Latest Cybersecurity News and Articles
03 July 2023
A Chinese nation-state group has been observed targeting Foreign Affairs ministries and embassies in Europe using HTML smuggling techniques to deliver the PlugX remote access trojan on compromised systems.
Cybersecurity firm Check Point said the activity, dubbed SmugX, has been ongoing since at least December 2022.
"The campaign uses new delivery methods to deploy (most notably – HTML Smuggling)
03 July 2023
A multi-national policing operation has led to the arrest of dozens of suspects including the alleged boss of an organized crime operation that targeted elderly victims with scam phone calls, according to Europol.
03 July 2023
While no HHS systems or networks were compromised, attackers gained access to HHS data by exploiting the vulnerability in the MOVEit software used by third-party vendors, the official said.
03 July 2023
94% of global respondents believe their hybrid cloud security offers full visibility into IT infrastructure, yet almost one-third of security breaches go undetected by IT pros, according to a Gigamon report.
03 July 2023
"The Meduza Stealer has a singular objective: comprehensive data theft," Uptycs said in a new report. "It pilfers users' browsing activities, extracting a wide array of browser-related data."
03 July 2023
A new report shows that three of the four new malware threats in the Q1 2023 top 10 list have originated in China and Russia.
03 July 2023
A recently released report tracks trends and impacts of ransomware attacks including encryption-less extortion and growth of ransomware-as-a-service.
03 July 2023
Officials across at least five US states, including Nebraska, South Dakota, Texas, Pennsylvania, and South Carolina, are investigating hacking claims by a suspected politically motivated group against websites connected to local governments.
03 July 2023
Officials across at least five US states, including Nebraska, South Dakota, Texas, Pennsylvania, and South Carolina, are investigating hacking claims by a suspected politically motivated group against websites connected to local governments.
03 July 2023
Every website owner or webmaster grapples with the issue of spam on their website forms. The volume of spam can be so overwhelming that finding useful information within it becomes quite challenging. What exacerbates this issue is that spam can populate your public pages, appearing in comments and reviews. You likely understand how this can damage your website's reputation, affect search results
03 July 2023
The claims of a direct hack of its IT systems were quashed by a TSMC spokesperson who told Information Security Media Group the data leak actually had affected Kinmax Technology Inc., one of its IT hardware suppliers.
03 July 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has placed a set of eight flaws to the Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
This includes six shortcomings affecting Samsung smartphones and two vulnerabilities impacting D-Link devices. All the flaws have been patched as of 2021.
CVE-2021-25394 (CVSS score: 6.4) - Samsung mobile
03 July 2023
Researchers have pulled back the curtain on an updated version of an Apple macOS malware called RustBucket that comes with improved capabilities to establish persistence and avoid detection by security software.
03 July 2023
U.S. prosecutors obtained a guilty plea Thursday from a third Nigerian man, Chibundu Joseph Anuebunwa, accused of participating in a business email compromise (BEC) ring in the mid-2010s.
03 July 2023
In yet another sign of a lucrative crimeware-as-a-service (CaaS) ecosystem, cybersecurity researchers have discovered a new Windows-based information stealer called Meduza Stealer that's actively being developed by its author to evade detection by software solutions.
"The Meduza Stealer has a singular objective: comprehensive data theft," Uptycs said in a new report. "It pilfers users' browsing
03 July 2023
Cait Conley, a senior adviser to CISA Director Jen Easterly, will assume “additional responsibilities,” including supervising election security and protecting voters from disinformation campaigns.
03 July 2023
The Illinois law, known as the Biometric Information Privacy Act (BIPA), mandates companies that collect or obtain an Illinois resident’s biometric identifier to alert that individual beforehand and get their consent in writing.
03 July 2023
According to Nexusguard, the top three DDoS attack vectors in 2022 were NTP (network time protocol) amplification, memcached, and UDP attacks. UDP-based attacks increased 121.3% year-over-year (YoY).
03 July 2023
The US Cybersecurity and Infrastructure Security Agency (CISA) has added half a dozen flaws affecting Samsung smartphones to its Known Exploited Vulnerabilities Catalog, and they have all likely been exploited by a commercial spyware vendor.
03 July 2023
The early adoption of generative AI or any nascent technology, particularly LLMs, requires comprehensive risk assessment and adherence to robust security practices throughout the entire software development life cycle (SDLC).