Latest Cybersecurity News and Articles


New Info-stealer Bandit Stealer Targets Browsers, Cryptocurrency Wallets

26 May 2023
The malware tries to use runas.exe, a command-line utility program in Windows operating systems (OS) that allows users to run specific programs or commands with user credentials or permissions other than those from the current user's account.

Predator Android Spyware: Researchers Sound the Alarm on Alarming Capabilities

26 May 2023
Security researchers have shared a deep dive into the commercial Android spyware called Predator, which is marketed by the Israeli company Intellexa (previously Cytrox). Predator was first documented by Google's Threat Analysis Group (TAG) in May 2022 as part of attacks leveraging five different zero-day flaws in the Chrome web browser and Android. The spyware, which is delivered by means of

Fresh perspectives needed to manage growing vulnerabilities

26 May 2023
In the inaugural 2023 Offensive Security Vision Report by NetSPI, lack of resources, vulnerability prioritization, and business priorities, were reported as the top three barriers to timely and effective vulnerability remediation.

BlackByte Lists City of Augusta as its Latest Victim After 'Cyber Incident'

26 May 2023
In a Wednesday statement about the "network outage" posted on the city's website, Augusta Mayor Garnett Johnson said the "technical difficulties" – which disrupted some of the city's computer systems – started on Sunday, May 21.

5 Must-Know Facts about 5G Network Security and Its Cloud Benefits

26 May 2023
5G is a game changer for mobile connectivity, including mobile connectivity to the cloud. The technology provides high speed and low latency when connecting smartphones and IoT devices to cloud infrastructure. 5G networks are a critical part of all infrastructure layers between the end user and the end service; these networks transmit sensitive data that can be vital for governments and

Advanced Phishing Attacks Surge 356% in 2022

26 May 2023
Among the reasons behind this growth is the fact that malicious actors continue to gain widespread access to new tools, including artificial intelligence (AI) and machine learning (ML)-powered tools.

New Russia-Linked ICS Malware 'COSMICENERGY' can Cause Cyber-Physical Disruption

26 May 2023
The malware can create disruptions in the electrical power supply by interacting with IEC 60870-5-104 (IEC-104) devices. These devices, including RTUs, are widely used in electric transmission and distribution in Europe, the Middle East, and Asia.

North Korea Actor Kimsuky Updates its Reconnaissance Malware RandomQuery

26 May 2023
Kimsuky, the North Korean APT group, is actively distributing a variant of custom malware known as RandomQuery as part of its reconnaissance campaigns. The malware has been specifically designed to perform two primary functions: file enumeration and data exfiltration. A real-time threat intelligence exchange platform can help fend off the threats from RandomQuery and other similar custom espionage tools.

Cybercriminals masquerading as MFA vendors

26 May 2023
Cybercriminals are increasingly posing as multi-factor authentication vendors and small businesses are becoming more popular targets, according to VIPRE. Financial institutions (48%) are still the most targeted sector by a wide margin.

New Mirai Variant Targets Multiple IoT Devices

26 May 2023
On April 10, Unit 42 researchers observed a Mirai variant called IZ1H9, which used several vulnerabilities to target exposed servers and networking devices running Linux, including CVE-2023-27076, CVE-2023-26801, CVE-2023-26802, and others.

It's 2023 and Sri Lanka lacks a cybersecurity authority

26 May 2023
Sri Lanka's Ministry of Technology has confirmed it will have a cybersecurity authority soon. As per local media, state minister Kanaka Herath told the Cyber Security Conference in Colombo that efforts to create the authority in 2023 are underway.

Mercenary mayhem: A technical analysis of Intellexa's PREDATOR spyware

26 May 2023
Intellexa’s spyware products, like most recently exposed spyware tools, have multiple components that can be grouped into three major buckets aligned with consecutive stages of the attack: exploitation, privilege escalation, and malware deployment.

Four Key GDPR Trends on the Law’s Fifth Anniversary

26 May 2023
The application of the GDPR across the EU on May 25, 2018, was a landmark occasion – with the legislation replacing often disjointed and outdated data protection rules across Europe with a coordinated one designed for the modern digital age.

Microsoft Encrypted Restricted Permission Messages Deliver Phishing

26 May 2023
Trustwave researchers reported that over the recent days, they had observed phishing attacks that employed a mix of compromised Microsoft 365 accounts and .rpmsg encrypted emails to distribute the phishing message.

The essence of OT security: A proactive guide to achieving CISA’s Cybersecurity Performance Goals

26 May 2023
Recently, CISA updated the CPGs to align with NIST’s standard cybersecurity framework, establishing each of the five goals as a prioritized subset of IT and OT cybersecurity practices.

Trojanized App Infects Over 50,000 with AhRAt Trojan

26 May 2023
AhRAT is a newly discovered threat by ESET researchers on the Google Play Store that disguises itself as a screen recording application, which witnessed tens of thousands of installations. Threat actors added malicious functionality at a later stage of its release in August 2022. Organizations must use the updated IOCs to understand the attack patterns and implement necessary detection systems.

AI Used to Create Malware, WithSecure Observes

26 May 2023
Alarm bells continue to ring in the cybersecurity world around the potential threats from AI in the hands of threat actors. In particular, malware being created through ChatGPT appears to be a reality.

D-Link fixes auth bypass and RCE flaws in D-View 8 software

26 May 2023
D-Link has fixed two critical-severity vulnerabilities in its D-View 8 network management suite that could allow remote attackers to bypass authentication and execute arbitrary code.

New COSMICENERGY Malware Exploits ICS Protocol to Sabotage Power Grids

26 May 2023
A new strain of malicious software that's engineered to penetrate and disrupt critical systems in industrial environments has been unearthed. Google-owned threat intelligence firm Mandiant dubbed the malware COSMICENERGY, adding it was uploaded to a public malware scanning utility in December 2021 by a submitter in Russia. There is no evidence that it has been put to use in the wild. "The

Barracuda Warns of Zero-Day Exploited to Breach Email Security Gateway Appliances

26 May 2023
Email protection and network security services provider Barracuda is warning users about a zero-day flaw that it said has been exploited to breach the company's Email Security Gateway (ESG) appliances. The zero-day is being tracked as CVE-2023-2868 and has been described as a remote code injection vulnerability affecting versions 5.1.3.001 through 9.2.0.006. The California-headquartered firm