Latest Cybersecurity News and Articles


Update: Microsoft admits DDOS as cause of recent cloud outages

19 June 2023
The Associated Press reported that in response to its inquiries about the cause of the outage, Microsoft admitted that Anonymous Sudan and DDoS orchestrated by the group were the cause of the outages.

Genetic testing firm accused by FTC of violating customers’ privacy

19 June 2023
The Federal Trade Commission is accusing the genetic testing firm 1Health.io of allegedly failing to secure customers’ genetic and health data and for duping them about the potential for getting their data erased.

Microsoft Blames Massive DDoS Attack for Azure, Outlook, and OneDrive Disruptions

19 June 2023
Microsoft on Friday attributed a string of service outages aimed at Azure, Outlook, and OneDrive earlier this month to an uncategorized cluster it tracks under the name Storm-1359. "These attacks likely rely on access to multiple virtual private servers (VPS) in conjunction with rented cloud infrastructure, open proxies, and DDoS tools," the tech giant said in a post on Friday. Storm-#### (

Cybersecurity culture improves despite the dark clouds of the past year

19 June 2023
While not directly linked, the disparity between falling material breaches and incidents and overall security postures might partly be explained by the positive cultural gains that CISOs have observed.

Update: Reddit hackers threaten to leak data stolen in February breach

19 June 2023
In a "Reddit Files" post on the BlackCat ransomware gang's data leak site, the threat actors claim to have stolen 80 GB of compressed data from the company during the February 5th attack and now plan on leaking the data.

Millions of Oregon, Louisiana state IDs stolen in MOVEit breach

17 June 2023
According to press releases by the Louisiana Office of Motor Vehicles and the Oregon Driver & Motor Vehicle Services, both agencies used the MOVEit Transfer software, which was breached during these attacks.

A simple bug exposed access to thousands of smart security alarm systems

17 June 2023
U.S. power and electronics giant Eaton has fixed a security vulnerability that allowed a security researcher to remotely access thousands of smart security alarm systems.

From Cryptojacking to DDoS Attacks: Diicot Expands Tactics with Cayosin Botnet

17 June 2023
Cybersecurity researchers have discovered previously undocumented payloads associated with a Romanian threat actor named Diicot, revealing its potential for launching distributed denial-of-service (DDoS) attacks. "The Diicot name is significant, as it's also the name of the Romanian organized crime and anti-terrorism policing unit," Cado Security said in a technical report. "In addition,

Third MOVEit bug fixed a day after PoC exploit made public

17 June 2023
Details of the latest vulnerability, tracked as CVE-2023-35708, were made public Thursday; proof-of-concept (PoC) exploit for the flaw, now fixed today, also emerged on Thursday. Progress Software issued a fix for it on Friday.

Gurvinder Rekhi named VP and CIO at the University of Dayton

16 June 2023
Gurvinder Rekhi was hired as the University of Dayton VP and CIO. Rekhi joins the university with more than 25 years of IT and leadership experience.

Rhysida ransomware leaks documents stolen from Chilean Army

16 June 2023
The Rhysida ransomware gang has now published 30% of all the data they claim to have stolen from the Chilean Army's network after initially adding it to their data leak site and claiming the attack.

FTC charges genetic testing organization for privacy concerns

16 June 2023
Genetic testing firm 1Health has been charged by the Federal Trade Commission (FTC) for leaving personal genetic and health data unsecured. 

Clop ransomware gang starts extorting MOVEit data-theft victims

16 June 2023
The Clop ransomware gang has started extorting companies impacted by the MOVEit data theft attacks, first listing the company's names on a data leak site—an often-employed tactic before public disclosure of stolen information

MOVEit Transfer customers warned of new flaw as PoC info surfaces

16 June 2023
Until security updates are released for affected MOVEit Transfer versions, Progress "strongly" recommends modifying firewall rules to deny HTTP and HTTPs traffic to MOVEit Transfer on ports 80 and 443 as a temporary workaround.

Balada Injector Campaign Hacks WordPress Sites Using Unpatched Plugins

16 June 2023
Balada leverages functions written in the Go language to spread itself and maintain persistence by executing a series of attacks, cross-site infections, and installation of backdoors.

Two Energy Department Entities Breached as Part of Massive MOVEit Transfer Compromise

16 June 2023
Multiple federal agencies, including two Department of Energy entities, were victims of a cyberattack that resulted from a widespread vulnerability in MOVEit file transfer software, federal officials said Thursday.

US Agencies Publish Guidelines on Hardening Baseboard Management Controllers

16 June 2023
The joint guidance emphasizes the importance of taking proactive measures to secure and maintain BMCs effectively, adding that many organizations fail to implement even minimum security practices.

New Diicot Threat Group Targets SSH Servers with Brute-Force Malware

16 June 2023
Deploying Cayosin botnet, an off-the-shelf Mirai-based botnet agent to target routers running the Linux-based OS OpenWRT is a newly adopted tactic, indicating that the group changes its attack style after examining its targets.

75% of OT organizations had at least 1 intrusion in the last year

16 June 2023
A new report shows three-fourths of operational technology organizations reported at least one intrusion in the last year, with 56% from malware and 49% from phishing.

Proposed SEC cyber rules would benefit ‘overall health of the cybersecurity ecosystem,’ report says

16 June 2023
A report published Wednesday by the Atlantic Council’s Cyber Statecraft Initiative asserts that the SEC’s proposed rules — requiring incident disclosure within four days — substantially differ from CIRCIA regulations.