Latest Cybersecurity News and Articles


UAE, Israel create ‘Crystal Ball’ platform to fight hackers

28 June 2023
The mission is to “design, deploy and enable regional intelligence enhancement” through collaboration and knowledge-sharing to combat national-level cyberthreats, according to a presentation by Mohamed Al Kuwaiti, UAE head of cybersecurity.

State and local governments grapple to mitigate cyber risks

28 June 2023
State and local governments face increased challenges amid a rising threat landscape due to malicious ransomware attacks and sophisticated nation-state threat actors, according to a report released Monday from Moody’s Investors Service.

5 Things CISOs Need to Know About Securing OT Environments

28 June 2023
For too long the cybersecurity world focused exclusively on information technology (IT), leaving operational technology (OT) to fend for itself. Traditionally, few industrial enterprises had dedicated cybersecurity leaders. Any security decisions that arose fell to the plant and factory managers, who are highly skilled technical experts in other areas but often lack cybersecurity training or

Update: MOVEit vulnerability ensnares more victims

28 June 2023
At least 108 organizations, including seven U.S. universities, have been listed by Clop or disclosed as having been impacted thus far, according to Brett Callow, a threat analyst at Emsisoft.

Mario Meets Malware: An Unwanted Power-Up

28 June 2023
Researchers spotted a trojanized version of the Super Mario 3: Mario Forever installer spreading Windows malware called Umbral Stealer. The installer is being promoted on gaming forums and social media groups. Researchers recommend users check their system performance and CPU usage regularly and implement proper cybersecurity hygiene to stay safe.

8Base Ransomware Spikes in Activity, Threatens U.S. and Brazilian Businesses

28 June 2023
A ransomware threat called 8Base that has been operating under the radar for over a year has been attributed to a "massive spike in activity" in May and June 2023. "The group utilizes encryption paired with 'name-and-shame' techniques to compel their victims to pay their ransoms," VMware Carbon Black researchers Deborah Snyder and Fae Carlisle said in a report shared with The Hacker News. "8Base

Swiss intelligence warns of fallout in cyberspace as West clamps down on spies

28 June 2023
Switzerland’s Federal Intelligence Service (FIS) explained that this cyber espionage was a “compensatory measure … where there has been a reduction in the number of intelligence staff deployed in the target countries.”

New Fast-Developing ThirdEye Infostealer Pries Open System Information

28 June 2023
The newly discovered malware is designed to collect various information from compromised machines, such as BIOS and hardware data, and send it to a command-and-control server.

BeeKeeperAI raises $12.1 million to accelerate AI development on privacy protected healthcare data

28 June 2023
The Series A round was led by Sante Ventures, with participation from the Icahn School of Medicine at Mount Sinai, AIX Ventures, Continuum Health Ventures, TA Group Holdings, and UCSF.

New Ongoing Campaign Targets npm Ecosystem with Unique Execution Chain

28 June 2023
"The packages in question seem to be published in pairs, each pair working in unison to fetch additional resources which are subsequently decoded and/or executed," software supply chain security firm Phylum said in a report released last week.

Malvertising Campaigns on the Rise: Anatsa Malware Targets over 600 Banking Applications

28 June 2023
The Anatsa Android banking trojan is being distributed via the Google Play Store, with over 30,000 installations recorded. The trojan collects financial information and performs on-device fraud. The malware has already amassed over 30,000 installations. mobile users need to exercise caution with app installations; they must carefully proceed to download apps.

Critical SQL Injection Flaws Expose Gentoo Soko to Remote Code Execution

28 June 2023
The two issues, which were discovered in the search feature of Soko, have been collectively tracked as CVE-2023-28424 (CVSS score: 9.1). They were addressed within 24 hours of responsible disclosure on March 17, 2023.

Critical SQL Injection Flaws Expose Gentoo Soko to Remote Code Execution

28 June 2023
Multiple SQL injection vulnerabilities have been disclosed in Gentoo Soko that could lead to remote code execution (RCE) on vulnerable systems. "These SQL injections happened despite the use of an Object-Relational Mapping (ORM) library and prepared statements," SonarSource researcher Thomas Chauchefoin said, adding they could result in RCE on Soko because of a "misconfiguration of the database.

NCSC CEO at UK-INDIA Week 2023

27 June 2023
Lindy Cameron discusses the shared opportunities and threats to both nations in cyberspace at UK-INDIA Week 2023.

U.K. Cyber Thug “PlugwalkJoe” Gets 5 Years in Prison

27 June 2023
Joseph James "PlugwalkJoe" O'Connor, a 24-year-old from the United Kingdom who earned his 15 minutes of fame by participating in the July 2020 hack of Twitter, has been sentenced to five years in a U.S. prison. That may seem like harsh punishment for a brief and very public cyber joy ride. But O'Connor also pleaded guilty in a separate investigation involving a years-long spree of cyberstalking and cryptocurrency theft enabled by "SIM swapping," a crime wherein fraudsters trick a mobile provider into diverting a customer's phone calls and text messages to a device they control.

Hackers Steal Messages, Call Logs, and Locations Intercepted by Phone Monitoring App

27 June 2023
The phone monitoring app, which is used to spy on thousands of people using Android phones, said in a notice on its login page that on June 21, “a security incident occurred involving obtaining unauthorized access to the data of website users??.”

Experts found hundreds of devices within federal networks having internet-exposed management interfaces

27 June 2023
Researchers at Censys have analyzed the attack surfaces of more than 50 Federal Civilian Executive Branch (FCEB) organizations and sub-organizations and discovered more than 13,000 distinct hosts across 100 autonomous systems.

Senior Choice, Inc. Provides Notice of Security Incident

27 June 2023
The company, which manages three residential facilities in Pennsylvania, discovered suspicious activity in its internal systems used for business operations and immediately implemented measures to contain the situation.

CISA releases cloud services guidance and resources

27 June 2023
CISA has recently released the first series of final security guidance resources under the organization's Secure Cloud Business Applications (SCuBA) project.

New Mockingjay process injection technique evades EDR detection

27 June 2023
Researchers at cybersecurity firm Security Joes discovered the method, which utilizes legitimate DLLs with RWX (read, write, execute) sections for evading EDR hooks and injecting code into remote processes.