Latest Cybersecurity News and Articles


Lack of adequate investments hinders identity security efforts

13 June 2023
Organizations are still grappling with identity-related incidents, with an alarming 90% reporting one in the last 12 months, a 6% increase from last year, according to The Identity Defined Security Alliance (IDSA).

99% of organizations expect identity-related compromise this year

13 June 2023
Current economic conditions and technology development have shown a rise in identity-based cybersecurity exposure, according to a report by CyberArk.

Ransomware Attack Played Major Role in Shutdown of Illinois Hospital

13 June 2023
The attack occurred in February 2021 and forced the shutdown of the Spring Valley hospital’s computer network, impacting all web-based operations, including its patient portal. The Peru branch was not affected, as it operated on a separate system.

DoubleFinger Loader Delivers GreetingGhoul Stealer to Target Crypto Wallets

13 June 2023
Cybercriminals have added a new malware loader called DoubleFinger to their arsenal for stealing cryptocurrency and business information. GreetingGhoul comprises two major components that work together to steal cryptocurrency credentials. To protect themselves, organizations must look at the TTPs and IOCs associated with the malware.

SPECTRALVIPER Backdoor Focuses on Vietnamese Public Companies

13 June 2023
Vietnamese public companies have been targeted by the SPECTRALVIPER backdoor in an ongoing campaign. The backdoor, a previously undisclosed x64 variant, offers various capabilities including file manipulation, token impersonation, and PE loading. SPECTRALVIPER can be compiled as an executable or DLL to imitate known binary exports.

Report highlights key threats disrupting businesses

13 June 2023
A new report highlights the top threats observed in the first half of 2023, and emerging cybersecurity trends impacting the healthcare and financial services industries. 

Experts released PoC exploit for MOVEit Transfer CVE-2023-34362 flaw

13 June 2023
Security researchers from Horizon3 have released a proof-of-concept (PoC) exploit code for the CVE-2023-34362 flaw. The experts created the PoC exploit by performing reverse engineering of the patch released by the company.

Beware: New DoubleFinger Loader Targets Cryptocurrency Wallets with Stealer

13 June 2023
A novel multi-stage loader called DoubleFinger has been observed delivering a cryptocurrency stealer dubbed GreetingGhoul in what's an advanced attack targeting users in Europe, the U.S., and Latin America. "DoubleFinger is deployed on the target machine, when the victim opens a malicious PIF attachment in an email message, ultimately executing the first of DoubleFinger's loader stages,"

Obfuscation Tool 'BatCloak’ Claims to Evade 80% of AV Detection Engines

13 June 2023
Researchers warn that tools using the BatCloak component are becoming increasingly popular with adversaries, making the already difficult task of detecting BAT files harder.

47% of organizations struggle with detecting and mitigating threats

13 June 2023
A new study reveals 70% of IT leaders in financial services reported a significant increase in data breaches compared to previous years.

New Phishing Scam Spoofs German Media, Broadband Conference Anga

13 June 2023
Hackers have devised an intricate phishing attack by leveraging the reputation of Germany’s renowned Anga Com conference to send spoofed emails and create deceptive web pages, deceiving unsuspecting users into divulging their login credentials.

Over Half of Security Leaders Lack Confidence in Protecting App Secrets, Study Reveals

13 June 2023
It might come as a surprise, but secrets management has become the elephant in the AppSec room. While security vulnerabilities like Common Vulnerabilities and Exposures (CVEs) often make headlines in the cybersecurity world, secrets management remains an overlooked issue that can have immediate and impactful consequences for corporate safety.  A recent study by GitGuardian found that 75% of IT

68% of organizations expect employee churn-driven cyber issues in 2023

13 June 2023
A new report shows how the tension between difficult economic conditions and the pace of technology innovation influences the growth of identity-led cybersecurity exposure.

Adversary-in-the-Middle Attack Campaign Hits Dozens of Global Organizations

13 June 2023
"Dozens" of organizations across the world have been targeted as part of a broad business email compromise (BEC) campaign that involved the use of adversary-in-the-middle (AitM) techniques to carry out the attacks. "Following a successful phishing attempt, the threat actor gained initial access to one of the victim employee's account and executed an 'adversary-in-the-middle' attack to bypass

Update: Have I Been Pwned warns of new Zacks data breach impacting 8 million

13 June 2023
Zacks Investment Research (Zacks) has reportedly suffered an older, previously undisclosed data breach impacting 8.8 million customers, with the database now shared on a hacking forum.

Critical FortiOS and FortiProxy Vulnerability Likely Exploited - Patch Now!

13 June 2023
The vulnerability, tracked as CVE-2023-27997, concerns a heap-based buffer overflow vulnerability in FortiOS and FortiProxy SSL-VPN that could allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.

Cyberattack on German University HS Kaiserslautern Takes ‘Entire IT Infrastructure’ Offline

13 June 2023
The Kaiserslautern University of Applied Sciences (HS Kaiserslautern) has become the latest German-speaking university to be hit by a ransomware attack, following incidents affecting at least half a dozen similar institutions in recent months.

Intellihartx Notifies 490,000 Patients of GoAnywhere-Related Data Breach

13 June 2023
The affected information, the company says, includes names, addresses, insurance data and medical billing, diagnosis and medication information, birth dates, and Social Security numbers.

The multiplying impact of BEC attacks

13 June 2023
The 2023 Verizon Data Breach Investigations Report (DBIR) has confirmed what the FBI’s Internet Crime Complaint Center has pointed out earlier this year: BEC scammers are ramping up their social engineering efforts to great success.

Illinois and Minnesota Government Departments Hit by MOVEit Transfer Breaches

13 June 2023
The latest victims to come forward are government organizations: the Illinois Department of Innovation & Technology (DoIT) and the Minnesota Department of Education (MDE).