Latest Cybersecurity News and Articles
13 June 2023
Believe it or not, your attack surface is expanding faster than you realize. How? APIs, of course! More formally known as application programming interfaces, API calls are growing twice as fast as HTML traffic, making APIs an ideal candidate for new security solutions aimed at protecting customer data, according to Cloudflare.
According to the "Quantifying the Cost of API Insecurity" report, US
13 June 2023
The U.S. Department of Justice (DoJ) has charged two Russian nationals in connection with masterminding the 2014 digital heist of the now-defunct cryptocurrency exchange Mt. Gox.
According to unsealed indictments released last week, Alexey Bilyuchenko, 43, and Aleksandr Verner, 29, have been accused of conspiring to launder approximately 647,000 bitcoins stolen from September 2011 through at
13 June 2023
Britain’s communications regulator Ofcom announced on Monday that confidential information that it held on companies it regulates was downloaded by hackers exploiting a vulnerability in the MOVEit file transfer tool.
13 June 2023
In a major digital security breach, a website is offering personal data about Turkish citizens, including President Recep Tayyip Erdogan, that appears to have been stolen by hackers from a government services website.
13 June 2023
Orange Cyberdefense published its Cy-Xplorer 2023 report noting that cyber extortion groups have shifted their focus from North America and Europe to Latin America. While cyber extortion victims were identified across 96 countries, certain regions witnessed a rise in popularity among threat actors throughout 2022. Cyber extortion is a problem that businesses cannot effectively address in isolation.
13 June 2023
A newly discovered multi-stage AitM phishing and BEC attack campaign has been targeting banking and financial organizations. The phishing kit enabled the attackers to send out more than 16,000 emails to a target’s contacts as part of the second-stage phishing campaign. To remediate the issue, it is recommended to reset the passwords for compromised users.
13 June 2023
Fortinet on Monday disclosed that a newly patched critical flaw impacting FortiOS and FortiProxy may have been "exploited in a limited number of cases" in attacks targeting government, manufacturing, and critical infrastructure sectors.
The vulnerability, tracked as CVE-2023-27997 (CVSS score: 9.2), concerns a heap-based buffer overflow vulnerability in FortiOS and FortiProxy SSL-VPN that could
12 June 2023
According to research by the Federal Trade Commission, the most common form of text message scam reported to the FTC were false bank fraud warnings.
12 June 2023
The websites of several Swiss federal agencies and state-linked companies were inaccessible on Monday, June 12, 2023, due to a cyberattack, Switzerland’s finance ministry has confirmed.
12 June 2023
A new report reveals the use of MFA has nearly doubled since 2020 and that phishing-resistant authenticators represent the best choice in terms of security for users.
12 June 2023
Security researchers have warned about an "easily exploitable" flaw in the Microsoft Visual Studio installer that could be abused by a malicious actor to impersonate a legitimate publisher and distribute malicious extensions.
"A threat actor could impersonate a popular publisher and issue a malicious extension to compromise a targeted system," Varonis researcher Dolev Taler said. "Malicious
12 June 2023
SPECTRALVIPER is designed to contact an attacker-controlled server and awaits further commands while also adopting obfuscation methods like control flow flattening to resist analysis.
12 June 2023
Security executives are overwhelmingly craving more AI solutions in 2023 to help them battle the growing cybersecurity threat landscape, according to a report by Netrix Global.
12 June 2023
Scam Sniffer used blockchain analysis to detect the Pink Drainer hacking group, which it said has now stolen over $3 million from more than 2000 victims, some of which are said to be high-profile individuals such as OpenAI CTO Mira Murati.
12 June 2023
In their haste to make money, some new players are picking over the discarded remnants of previous ransomware groups, cobbling together ransomware rather than going through the trouble of coding bespoke crypto-locking software.
12 June 2023
According to The Athletic, three class action lawsuits related to the breach were combined into one case. The plaintiffs filed settlement papers in California federal court, the site reported, which they described as an “unopposed motion.”
12 June 2023
Researchers found that the Strava heatmap feature opens up the possibility for tracking and de-anonymizing users using publicly available heatmap data combined with specific user metadata.
12 June 2023
The term "attack surface management" (ASM) went from unknown to ubiquitous in the cybersecurity space over the past few years. Gartner and Forrester have both highlighted the importance of ASM recently, multiple solution providers have emerged in the space, and investment and acquisition activity have seen an uptick.
Many concepts come and go in cybersecurity, but attack surface management
12 June 2023
A fully undetectable (FUD) malware obfuscation engine named BatCloak is being used to deploy various malware strains since September 2022, while persistently evading antivirus detection.
The samples grant "threat actors the ability to load numerous malware families and exploits with ease through highly obfuscated batch files," Trend Micro researchers said.
About 79.6% of the total 784 artifacts
12 June 2023
In addition to the rise in botnet-driven DDoS attacks, Nokia's Threat Intelligence Report highlighted a doubling in the number of trojans targeting personal banking information on mobile devices, now accounting for 9% of all infections.