 2022 compared to a year previously, according to law firm RPC. The findings, which cover the full year to December 2022, were sourced from the UK's Action Fraud.

RomCom RAT Targeting NATO and Ukraine Support Groups

10 July 2023
The threat actors behind the RomCom RAT have been suspected of phishing attacks targeting the upcoming NATO Summit in Vilnius as well as an identified organization supporting Ukraine abroad.

Central Bankers Develop Framework For Securing Digital Currencies

10 July 2023
An international financial institution owned by the world’s central banks has published a new framework designed to help members mitigate cyber risks associated with their digital currencies.

Genesis Market gang tries to sell platform after FBI disruption

10 July 2023
Unlike its competitors, Genesis Market did not just sell stolen data and credentials but also provided a platform to criminals that allowed them to weaponize that data using a custom browser extension to impersonate victims.

Cybersecurity researchers identify new ShadowVault malware

10 July 2023
A new malware has been identified by Guardz. The malware known as 'ShadowVault' is capable of stealing sensitive data from macOS-based devices.

PoC Exploit Published for Recent Ubiquiti EdgeRouter Vulnerability

10 July 2023
A recently patched vulnerability in Ubiquiti EdgeRouter and AirCube devices could be exploited to execute arbitrary code, vulnerability reporting firm SSD Secure Disclosure warns.

Honeywell Boosting OT Cybersecurity Offering With Acquisition of SCADAfence

10 July 2023
Honeywell has agreed to acquire SCADAfence for an undisclosed amount and plans on integrating its solutions into the company’s Forge Cybersecurity+ suite. The deal is expected to close in the second half of the year.

35 Million Indonesians' Passport Data for Sale on Dark Web for $10K

10 July 2023
Indonesian security researcher Teguh Aprianto revealed on Twitter last week that a hacker had put up for sale Indonesian passport holders' details including their full names, birth dates, gender, passport numbers, and passport validity dates.

Midyear Health Data Breach Analysis: The Top Culprits

10 July 2023
The HHS HIPAA Breach Reporting Tool shows that 336 major health data breaches affected nearly 41.4 million individuals between January 1st and June 30th this year - nearly double the number affected during the same period last year.

ISACA joins ECSO to strengthen cybersecurity and digital skills in Europe

10 July 2023
ISACA is joining the European Cyber Security Organisation (ECSO). The membership will work to accelerate ECSO and ISACA’s shared commitment to advancing cybersecurity, fostering collaboration and driving digital trust across Europe.

New Phishing Attack Spoofs Microsoft 365 Authentication System

10 July 2023
According to researchers at Vade, the attack email includes a harmful HTML attachment with JavaScript code. This code is designed to gather the recipient’s email address and modify the page using data from a callback function’s variable.

More Than 42,000 Affected by Ransomware Attack on Pro Bono California Law Firm

10 July 2023
The Law Foundation of Silicon Valley notified regulators in California and Maine last week that the February ransomware attack on their offices resulted in the leak of Social Security numbers and other personal information.

New Mozilla Feature Blocks Risky Add-Ons on Specific Websites to Safeguard User Security

10 July 2023
Mozilla has announced that some add-ons may be blocked from running on certain sites as part of a new feature called Quarantined Domains. "We have introduced a new back-end feature to only allow some extensions monitored by Mozilla to run on specific websites for various reasons, including security concerns," the company said in its Release Notes for Firefox 115.0 released last week. The company

Germany Must be Able to Defend Itself, Warns New Cybersecurity Chief

10 July 2023
Germany’s new cybersecurity chief, Claudia Plattner, told journalists on Friday that the country needed to defend itself amidst a surge in attacks on hospitals, local government authorities and private sector businesses in the country.

New TOITOIN Banking Trojan Targeting Latin American Businesses

10 July 2023
Businesses operating in the Latin American (LATAM) region are the target of a new Windows-based banking trojan called TOITOIN since May 2023. "This sophisticated campaign employs a trojan that follows a multi-staged infection chain, utilizing specially crafted modules throughout each stage," Zscaler researchers Niraj Shivtarkar and Preet Kamal said in a report published last week. "These modules

New 'Letscall' Malware Employs Voice Traffic Routing to Target Victims in South Korea

10 July 2023
The "Letscall" group consists of Android developers, designers, frontend and backend developers, as well as call operators specializing in voice social engineering attacks.

Real Estate Firm Faces Three Lawsuits in Addiction Center Breach

10 July 2023
All the lawsuits were filed in the U.S. District Court for the Eastern District of Pennsylvania. They seek relief including monetary damages and an injunctive order compelling Onix to improve its security practices to prevent future incidents.

Global Retailers Must Keep an Eye on Their SaaS Stack

10 July 2023
Brick-and-mortar retailers and e-commerce sellers may be locked in a fierce battle for market share, but one area both can agree on is the need to secure their SaaS stack. From communications tools to order management and fulfillment systems, much of today's critical retail software lives in SaaS apps in the cloud. Securing those applications is crucial to ongoing operations, chain management,

Bangladesh Government Website Leaks Millions of Citizens' Personal Data

10 July 2023
Viktor Markopoulos, a researcher at Bitcrack Cyber Security, said he accidentally discovered the leak on June 27, and shortly after contacted the Bangladeshi e-Government CERT. He said the leak includes data of millions of Bangladeshi citizens.