Latest Cybersecurity News and Articles


Ransomware Hackers and Scammers Utilizing Cloud Mining to Launder Cryptocurrency

15 June 2023
Ransomware actors and cryptocurrency scammers have joined nation-state actors in abusing cloud mining services to launder digital assets, new findings reveal. "Cryptocurrency mining is a crucial part of our industry, but it also holds special appeal to bad actors, as it provides a means to acquire money with a totally clean on-chain original source," blockchain analytics firm Chainalysis said in

Chrome 114 Update Patches Critical Vulnerability

15 June 2023
The new Chrome 114 update that resolves five vulnerabilities, including four critical- and high-severity bugs reported by external researchers. The most important of these is CVE-2023-3214, a critical use-after-free flaw in Autofill payments.

CISA Order Highlights Persistent Risk at Network Edge

15 June 2023
The U.S. government agency in charge of improving the nation's cybersecurity posture is ordering all federal civilian agencies to take new measures to restrict access to Internet-exposed networking equipment. The directive comes amid a surge in attacks targeting previously unknown vulnerabilities in widely used security and networking appliances.

Android Spyware GravityRAT Goes After WhatsApp Backups

15 June 2023
The BingeChat campaign is ongoing and the spyware can exfiltrate WhatsApp backups and receive commands to delete files. The actor behind GravityRAT remains unknown, and the group is tracked internally as SpaceCobra.

Cyber Command reshuffles force expansion due to Navy readiness woes

15 June 2023
The U.S. military has rearranged a years-long effort to expand the "action arm" of its top cyber forces, according to multiple sources, as leaders try to balance fighting advanced foreign threats like China with maintaining basic readiness.

Chinese UNC4841 Group Exploits Zero-Day Flaw in Barracuda Email Security Gateway

15 June 2023
A suspected China-nexus threat actor dubbed UNC4841 has been linked to the exploitation of a recently patched zero-day flaw in Barracuda Email Security Gateway (ESG) appliances since October 2022. "UNC4841 is an espionage actor behind this wide-ranging campaign in support of the People's Republic of China," Google-owned Mandiant said in a new report published today, describing the group as "

BreachForums Returns Under the Control of ShinyHunters Hackers

15 June 2023
The notorious hacking group ShinyHunters, who has been responsible for numerous massive data leaks in the past, has assumed control of the revived platform, raising alarm among cybersecurity experts and law enforcement agencies worldwide.

Public sector application flaws increased in last 12 months

15 June 2023
According to research by Veracode, public sector applications tend to have more flaws and vulnerabilities than private sector applications. 

E-Commerce Firms Are Top Targets for API, Web Apps Attacks

15 June 2023
Hackers hit the e-commerce industry with 14 billion attacks in 15 months, pushing it to the top of the list of targets for web application and API exploits, according to a new report by Akamai.

Chinese Hackers Use DNS-Over-HTTPS for Linux Malware Communication

15 June 2023
The Chinese threat group 'ChamelGang' infects Linux devices with a previously unknown implant named 'ChamelDoH,' allowing DNS-over-HTTPS communications with attackers' servers.

Vidar Malware Using New Tactics to Evade Detection and Anonymize Activities

15 June 2023
The threat actors behind the Vidar malware have made changes to their backend infrastructure, indicating attempts to retool and conceal their online trail in response to public disclosures about their modus operandi. "Vidar threat actors continue to rotate their backend IP infrastructure, favoring providers in Moldova and Russia," cybersecurity company Team Cymru said in a new analysis shared

Small organizations outpace large enterprises in MFA adoption

15 June 2023
The use of MFA has nearly doubled since 2020 and that phishing-resistant authenticators represent the best choice in terms of security and convenience for users, according to Okta.

Microsoft Links Data Wiping Attacks on Ukraine to New Russian Threat Actor

15 June 2023
The computing giant dubbed the threat actor Cadet Blizzard and said it's distinct from other well-known Russian military intelligence hacking groups, such as Sandworm and APT28, which is also known as Fancy Bear.

Warning: GravityRAT Android Trojan Steals WhatsApp Backups and Deletes Files

15 June 2023
An updated version of an Android remote access trojan dubbed GravityRAT has been found masquerading as messaging apps BingeChat and Chatico as part of a narrowly targeted campaign since June 2022. "Notable in the newly discovered campaign, GravityRAT can exfiltrate WhatsApp backups and receive commands to delete files," ESET researcher Lukáš Štefanko said in a new report published today. "The

Bill for Rural Hospital Cyber Skills Passes Senate Committee

15 June 2023
Bipartisan legislation proposing to help rural hospitals better address cybersecurity personnel shortages cleared a Senate committee Wednesday amid signs of a deepening ransomware crisis affecting hospitals serving areas with low population density.

CISA Says LockBit Made $91 Million From US Victims in Two Years

15 June 2023
The US CISA, UK NCSC, and their Australian, New Zealand, Canadian, French, and German equivalents penned the document after warning of the continued threat posed by the collective.

Spotify Fined $5.4 Million for GDPR Violations

15 June 2023
The Swedish Authority for Privacy Protection, or IMY, on Tuesday, imposed a fine of 58 million Swedish kroner (~$5.4 million) in a statement saying Spotify should be more specific about how and for which purposes it collects individuals' data.

Josh Lemos appointed as GitLab Chief Information Security Officer

15 June 2023
GitLab Inc., has recently announced the appointment of Josh Lemos as Chief Information Security Officer (CISO).

New Research: 6% of Employees Paste Sensitive Data into GenAI tools as ChatGPT

15 June 2023
The revolutionary technology of GenAI tools, such as ChatGPT, has brought significant risks to organizations' sensitive data. But what do we really know about this risk? A new research by Browser Security company LayerX sheds light on the scope and nature of these risks. The report titled "Revealing the True GenAI Data Exposure Risk" provides crucial insights for data protection stakeholders and

New Supply Chain Attack Exploits Abandoned S3 Buckets to Distribute Malicious Binaries

15 June 2023
In what's a new kind of software supply chain attack aimed at open source projects, it has emerged that threat actors could seize control of expired Amazon S3 buckets to serve rogue binaries without altering the modules themselves. "Malicious binaries steal the user IDs, passwords, local machine environment variables, and local host name, and then exfiltrates the stolen data to the hijacked