Latest Cybersecurity News and Articles


Mastodon Social Network Patches Critical Flaws Allowing Server Takeover

07 July 2023
The most critical vulnerability, CVE-2023-36460, allows hackers to exploit a flaw in the media attachments feature, creating and overwriting files in any location the software could access on an instance.

MOVEit Transfer customers warned to patch new critical flaw

07 July 2023
“An attacker could submit a crafted payload to a MOVEit Transfer application endpoint which could result in modification and disclosure of MOVEit database content,” an advisory by MOVEit said.

Lee Buttke hired as Managing Director and CISO at AgileBlue

07 July 2023
Lee Buttke has been hired as Managing Director and Chief Information Security Officer (CISO) at AgileBlue. Buttke brings threat mitigation experience.

BlackByte 2.0 Ransomware: Infiltrate, Encrypt, and Extort in Just 5 Days

07 July 2023
Recently, Microsoft's Incident Response team investigated several BlackByte 2.0 ransomware attacks and exposed these cyber strikes' terrifying velocity and damaging nature.

Iranian Hackers' Sophisticated Malware Targets Windows and macOS Users

07 July 2023
"TA453 eventually used a variety of cloud hosting providers to deliver a novel infection chain that deploys the newly identified PowerShell backdoor GorjolEcho," Proofpoint said in a new report.

Another Critical Unauthenticated SQLi Flaw Discovered in MOVEit Transfer Software

07 July 2023
Progress Software has announced the discovery and patching of a critical SQL injection vulnerability in MOVEit Transfer, popular software used for secure file transfer. In addition, Progress Software has patched two other high-severity vulnerabilities. The identified SQL injection vulnerability, tagged as CVE-2023-36934, could potentially allow unauthenticated attackers to gain unauthorized

Cybercriminals can Break Voice Authentication with 99% Success Rate

07 July 2023
Computer scientists at the University of Waterloo have discovered a method of attack that can successfully bypass voice authentication security systems with up to a 99% success rate after only six tries.

Truebot's Activity Spikes, U.S and Canada Authorities Issue Warning

07 July 2023
A joint advisory from the CISA, the FBI, the MS-ISAC, and the Canadian Centre for Cyber Security (CCCS) discovered a rise in the use of the Truebot malware by threat actors. Notably, these actors are increasingly exploiting the CVE-2022-31199 flaw to target organizations in the U.S. and Canada with the malware. Organizations are also advised to use IOCs to hunt for signs of malicious activity pointing to a Truebot infection.  

ChatGPT’s unknown potential keeps us guessing

07 July 2023
A survey by Malwarebytes revealed that a majority of respondents do not trust the information produced by ChatGPT and believe it poses potential safety and security risks.

Two Apps with 1.5M Installations on Google Play Found Sending User Data to China

07 July 2023
The apps, both from the same publisher, can launch without any user interaction to steal sensitive data and send it to servers in China. Despite being reported to Google, the two apps continue to be available in Google Play at the time of publishing.

Mastodon Social Network Patches Critical Flaws Allowing Server Takeover

07 July 2023
Mastodon, a popular decentralized social network, has released a security update to fix critical vulnerabilities that could expose millions of users to potential attacks. Mastodon is known for its federated model, consisting of thousands of separate servers called "instances," and it has over 14 million users across more than 20,000 instances. The most critical vulnerability, CVE-2023-36460,

CISA, FBI, MS-ISAC, and CCCS Warn of Truebot Infecting US and Canadian Organizations

07 July 2023
The threat actors behind the attacks compromised target networks by exploiting a critical remote code execution (RCE) vulnerability in the Netwrix Auditor software tracked as CVE-2022-31199.

13% of businesses continuously monitor third-party vendor security risks

07 July 2023
A new report shows that 13% of organizations continuously monitor the security risks of their third parties.

85% of organizations are adopting multicloud strategies

07 July 2023
A report reveals a large multicloud skills gap, underscoring how critical cloud skills development is for organizations.

How to cultivate a culture of continuous cybersecurity improvement

07 July 2023
Building a culture of continuous cyber improvement involves implementing a robust real-time vulnerability management strategy that includes consistent monitoring, threat intelligence integration, risk assessment, and rapid response.

New Silentbob Campaign Deploys Tsunami Backdoor and Hijacks Cloud Resources

07 July 2023
Cybersecurity researchers at Aqua unearthed an attack infrastructure that's being used as part of a "potentially massive campaign" against cloud-native environments to deploy Tsunami malware, and hijack credentials and resources.

Chinese Affiliated Spyware Uncovered on Google Play Store

07 July 2023
Security analysts at Mobile security solutions provider Pradeo uncovered details of a couple of spyware apps on the Google Play Store - File Recovery and Data Recovery and File Manager. With a collective download of over 1.5 million, these apps can automatically start without any input from the device owners and covertly send sensitive user data to multiple malicious servers in China.

Ransomware accounts for 54% of cyber threats in the health sector

07 July 2023
A report by ENISA found that ransomware accounts for 54% of cybersecurity threats in the health sector. Most of the surveyed organizations (73%) in the health sector haven’t got a program to mitigate ransomware attacks.

Update: Shell Confirms MOVEit-Related Breach After Ransomware Group Leaks Data

07 July 2023
“Some personal information relating to employees of the BG Group has been accessed without authorization,” the company said. It’s unclear exactly what type of information has been compromised, but impacted individuals are being notified.

Close Security Gaps with Continuous Threat Exposure Management

07 July 2023
CISOs, security leaders, and SOC teams often struggle with limited visibility into all connections made to their company-owned assets and networks. They are hindered by a lack of open-source intelligence and powerful technology required for proactive, continuous, and effective discovery and protection of their systems, data, and assets. As advanced threat actors constantly search for easily