Latest Cybersecurity News and Articles


Webinar - Mastering API Security: Understanding Your True Attack Surface

13 June 2023
Believe it or not, your attack surface is expanding faster than you realize. How? APIs, of course! More formally known as application programming interfaces, API calls are growing twice as fast as HTML traffic, making APIs an ideal candidate for new security solutions aimed at protecting customer data, according to Cloudflare. According to the "Quantifying the Cost of API Insecurity" report, US

Two Russian Nationals Charged for Masterminding Mt. Gox Crypto Exchange Hack

13 June 2023
The U.S. Department of Justice (DoJ) has charged two Russian nationals in connection with masterminding the 2014 digital heist of the now-defunct cryptocurrency exchange Mt. Gox. According to unsealed indictments released last week, Alexey Bilyuchenko, 43, and Aleksandr Verner, 29, have been accused of conspiring to launder approximately 647,000 bitcoins stolen from September 2011 through at

Confidential data downloaded from UK regulator Ofcom in cyberattack

13 June 2023
Britain’s communications regulator Ofcom announced on Monday that confidential information that it held on companies it regulates was downloaded by hackers exploiting a vulnerability in the MOVEit file transfer tool.

Turkish Citizens’ Personal Data Offered Online After Government Site Hacked

13 June 2023
In a major digital security breach, a website is offering personal data about Turkish citizens, including President Recep Tayyip Erdogan, that appears to have been stolen by hackers from a government services website.

LatAm and Asia Face Growing Attacks, Report Warns

13 June 2023
Orange Cyberdefense published its Cy-Xplorer 2023 report noting that cyber extortion groups have shifted their focus from North America and Europe to Latin America. While cyber extortion victims were identified across 96 countries, certain regions witnessed a rise in popularity among threat actors throughout 2022. Cyber extortion is a problem that businesses cannot effectively address in isolation.

Microsoft Warns of AitM Phishing Attacks Against Financial Organizations

13 June 2023
A newly discovered multi-stage AitM phishing and BEC attack campaign has been targeting banking and financial organizations. The phishing kit enabled the attackers to send out more than 16,000 emails to a target’s contacts as part of the second-stage phishing campaign. To remediate the issue, it is recommended to reset the passwords for compromised users.

Critical FortiOS and FortiProxy Vulnerability Likely Exploited - Patch Now!

13 June 2023
Fortinet on Monday disclosed that a newly patched critical flaw impacting FortiOS and FortiProxy may have been "exploited in a limited number of cases" in attacks targeting government, manufacturing, and critical infrastructure sectors. The vulnerability, tracked as CVE-2023-27997 (CVSS score: 9.2), concerns a heap-based buffer overflow vulnerability in FortiOS and FortiProxy SSL-VPN that could

Bank fraud warnings are the most common text scam

12 June 2023
According to research by the Federal Trade Commission, the most common form of text message scam reported to the FTC were false bank fraud warnings.

Swiss Government Websites Face Outage After Being Targeted by Pro-Russian Threat Actor

12 June 2023
The websites of several Swiss federal agencies and state-linked companies were inaccessible on Monday, June 12, 2023, due to a cyberattack, Switzerland’s finance ministry has confirmed.

Use of multi-factor authentication nearly doubles since 2020

12 June 2023
A new report reveals the use of MFA has nearly doubled since 2020 and that phishing-resistant authenticators represent the best choice in terms of security for users.

Researchers Uncover Publisher Spoofing Bug in Microsoft Visual Studio Installer

12 June 2023
Security researchers have warned about an "easily exploitable" flaw in the Microsoft Visual Studio installer that could be abused by a malicious actor to impersonate a legitimate publisher and distribute malicious extensions. "A threat actor could impersonate a popular publisher and issue a malicious extension to compromise a targeted system," Varonis researcher Dolev Taler said. "Malicious

New SPECTRALVIPER Backdoor Targeting Vietnamese Public Companies

12 June 2023
SPECTRALVIPER is designed to contact an attacker-controlled server and awaits further commands while also adopting obfuscation methods like control flow flattening to resist analysis.

Factors influencing IT security spending

12 June 2023
Security executives are overwhelmingly craving more AI solutions in 2023 to help them battle the growing cybersecurity threat landscape, according to a report by Netrix Global.

Pink Drainer Group Impersonates Journalists to Steal Millions via Twitter and Discord

12 June 2023
Scam Sniffer used blockchain analysis to detect the Pink Drainer hacking group, which it said has now stolen over $3 million from more than 2000 victims, some of which are said to be high-profile individuals such as OpenAI CTO Mira Murati.

New Entrants to Ransomware Unleash Frankenstein Malware

12 June 2023
In their haste to make money, some new players are picking over the discarded remnants of previous ransomware groups, cobbling together ransomware rather than going through the trouble of coding bespoke crypto-locking software.

San Francisco 49ers agree to pay out victims of 2022 data breach

12 June 2023
According to The Athletic, three class action lawsuits related to the breach were combined into one case. The plaintiffs filed settlement papers in California federal court, the site reported, which they described as an “unopposed motion.”

Strava heatmap feature can be abused to find home addresses

12 June 2023
Researchers found that the Strava heatmap feature opens up the possibility for tracking and de-anonymizing users using publicly available heatmap data combined with specific user metadata.

Why Now? The Rise of Attack Surface Management

12 June 2023
The term "attack surface management" (ASM) went from unknown to ubiquitous in the cybersecurity space over the past few years. Gartner and Forrester have both highlighted the importance of ASM recently, multiple solution providers have emerged in the space, and investment and acquisition activity have seen an uptick. Many concepts come and go in cybersecurity, but attack surface management

Cybercriminals Using Powerful BatCloak Engine to Make Malware Fully Undetectable

12 June 2023
A fully undetectable (FUD) malware obfuscation engine named BatCloak is being used to deploy various malware strains since September 2022, while persistently evading antivirus detection. The samples grant "threat actors the ability to load numerous malware families and exploits with ease through highly obfuscated batch files," Trend Micro researchers said. About 79.6% of the total 784 artifacts

IoT Botnet DDoS Attacks Threaten Global Telecom Networks, Nokia Reports

12 June 2023
In addition to the rise in botnet-driven DDoS attacks, Nokia's Threat Intelligence Report highlighted a doubling in the number of trojans targeting personal banking information on mobile devices, now accounting for 9% of all infections.