Latest Cybersecurity News and Articles


New Python Tool Checks NPM Packages for Manifest Confusion Issues

04 July 2023
A malicious actor could manipulate the manifest data of a new package, and potentially expose developers to risks such as cache poisoning, installation of unknown dependencies, execution of unknown scripts, and possibly even downgrade attacks.

DDoSia Attack Tool Evolves with Encryption, Targeting Multiple Sectors

04 July 2023
DDoSia is attributed to a pro-Russian hacker group called NoName(057)16. Launched in 2022 and a successor of the Bobik botnet, the attack tool is designed for staging distributed denial-of-service (DDoS) attacks against targets.

Microsoft Denies Major 30 Million Customer-Breach

04 July 2023
“At this time, our analysis of the data shows that this is not a legitimate claim and an aggregation of data. We have seen no evidence that our customer data has been accessed or compromised,” Microsoft noted.

Thirty-three US Hospitals Hit By Ransomware This Year

04 July 2023
According to Emsisoft data, at least 19 healthcare providers hit by ransomware attacks operate 33 hospitals and at least 16 of the 19 had data exfiltrated. Data exfiltration last year occurred in 68% of cases.

Major Data Leaks on TikTok, Instagram, and Yahoo

04 July 2023
A SOCRadar dark web analyst recently discovered an alleged database leak for Instagram. The leaked data reportedly contains over 17 million records in JSON format. The nature of the data suggests that it may have been collected from open source.

DDoSia Attack Tool Evolves with Encryption, Targeting Multiple Sectors

04 July 2023
The threat actors behind the DDoSia attack tool have come up with a new version that incorporates a new mechanism to retrieve the list of targets to be bombarded with junk HTTP requests in an attempt to bring them down. The updated variant, written in Golang, "implements an additional security mechanism to conceal the list of targets, which is transmitted from the [command-and-control] to the

Anonymous Sudan Claims to Have Stolen 30 Million Microsoft’s Customer Accounts

04 July 2023
Attackers said “We announce that we have successfully hacked Microsoft and have access to a large database containing more than 30 million Microsoft accounts, email and password. Price for full database : 50,000 USD.”

Mexico-Based Hacker Targets Global Banks with Android Malware

04 July 2023
An e-crime actor of Mexican provenance has been linked to an Android mobile malware campaign targeting financial institutions globally, but with a specific focus on Spanish and Chilean banks, from June 2021 to April 2023. The activity is being attributed to an actor codenamed Neo_Net, according to security researcher Pol Thill. The findings were published by SentinelOne following a Malware

Report: Fileless Attacks Increase by 1,400%

04 July 2023
Protecting runtime environments requires at least a monitoring approach that includes scanning for known malicious files and network communications, then blocking them and alerting when they appear. However, this is still insufficient.

Malvertising Leads to BlackCat Ransomware Infection

04 July 2023
Trend Micro researchers have identified a malvertising campaign that distributes BlackCat ransomware. Adversaries create cloned webpages, including that of the open-source file transfer app WinSCP, resembling legitimate organizations. Additionally, the criminals used SpyBoy, a tool that tampers with the protective measures implemented by security agents.

Alert: 330,000 FortiGate Firewalls Still Unpatched to CVE-2023-27997 RCE Flaw

04 July 2023
No less than 330000 FortiGate firewalls are still unpatched and vulnerable to CVE-2023-27997, a critical security flaw affecting Fortinet devices that have come under active exploitation in the wild. Cybersecurity firm Bishop Fox, in a report published last week, said that out of nearly 490,000 Fortinet SSL-VPN interfaces exposed on the internet, about 69 percent remain unpatched. CVE-2023-27997

Hackers Use Proxyjacking to Profit from Compromised SSH Servers' Bandwidth

04 July 2023
A new Proxyjacking campaign has come to light that targets SSH servers and proceeds to establish Docker services, utilizing the victim's bandwidth to generate revenue. Further investigation revealed the presence of cryptocurrency miners, exploits, and hacking tools on the compromised server. Organizations are advised to implement standard security measures.

GCHQ reveals British government was hacked by foreign cyber spies 20 years ago

03 July 2023
This month marks the 20th anniversary of the first time cyber experts at GCHQ responded to a foreign state hacking the British government, the intelligence and security agency revealed on Friday.

Hacks targeting British exam boards raise fears of students cheating

03 July 2023
Police in Britain are investigating multiple incidents in which national exam papers for school-leavers were stolen by hackers and sold online to students seeking to cheat on their tests.

Ireland: Dublin Airport staff pay data hit by criminals

03 July 2023
Pay and benefits details of Dublin Airport staff were compromised in a cyberattack on professional service provider Aon, highlighting the vulnerability of supply chain attacks.

Chinese Hackers Use HTML Smuggling to Infiltrate European Ministries with PlugX

03 July 2023
A Chinese nation-state group has been observed targeting Foreign Affairs ministries and embassies in Europe using HTML smuggling techniques to deliver the PlugX remote access trojan on compromised systems.

300,000+ Fortinet firewalls vulnerable to critical FortiOS RCE bug

03 July 2023
Hundreds of thousands of FortiGate firewalls are vulnerable to a critical security issue identified as CVE-2023-27997, almost a month after Fortinet released an update that addresses the problem.

GuLoader Campaign Targets Law Firms in the US

03 July 2023
The GuLoader malware campaign utilizes a multi-stage infection chain, including a PDF lure, a GuLoader VBScript, and obfuscated Powershell scripts, to deliver the Remcos RAT.

Who’s Behind the DomainNetworks Snail Mail Scam?

03 July 2023
If you've ever owned a domain name, the chances are good that at some point you've received a snail mail letter which appears to be a bill for a domain or website-related services. In reality, these misleading missives try to trick people into paying for useless services they never ordered, don't need, and probably will never receive. Here's a look at the most recent incarnation of this scam -- DomainNetworks -- and some clues about who may be behind it.

Torrent of image-based phishing emails are harder to detect and more convincing

03 July 2023
Phishing mongers have released a torrent of image-based junk emails that embed QR codes into their bodies to successfully bypass security protections and provide a level of customization to more easily fool recipients, researchers said.