Latest Cybersecurity News and Articles


Microsoft warns of hackers hijacking Linux systems using trojanized OpenSSH version

24 June 2023
After gaining access to a system, the attackers deploy a trojanized OpenSSH package that helps them backdoor the compromised devices and steal SSH credentials to maintain persistence.

Researcher Identifies Popular Swing VPN Android App as DDoS Botnet

24 June 2023
Swing VPN is a legitimate VPN app developed for Android and iOS systems by Limestone Software Solutions. However, according to researcher Lecromee, the Android version of this app is a DDoS botnet and allegedly harbors malicious intent.

Survey shows disconnect in cloud security perception vs. readiness

23 June 2023
While many security professionals leverage high-risk practices and behaviors in their cloud environments, they are confident security tools will protect against attacks. 

Drones Contain Over 156 Different Cyber Threats, Research Finds

23 June 2023
Out of the 156 threats identified in drone control systems, the top 50 fall into four categories — namely reporting falsified data, denying access to real-time data, impersonation of UAS and its operator, and tempering with telemetry data.

Microsoft Teams bug allows malware delivery from external accounts

23 June 2023
The attack works with Microsoft Teams running the default configuration, which permits communication with Microsoft Teams accounts outside the company, typically referred to as "external tenants."

Fortinet fixes critical FortiNAC remote command execution flaw

23 June 2023
"A deserialization of untrusted data vulnerability [CWE-502] in FortiNAC may allow an unauthenticated user to execute unauthorized code or commands via specifically crafted requests to the TCP/1050 service," Fortinet stated.

2.5 million Genworth policyholders affected by MOVEit hack

23 June 2023
A third-party vendor lost the personal data of at least 2.5 million Genworth Financial policyholders, including Social Security numbers, to the Russian Cl0p ransomware gang, according to the Fortune 500 insurer.

Google announces $20 million investment for cyber clinics

23 June 2023
By deploying students to community organizations to improve digital defenses, university cybersecurity clinics aim to give students cybersecurity experience, improve local defensive capacity and steer students toward work in cybersecurity.

MOVEit Data Breach Victims Sue Progress Software

23 June 2023
Fallout for Progress Software continues over a massive data breach that appears to have affected hundreds of private and public sector organizations that use its MOVEit file transfer software.

New Mirai botnet targets tens of flaws in popular IoT devices

23 June 2023
The botnet has been observed targeting IoT devices, routers, DVRs, access control systems, and Solar power generation monitoring systems from brands such as D-Link, Arris, Zyxel, TP-Link, Tenda, Netgear, and MediaTek.

Federal incentives could help utilities overcome major cybersecurity hurdle: money

23 June 2023
A new cyber incentive framework from the Federal Energy Regulatory Commission could help utilities adapt to new threats at a faster pace, by providing flexibility for them to invest in pre-qualified cybersecurity measures.

U.S. military members receive unsolicited smartwatches in the mail

23 June 2023
Service members across the United States military have reportedly been receiving unsolicited smartwatches in the mail, which is raising cybersecurity concerns.

Cybercrime Group 'Muddled Libra' Targets BPO Sector with Advanced Social Engineering

23 June 2023
A threat actor known as Muddled Libra is targeting the business process outsourcing (BPO) industry with persistent attacks that leverage advanced social engineering ploys to gain initial access. "The attack style defining Muddled Libra appeared on the cybersecurity radar in late 2022 with the release of the 0ktapus phishing kit, which offered a prebuilt hosting framework and bundled templates,"

NSA Shares Guidance on Blocking BlackLotus UEFI Bootkit Malware Attacks

23 June 2023
BlackLotus has been circulating on hacking forums since October 2022, marketed as malware capable of evading detection, withstanding removal efforts, and neutralizing multiple Windows security features such as Defender, HVCI, and BitLocker.

CISOs say AI & machine learning pose the most significant cyber risks

23 June 2023
A new report reveals that 54% of Chief Information Security Officers (CISO) identified burnout as their most significant personal risk, up from 48% in 2022.

Data Breach Lawsuit Alleges Mismanagement of 3rd-Party Risk

23 June 2023
A proposed federal class action lawsuit alleges that patient debt collection software firm Intellihartx was negligent in its handling of third-party risk, contributing to a breach affecting nearly 490,000 individuals.

John Hopkins University suffers data breach

23 June 2023
Johns Hopkins University and Johns Hopkins Health System suffered a cyberattack that may have impacted sensitive personal and financial information.

MULTI#STORM Campaign Targets India and U.S. with Remote Access Trojans

23 June 2023
"The attack chain ends with the victim machine infected with multiple unique remote access trojan malware instances, such as Warzone RAT and Quasar RAT," Securonix researchers Den Iuzvyk, Tim Peck, and Oleg Kolesnikov said.

French Ad Tech Firm Fined 40M Euros for GDPR Violations

23 June 2023
The top French privacy regulator has imposed a fine of 40 million euros against a Parisian advertising technology company for its use of website tracking cookies and failure to process users' personal data in compliance with privacy laws.

BlackCat Ransomware Gang Threatens to Leak Plastic Surgery Photos

23 June 2023
The notorious extortion crew, aka ALPHV, added the Beverly Hills Plastic Surgery to its list of compromised organizations, and bragged about swiping people's personal information and healthcare records.