Latest Cybersecurity News and Articles


How Kids Pay the Price for Ransomware Attacks on Education

10 July 2023
Ransomware attacks on educational institutions have increased significantly in recent years, with the Vice Society ransomware gang especially targeting the education sector in the United States and the United Kingdom.

Killnet as a Private Military Hacking Company? For Now, It’s Probably Just a Dream

10 July 2023
The Russian hacking group Killnet aims to transform into a private military hacking company that conducts cybercrime on behalf of the Russian state. The group plans to expand its capabilities and hire skilled hackers for more destructive attacks.

Only 5% of CISOs report to CEOs, survey finds

10 July 2023
CISOs predominantly report to CIOs and are less likely to report to CEOs now than in previous years, according to a Heidrick & Struggles survey. Despite a slight year-over-year decrease, over one-third of CISOs report directly to the CIO.

BreachForums replacement emerges as robust forum for criminal hackers to trade their spoils

10 July 2023
Even before the FBI seized domains related to BreachForums, the notorious online bazaar where cybercriminals bought and sold hacked or stolen data, a replacement marketplace was taking shape.

More Than $125 Million Taken From Crypto Platform Multichain

10 July 2023
“The team is not sure what happened and is currently investigating. It is recommended that all users suspend the use of Multichain services and revoke all contract approvals related to Multichain,” the crypto platform said in a statement.

Man Charged for Breaching the Discovery Bay Water Treatment Facility

10 July 2023
Rambler Gallo (53), a man from Tracy, California, has been charged with intentionally causing damage to a computer after he allegedly breached the network of the Discovery Bay Water Treatment Facility.

TOITOIN Trojan: A New Multi-Stage Attack Targeting LATAM

10 July 2023
The TOITOIN Trojan utilizes advanced techniques such as XOR decryption, system reboots, and process injection to evade detection and gather sensitive information from infected systems.

RomCom RAT Targeting NATO and Ukraine Support Groups

10 July 2023
The threat actors behind the RomCom RAT have been suspected of phishing attacks targeting the upcoming NATO Summit in Vilnius as well as an identified organization supporting Ukraine abroad. The findings come from the BlackBerry Threat Research and Intelligence team, which found two malicious documents submitted from a Hungarian IP address on July 4, 2023. RomCom, also tracked under the names

Hackers Steal $20 Million by Exploiting Flaw in Revolut's Payment Systems

10 July 2023
Malicious actors exploited an unknown flaw in Revolut's payment systems to steal more than $20 million of the company's funds in early 2022. The development was reported by the Financial Times, citing multiple unnamed sources with knowledge of the incident. The breach has not been disclosed publicly. The fault stemmed from discrepancies between Revolut's U.S. and European systems, causing funds

New Campaigns Use Malicious npm Packages to Support Phishing Kits

08 July 2023
These packages imitated legitimate modules, such as jquery, which has millions of weekly downloads. Although the malicious packages were downloaded roughly 1000 times, they were swiftly removed from npm after detection.

Tailing Big Head Ransomware’s Variants, Tactics, and Impact

08 July 2023
The Big Head ransomware displays a fake Windows update to deceive victims, communicates with the threat actor via a Telegram bot, and drops ransom notes with contact information.

CISA warns govt agencies to patch actively exploited Android driver

08 July 2023
CISA ordered federal agencies today to patch a high-severity Arm Mali GPU kernel driver privilege escalation flaw added to its list of actively exploited vulnerabilities and addressed with this month's Android security updates.

Two Spyware Apps on Google Play with 1.5 Million Users Sending Data to China

08 July 2023
Two file management apps on the Google Play Store have been discovered to be spyware, putting the privacy and security of up to 1.5 million Android users at risk. These apps engage in deceptive behaviour and secretly send sensitive user data to malicious servers in China. Pradeo, a leading mobile security company, has uncovered this alarming infiltration. The report shows that both spyware apps,

WISE REMOTE Stealer Unleashed : Unveiling Its Multifaceted Malicious Arsenal

08 July 2023
The WISE REMOTE Stealer is an advanced information stealer and Remote Access Trojan (RAT) that is coded in the Go programming language and utilizes code manipulation techniques to evade antivirus detection, making it difficult to detect and mitigate.

Global Translation Service Exposed Highly Sensitive Records Online

08 July 2023
Website Planet‘s security researcher Jeremiah Fowler discovered a non-password-protected database that contained over 25,000 records, all publicly exposed, including ‘highly sensitive’ documents.

Vulnerabilities in PiiGAB Product Could Expose Industrial Organizations to Attacks

08 July 2023
The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday published an advisory describing the vulnerabilities discovered by researchers at Radboud University in PiiGAB M-Bus 900s gateway/converter.

Top Suspect in 2015 Ashley Madison Hack Committed Suicide in 2014

07 July 2023
When the marital infidelity website AshleyMadison.com learned in July 2015 that hackers were threatening to publish data stolen from 37 million users, the company’s then-CEO Noel Biderman was quick to point the finger at an unnamed former contractor. But as a new documentary series on Hulu reveals [SPOILER ALERT!], there was just one problem with that theory: Their top suspect had killed himself more than a year before the hackers began publishing stolen user data.

Cybersecurity is top concern for education technology leaders

07 July 2023
A recent report by the Consortium for School Networking (CoSN) analyzed the cybersecurity priorities of education technology (EdTech) leaders. 

Vishing Goes High-Tech: New 'Letscall' Malware Employs Voice Traffic Routing

07 July 2023
Researchers have issued a warning about an emerging and advanced form of voice phishing (vishing) known as "Letscall." This technique is currently targeting individuals in South Korea. The criminals behind "Letscall" employ a multi-step attack to deceive victims into downloading malicious apps from a counterfeit Google Play Store website. Once the malicious software is installed, it redirects

TMF announces five new digital services and cybersecurity investments

07 July 2023
The Labor Department will use the $15.2 million in the most recent batch of funding for zero-trust architecture. The EPA will put its $2.5 million toward the cybersecurity of its analytical radiation data system.