Latest Cybersecurity News and Articles


3 Reasons SaaS Security is the Imperative First Step to Ensuring Secure AI Usage

30 June 2023
In today's fast-paced digital landscape, the widespread adoption of AI (Artificial Intelligence) tools is transforming the way organizations operate. From chatbots to generative AI models, these SaaS-based applications offer numerous benefits, from enhanced productivity to improved decision-making. Employees using AI tools experience the advantages of quick answers and accurate results, enabling

Iran's MuddyWater Evolves its C2 Framework From MuddyC3 to PhonyC2

30 June 2023
The Iranian state-sponsored group dubbed MuddyWater has been attributed to a previously unseen command-and-control (C2) framework called PhonyC2 that's been put to use by the actor since 2021.

Mobile Malware and Phishing Surge in 2022

30 June 2023
The volume of mobile malware, phishing sites dedicated to mobiles, and mobile vulnerabilities increased significantly in 2022, according to the Global Mobile Threat Report 2023 from Zimperium.

LockBit Dominates Ransomware World, New Report Finds

30 June 2023
According to analysis in the Acronis Mid-Year Cyberthreats Report 2023 LockBit’s known victims totaled 280 (49% of the total reviewed) and included the Housing Authority of the City of Los Angeles (HACLA), Aguas do Porto, and Wabtec Corporation.

Pro-Russia DDoSia hacktivist project sees 2,400% membership increase

30 June 2023
In a new report, Sekoia analysts say that the DDoSia platform has grown significantly over the year, reaching 10,000 active members contributing firepower to the project's DDoS attacks and 45,000 subscribers on its main Telegram channel.

Worker Inappropriately Accessed Patient Records for 15 Years

30 June 2023
A Cleveland-based healthcare system is notifying a not-yet-undisclosed number of individuals about an incident involving unauthorized medical records access by an employee over the past 15 years.

MIT Publishes Framework to Evaluate Cybersecurity Methods

30 June 2023
The Metior framework allows engineers and scientists to study various factors such as victim programs, attacker strategies, and obfuscation scheme configurations to determine the extent of information leakage.

WhatsApp Upgrades Proxy Feature Against Internet Shutdowns

30 June 2023
Meta's WhatsApp has rolled out updates to its proxy feature, allowing more flexibility in the kind of content that can be shared in conversations. This includes the ability to send and receive images, voice notes, files, stickers and GIFs, WhatsApp told The Hacker News. The new features were first reported by BBC Persian. Some of the other improvements include streamlined steps to simplify the

Apple opposes UK Online Safety Bill's 'spy clause'

30 June 2023
Apple has joined the rapidly growing chorus of tech organizations calling on British lawmakers to revise the nation's Online Safety Bill – which for now is in the hands of the House of Lords – so that it safeguards strong end-to-end encryption.

Cybercriminals Hijacking Vulnerable SSH Servers in New Proxyjacking Campaign

30 June 2023
An active financially motivated campaign is targeting vulnerable SSH servers to covertly ensnare them into a proxy network. "This is an active campaign in which the attacker leverages SSH for remote access, running malicious scripts that stealthily enlist victim servers into a peer-to-peer (P2P) proxy network, such as Peer2Profit or Honeygain," Akamai researcher Allen West said in a Thursday

Charming Kitten’s PowerStar Malware Evolves with Advanced Techniques

30 June 2023
The latest PowerStar variant offers remote execution of PowerShell and C# commands, persistence through various methods, dynamic configuration updates, multiple C2 channels, system reconnaissance, and monitoring of established persistence mechanisms.

IP Fabric Raises $25 Million in Series B Funding

30 June 2023
The new investment round was led by One Peak, with participation from Senovo and Presto Ventures. The company says it can help organizations address three main issues with network management — automation, complexity, and assurance.

NSA and CISA Release Guidelines to Secure CI/CD Environments

30 June 2023
The US National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) have published a comprehensive set of guidelines aimed at defending Continuous Integration/Continuous Delivery (CI/CD) environments.

MITRE Unveils Top 25 Most Dangerous Software Weaknesses of 2023: Are You at Risk?

30 June 2023
MITRE has released its annual list of the Top 25 "most dangerous software weaknesses" for the year 2023. "These weaknesses lead to serious vulnerabilities in software," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said. "An attacker can often exploit these vulnerabilities to take control of an affected system, steal data, or prevent applications from working." The list is

NCSC marks 20th anniversary of first response to state-sponsored cyber attack

29 June 2023
In June 2003, GCHQ experts were involved in responding to a cyber attack against the UK Government for the first time.

8Base Ransomware Activity Spikes, Researcher Warn

29 June 2023
Ransomware threat 8Base has been conducting double extortion attacks for over a year and its activities spiked suddenly in May and June 2023. 8Base has been connected to 67 attacks by Malwarebytes and NCC Group. Approximately 50% of the targeted victims belong to the business services, manufacturing, and construction sectors.

Russian Cybersecurity Executive Arrested for Alleged Role in 2012 Megahacks

29 June 2023
Nikita Kislitsin, formerly the head of network security for one of Russia's top cybersecurity firms, was arrested last week in Kazakhstan in response to 10-year-old hacking charges from the U.S. Department of Justice. Experts say Kislitsin's prosecution could soon put the Kazakhstan government in a sticky diplomatic position, as the Kremlin is already signaling that it intends to block his extradition to the United States.

European Cyber Agency Remains Underfunded

29 June 2023
There are multiple discrepancies in how the European Commission allocates funds to the cyber agency, Juhan Lepassaar, the executive director of the EU Agency for Cybersecurity, said during a Tuesday parliamentary hearing evaluating allocated budgets.

Details Disclosed for Critical SAP Vulnerabilities, Including Wormable Exploit Chain

29 June 2023
The vulnerabilities are tracked as CVE-2021-27610, CVE-2021-33677, CVE-2021-33684, and CVE-2023-0014, and they impact products that use the SAP Application Server for ABAP component.

Saudi Arabia's Cyber Capabilities Ranked Second Globally

29 June 2023
According to the IIMD, the development of a National Cybersecurity Authority (NCA) and the planned development of a Global Cybersecurity Forum institute in the country have both affirmed Saudi Arabia's role in the field of cybersecurity.