Latest Cybersecurity News and Articles


Chinese Phishing Gang "PostalFurious" Expands Campaign

02 June 2023
A recently discovered Chinese phishing gang has expanded its campaigns to the Middle East with new scams designed to harvest personal and payment data from victims, according to Group-IB.

Report: Advanced phishing attacks grew 356% in 2022

02 June 2023
A new report analyzed the most prevalent cyberattack trends and identified an 87% increase in the total number of attacks over the course of last year.

Camaro Dragon Strikes with New TinyNote Backdoor for Intelligence Gathering

02 June 2023
Israeli cybersecurity firm Check Point, which dubbed the Go-based malware TinyNote, said it functions as a first-stage payload capable of "basic machine enumeration and command execution via PowerShell or Goroutines."

New Horabot Campaign Targets Spanish-Speaking Users in the Americas

02 June 2023
Horabot enables the threat actor to control the victim’s Outlook mailbox, exfiltrate contacts’ email addresses, and send phishing emails with malicious HTML attachments to all addresses in the victim’s mailbox.

Discord Admins Hacked by Malicious Bookmarks – Krebs on Security

02 June 2023
A number of Discord communities focused on cryptocurrency have been hacked this past month after their administrators were tricked into running malicious Javascript code disguised as a Web browser bookmark.

Harvard Pilgrim Health Care Ransomware Attack Hits 2.5 Million People

02 June 2023
Last week, the organization published a notice informing that ransomware actors maintained access to its systems between March 28 and April 17, 2023, when the breach was discovered.

New Botnet Malware 'Horabot' Targets Spanish-Speaking Users in Latin America

02 June 2023
Spanish-speaking users in Latin America have been at the receiving end of a new botnet malware dubbed Horabot since at least November 2020. "Horabot enables the threat actor to control the victim's Outlook mailbox, exfiltrate contacts' email addresses, and send phishing emails with malicious HTML attachments to all addresses in the victim's mailbox," Cisco Talos researcher Chetan Raghuprasad 

Insurers Predict $33bn Bill for Catastrophic "Cyber Event"

02 June 2023
A catastrophic “once-in-200-years” cyber event could cause $33bn in losses for the cyber-insurance sector, according to the new Through the Looking Glass report from Guy Carpenter.

New MOVEit Transfer Zero-Day Mass-Exploited in Data Theft Attacks

02 June 2023
"Progress has discovered a vulnerability in MOVEit Transfer that could lead to escalated privileges and potential unauthorized access to the environment," reads a security advisory from Progress.

QBot Abuses Windows WordPad for Infection

02 June 2023
QBot operators are exploiting a DLL hijacking flaw in the Windows 10 WordPad executable known as write.exe to avoid detection. The infection may lead to the exposure of a user's email address which could be utilized in future phishing attacks. Furthermore, the impacted device can be infected by downloading other payloads, such as Cobalt Strike, for initial access. Experts revealed attackers can spread laterally throughout the network.

Phishing campaigns thrive as evasive tactics outsmart conventional detection

02 June 2023
A 25% increase in the use of phishing kits has been recorded in 2022, according to Group-IB. The key phishing trends observed are the increasing use of access control and advanced detection evasion techniques.

The Importance of Managing Your Data Security Posture

02 June 2023
Data security is reinventing itself. As new data security posture management solutions come to market, organizations are increasingly recognizing the opportunity to provide evidence-based security that proves how their data is being protected. But what exactly is data security posture, and how do you manage it?  Data security posture management (DSPM) became mainstream following the publication

Critical Vulnerabilities Found in Faronics Education Software

02 June 2023
NCC Group identified a total of 11 vulnerabilities in Faronics Insight, including three critical-severity flaws (CVSS score of 9.6) leading to RCE. Two of these could be exploited without authentication.

Camaro Dragon Strikes with New TinyNote Backdoor for Intelligence Gathering

02 June 2023
The Chinese nation-stage group known as Camaro Dragon has been linked to yet another backdoor that's designed to meet its intelligence-gathering goals. Israeli cybersecurity firm Check Point, which dubbed the Go-based malware TinyNote, said it functions as a first-stage payload capable of "basic machine enumeration and command execution via PowerShell or Goroutines." What the malware lacks in

Go-based GobRAT Targets Linux Routers in Japan

02 June 2023
Actors behind a new malware named GobRAT were observed launching attacks against Linux routers in Japan. Cybercriminals abuse routers with publicly accessible web user interfaces. The malware strain is written in Go and established C2 communication via TLS. It can receive as many as 22 varieties of encrypted commands for execution.

North Korea's Kimsuky Group Mimics Key Figures in Targeted Cyber Attacks

02 June 2023
U.S. and South Korean intelligence agencies have issued a new alert warning of North Korean cyber actors' use of social engineering tactics to strike think tanks, academia, and news media sectors. The "sustained information gathering efforts" have been attributed to a state-sponsored cluster dubbed Kimsuky, which is also known by the names APT43, ARCHIPELAGO, Black Banshee, Emerald Sleet (

MOVEit Transfer Under Attack: Zero-Day Vulnerability Actively Being Exploited

01 June 2023
A critical flaw in Progress Software's in MOVEit Transfer managed file transfer application has come under widespread exploitation in the wild to take over vulnerable systems. The shortcoming, which is yet to be assigned a CVE identifier, relates to a severe SQL injection vulnerability that could lead to escalated privileges and potential unauthorized access to the environment. "An SQL injection

Ask Fitis, the Bear: Real Crooks Sign Their Malware

01 June 2023
Code-signing certificates are supposed to help authenticate the identity of software publishers, and provide cryptographic assurance that a signed piece of software has not been altered or tampered with. Both of these qualities make stolen or ill-gotten code-signing certificates attractive to cybercriminal groups, who prize their ability to add stealth and longevity to malicious software. This post is a deep dive on "Megatraffer," a veteran Russian hacker who has practically cornered the underground market for malware focused code-signing certificates since 2015.

Evasive QBot Malware Leverages Short-lived Residential IPs for Dynamic Attacks

01 June 2023
An analysis of the "evasive and tenacious" malware known as QBot has revealed that 25% of its command-and-control (C2) servers are merely active for a single day. What's more, 50% of the servers don't remain active for more than a week, indicating the use of an adaptable and dynamic C2 infrastructure, Lumen Black Lotus Labs said in a report shared with The Hacker News. "This botnet has adapted

Maria Milosavljevic named next CISO at ANZ

01 June 2023
ANZ announced Maria Milosavljevic has been appointed CISO, replacing Lynwen Connick, who will retire in October after six years as ANZ’s CISO.