Latest Cybersecurity News and Articles


PoC released for Windows Win32k bug exploited in attacks

09 June 2023
The vulnerability is tracked as CVE-2023-29336 and was originally discovered by cybersecurity firm Avast. It was assigned a CVSS v3.1 severity rating of 7.8 as it allows low-privileged users to gain Windows SYSTEM privileges.

Update: North Korea's Lazarus Group linked to Atomic Wallet heist

09 June 2023
Elliptic researchers said that by tracking some of the stolen crypto, they were able to collect information about how it was handled and laundered, with the audit trail pointing in the direction of Lazarus Group.

Stealth Soldier: A New Custom Backdoor Targets North Africa with Espionage Attacks

09 June 2023
A new custom backdoor dubbed Stealth Soldier has been deployed as part of a set of highly-targeted espionage attacks in North Africa. "Stealth Soldier malware is an undocumented backdoor that primarily operates surveillance functions such as file exfiltration, screen and microphone recording, keystroke logging and stealing browser information," cybersecurity company Check Point said in a

Barracuda Urges Replacing — Not Patching — Its Email Security Gateways

08 June 2023
It's not often that a zero-day vulnerability causes a network security vendor to urge customers to physically remove and decommission an entire line of affected hardware -- as opposed to just applying software updates. But experts say that is exactly what transpired this week with Barracuda Networks, as the company struggled to combat a sprawling malware threat which appears to have undermined its email security appliances in such a fundamental way that they can no longer be safely updated with software fixes.

48% of security leaders say distributed workforce influences spending

08 June 2023
The quick development of artificial intelligence and new technologies has led security leaders to consider how to implement them in cybersecurity.

Aix-Marseille, France’s largest university, hit by cyberattack

08 June 2023
The institution’s management described the attack as coming “from a foreign country” but said its security systems triggered an alert allowing them to take the network offline before “great damage” was caused.

Josh DeFrain named Chief Information Security Officer at Rokt

08 June 2023
Ecommerce technology company Rokt has appointed Josh DeFrain as Chief Information Security Officer (CISO) effective immediately. 

37% of IT professionals report experiencing a data loss event

08 June 2023
Best practices for data protection were analyzed in a report finding that 25% of IT professionals follow industry best practices for backing up data.

Security professional's tweet forces big change to Google email authentication

08 June 2023
Less than a month after BIMI’s roll-out, scammers found a way around its controls and were able to successfully impersonate brands, sending emails to Google users that impersonated the logistics giant UPS.

Asylum Ambuscade: crimeware or cyberespionage?

08 June 2023
The group targets bank customers and cryptocurrency traders in various regions, including North America and Europe, as well as government entities in Europe and Central Asia.

Interpol: Human Trafficking is Fueling Fraud Epidemic

08 June 2023
Interpol is concerned about the threat, which first emerged in 2021, as it has spread from a focus on Chinese-speaking victims based in China, Malaysia, Thailand, and Singapore, to as far afield as South America, East Africa, and Western Europe.

German Recruiter Pflegia Leaks 360,000 Files Containing Sensitive Job Seeker Information

08 June 2023
The exposed AWS bucket held hundreds of thousands of files with sensitive information, including user-submitted resumes with details such as full names, dates of birth, and occupation history.

API Vulnerabilities in Honda eCommerce Platform Exposed Customer, Dealer Data

08 June 2023
A researcher has disclosed the details of serious vulnerabilities discovered in a Honda e-commerce platform used for equipment sales. Exploitation of the flaws could have allowed an attacker to gain access to customer and dealer information.

Experts Unveil PoC Exploit for Recent Windows Vulnerability Under Active Exploitation

08 June 2023
Details have emerged about a now-patched actively exploited security flaw in Microsoft Windows that could be abused by a threat actor to gain elevated privileges on affected systems. The vulnerability, tracked as CVE-2023-29336, is rated 7.8 for severity and concerns an elevation of privilege bug in the Win32k component. "An attacker who successfully exploited this vulnerability could gain

FTC charges Amazon for keeping children's voice recordings

08 June 2023
Amazon will be required to overhaul how it deletes data and implement new privacy guidelines following FTC and Department of Justice charges.

Ascension Seton Reports Data Breach of Two Websites Impacting User Information

08 June 2023
Ascension Seton said it did not have specific details about what information had been affected but that some users’ personal details, such as name, address, SSNs, credit card numbers, and insurance information may be at risk.

Clop Ransomware Gang Likely Exploiting MOVEit Transfer Vulnerability Since 2021

08 June 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have published a joint advisory regarding the active exploitation of a recently disclosed critical flaw in Progress Software's MOVEit Transfer application to drop ransomware. "The Cl0p Ransomware Gang, also known as TA505, reportedly began exploiting a previously unknown SQL injection

Cyber unicorn Snyk acquiring Israeli startup Enso Security for over $50 million

08 June 2023
Snyk said it plans to leverage Enso’s Application Security Posture Management (ASPM) solution to offer a developer security platform providing a holistic view of application security posture.

New Fractureiser Malware Used CurseForge Minecraft Mods to Infect Windows, Linux

08 June 2023
Hackers used the popular Minecraft modding platforms Bukkit and CurseForge to distribute a new 'Fractureiser' information-stealing malware through uploaded modifications and by injecting malicious code into existing projects.

Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions

08 June 2023
Cisco on Wednesday announced patches for a critical vulnerability in its Expressway series and TelePresence Video Communication Server (VCS) enterprise collaboration and video communication solutions.