Latest Cybersecurity News and Articles


Alert: Hackers Exploit Barracuda Email Security Gateway 0-Day Flaw for 7 Months

31 May 2023
Enterprise security firm Barracuda on Tuesday disclosed that a recently patched zero-day flaw in its Email Security Gateway (ESG) appliances had been abused by threat actors since October 2022 to backdoor the devices. The latest findings show that the critical vulnerability, tracked as CVE-2023-2868 (CVSS score: N/A), has been actively exploited for at least seven months prior to its discovery.

Discord Admins Hacked by Malicious Bookmarks

30 May 2023
A number of Discord communities focused on cryptocurrency have been hacked this past month after their administrators were tricked into running malicious Javascript code disguised as a Web browser bookmark.

Technology integration exposes infrastructure to cyberattacks

30 May 2023
From the disruption of fuel distribution to the interruption of emergency healthcare services, cyberattacks are no longer confined to cyberspace.

89% of businesses report concern over new privacy regulations

30 May 2023
Organizations must ensure only the right people have access to the right data and that malicious actors don't gain access to sensitive information.

Less than 1 in 5 U.S. clinics are protected against phishing

30 May 2023
A new survey of U.S.-based clinics and hospitals has revealed less than one in five institutions have correctly implemented basic phishing and spoofing protection.

Hackers Win $105,000 for Reporting Critical Security Flaws in Sonos One Speakers

30 May 2023
Multiple security flaws uncovered in Sonos One wireless speakers could be potentially exploited to achieve information disclosure and remote code execution, the Zero Day Initiative (ZDI) said in a report published last week. The vulnerabilities were demonstrated by three different teams from Qrious Secure, STAR Labs, and DEVCORE at the Pwn2Own hacking contest held in Toronto late last year,

CAPTCHA-Breaking Services with Human Solvers Helping Cybercriminals Defeat Security

30 May 2023
Cybersecurity researchers are warning about CAPTCHA-breaking services that are being offered for sale to bypass systems designed to distinguish legitimate users from bot traffic. "Because cybercriminals are keen on breaking CAPTCHAs accurately, several services that are primarily geared toward this market demand have been created," Trend Micro said in a report published last week. "These

68% of organizations suffered a cyberattack in past year

30 May 2023
A new report reveals that 68% of organizations suffered a cyberattack within the last 12 months.

Implementing Risk-Based Vulnerability Discovery and Remediation

30 May 2023
In this day and age, vulnerabilities in software and systems pose a considerable danger to businesses, which is why it is essential to have an efficient vulnerability management program in place. To stay one step ahead of possible breaches and reduce the damage they may cause, it is crucial to automate the process of finding and fixing vulnerabilities depending on the level of danger they pose.

NCC Group Releases Open Source Tools for Developers, Pentesters

30 May 2023
The first, named Code Credential Scanner (CSS), can be used by developers to scan configuration files in a repository to detect any stored credentials and remove them before they are leaked.

Blacktail Leverages LockBit and Babuk Source Code to Build Buhti

30 May 2023
Experts at Symantec observed that the operators behind the emerging Buhti ransomware have apparently abandoned their own customized malware and instead utilized the leaked versions of the LockBit and Babuk ransomware families to target both Windows and Linux operating systems. This competent threat can not be underestimated and calls for proactive defense strategies.

New hacking forum leaks data of 478,000 RaidForums members

30 May 2023
A database for the notorious RaidForums hacking forums has been leaked online, allowing threat actors and security researchers insight into the people who frequented the forum.

Invoice and CEO Scams Dominate Fraud Impacting Businesses

30 May 2023
Losses to fraud reported by Britain's financial services sector exceeded $1.5 billion in 2022. So says a new study from UK Finance, a London-based trade association for Britain's banking and financial services sector.

Sneaky DogeRAT Trojan Poses as Popular Apps, Targets Indian Android Users

30 May 2023
A new open source remote access trojan (RAT) called DogeRAT targets Android users primarily located in India as part of a sophisticated malware campaign. The malware is distributed via social media and messaging platforms under the guise of legitimate applications like Opera Mini, OpenAI ChatGOT, and Premium versions of YouTube, Netflix, and Instagram. "Once installed on a victim's device, the

Jimbos Protocol Hack Results in Loss of $7.5 Million Worth of Assets

29 May 2023
The latest victim of a protocol hack is Jimbos Protocol, a decentralized liquidity platform operating on the Arbitrum system. The attack resulted in a loss of 4,000 Ether (ETH), valued at around $7.5 million during the incident.

UK: 20 NHS trusts shared patient details with Facebook without consent

29 May 2023
The data includes granular details of pages viewed, buttons clicked and keywords searched. It is matched to the user’s IP address – an identifier linked to an individual or household – and, in many cases, details of their Facebook account.

New BrutePrint Attack Lets Attackers Unlock Smartphones with Fingerprint Brute-Force

29 May 2023
Researchers have discovered an inexpensive attack technique that could be leveraged to brute-force fingerprints on smartphones to bypass user authentication and seize control of the devices. The approach, dubbed BrutePrint, bypasses limits put in place to counter failed biometric authentication attempts by weaponizing two zero-day vulnerabilities in the smartphone fingerprint authentication (SFA

CISA warns govt agencies of recently patched Barracuda zero-day

29 May 2023
FCEB agencies must patch or mitigate the vulnerability as ordered by the BOD 22-01 binding operational directive. However, this is no longer needed since Barracuda has already patched all vulnerable devices by applying two patches over the weekend.

Sports Warehouse Fined $300,000 Over Payment Card Data Theft

29 May 2023
Investigators found that the retailer was storing nearly 20 years' worth of payment card data on its e-commerce server in plaintext format, protected by only a password, which the attacker guessed.

QBot malware abuses Windows WordPad EXE to infect devices

29 May 2023
The QBot malware operation has started to abuse a DLL hijacking flaw in the Windows 10 WordPad program to infect computers, using the legitimate program to evade detection by security software.