Latest Cybersecurity News and Articles


BBC and other organizations targeted in recent MOVEit vulnerability

08 June 2023
Organizations from around the world, including the BBC and British Airways, have been warned that stolen data will be published if demands aren’t met in a recent hack.

Kimsuky's Hack: Targeting North Korean Affairs for Intel

08 June 2023
SentinelOne identified the North Korean Kimsuky group targeting experts in North Korean affairs and media to gather intelligence and steal subscription information for news outlets reporting on the country's affairs. These actions likely contribute to its broader goal of gathering strategic intelligence and influencing North Korea's decision-making processes.

Zipper Manufacturing Giant YKK Confirms Cyberattack Targeted its U.S. Networks

08 June 2023
“There is no evidence that personal or financial information or intellectual property was compromised," Jessica Kennett Cork, VP of corporate communications at YKK Corporation of America said.

Biden taps Senate Intel Committee staff director to lead NCSC

08 June 2023
The president announced on Wednesday that he would nominate Michael Casey, a longtime Democratic staff director for the Senate Intelligence Committee, to be director of the National Counterintelligence and Security Center (NCSC).

Japanese Pharmaceutical Giant Eisai Suffers Ransomware Attack

08 June 2023
The attack has affected servers both within and outside Japan and resulted in some of the group’s IT functions, including logistics systems, being taken offline. There’s no clear indication yet whether sensitive data has been leaked.

How to Improve Your API Security Posture

08 June 2023
APIs, more formally known as application programming interfaces, empower apps and microservices to communicate and share data. However, this level of connectivity doesn't come without major risks. Hackers can exploit vulnerabilities in APIs to gain unauthorized access to sensitive data or even take control of the entire system. Therefore, it's essential to have a robust API security posture to

Dallas in the homestretch of ransomware attack recovery

08 June 2023
Most of Dallas’ network and IT infrastructure has been restored following a ransomware attack in early May that took most of the city’s services offline and disrupted operations, the city said Monday.

Update: Barracuda Urges Customers to Replace Hacked Email Security Appliances

08 June 2023
“If you have not replaced your appliance after receiving notice in your UI, contact support now,” Barracuda said. “Barracuda’s remediation recommendation at this time is full replacement of the impacted ESG.”

How to make developers love security

08 June 2023
Lack of business context, unclear prioritization, disputes over ownership and responsibility, long feedback loops, and insufficient ability to make change are some of the top issues inhibiting successful developer-security collaboration.

US government's TikTok ban extended to include contractors

08 June 2023
The rule would apply to all contracts, even those below the "simplified acquisition threshold" of $250,000, purchases of commercial and off-the-shelf equipment, and commercial services.

High-risk vulnerabilities patched in ABB Aspect building management system

08 June 2023
The two vulnerabilities affect versions before 3.07.01 and could result in remote code execution (RCE), and privilege escalation within the Aspect Control Engine software, potentially giving an attacker complete control over the BMS.

OneDrive to Enum Them All

08 June 2023
OneDrive can be used for user enumeration as it creates a unique URL for each user that is tied to their Azure/M365 account. This is possible because OneDrive doesn't require a login attempt, is completely silent, and there's no rate-limiting.

Service Rents Email Addresses for Account Signups – Krebs on Security

08 June 2023
Kopeechka is offering to help cybercriminals cut costs associated with large-scale spam and account creation campaigns by paying people to sell their email credentials and allowing customers to rent access to established accounts at major providers.

Outpost24 Acquires External Attack Surface Management Provider Sweepatic to Reduce Risk Exposure of Internet-Facing Assets

08 June 2023
Outpost24, a leading cybersecurity risk management platform, announced the acquisition of Sweepatic. Based in Leuven (BE), Sweepatic is an innovative external attack surface management (EASM) platform.

University of Rochester, Nova Scotia first known MoveIT victims in North America

08 June 2023
The government of Nova Scotia and the University of Rochester are the first organizations in North America to confirm data theft as a result of the exploitation of a new vulnerability affecting popular file transfer tool MOVEit.

Enigma revives PUP labeling lawsuit against Malwarebytes

08 June 2023
The US Ninth Circuit Court of Appeals last week ruled that Enigma Software Group can pursue its long-standing complaint against rival security firm Malwarebytes for classifying its software as "potentially unwanted programs" or PUPs.

Zoom Expands Privacy Options for European Customers

08 June 2023
The key element is the option for European Economic Area (EEA) data storage. Paid customers will be able to specify certain data for meetings, webinars, and team chats to be stored within the EEA.

New PowerDrop Malware Targets U.S. Aerospace Industry

08 June 2023
The U.S. aerospace industry has recently been targeted by an unidentified threat actor leveraging a newly discovered malware that researchers named PowerDrop. Its sophisticated evasion techniques include deception, encoding, and encryption.  The company suggests conducting vulnerability scans on Windows systems and remaining vigilant for any unusual pinging activity.

Urgent Security Updates: Cisco and VMware Address Critical Vulnerabilities

08 June 2023
VMware has released security updates to fix a trio of flaws in Aria Operations for Networks that could result in information disclosure and remote code execution. The most critical of the three vulnerabilities is a command injection vulnerability tracked as CVE-2023-20887 (CVSS score: 9.8) that could allow a malicious actor with network access to achieve remote code execution. Also patched by

Kimsuky Targets Think Tanks and News Media with Social Engineering Attacks

08 June 2023
The North Korean nation-state threat actor known as Kimsuky has been linked to a social engineering campaign targeting experts in North Korean affairs with the goal of stealing Google credentials and delivering reconnaissance malware. "Further, Kimsuky's objective extends to the theft of subscription credentials from NK News," cybersecurity firm SentinelOne said in a report shared with The