Latest Cybersecurity News and Articles


Security experts weigh in on Snake malware operation

22 May 2023
Security industry leaders share thoughts on the takedown of sophisticated Snake malware & discuss what organizations can learn and apply to cybersecurity moving forward.

EU Regulators Hit Meta with Record $1.3 Billion Fine for Data Transfer Violations

22 May 2023
Facebook's parent company Meta has been fined a record $1.3 billion by European Union data protection regulators for transferring the personal data of users in the region to the U.S. In a binding decision taken by the European Data Protection Board (EDPB), the social media giant has been ordered to bring its data transfers into compliance with the GDPR and delete unlawfully stored and processed

Malicious links and misaddressed emails slip past security controls

22 May 2023
The majority of organizations use six or more communication tools, across channels, with email remaining the channel seen as the most vulnerable to attacks (38%), according to Armorblox.

Update: Dallas under pressure as Royal ransomware group threatens leak

22 May 2023
The ransomware attack against Dallas entered a new and all-too-common phase Friday as Royal, the threat actor behind the attack, listed the city on its leak site almost three weeks after the city was first made aware of the attack.

Onfido acquires Airside to boost identity verification for individuals and businesses

22 May 2023
Cybersecurity firm Onfido acquired Airside Mobile to deliver user-controlled, shareable digital identity designed with data privacy and time-saving convenience at its core.

Indonesian Cybercriminals Exploit AWS for Profitable Crypto Mining Operations

22 May 2023
A financially motivated threat actor of Indonesian origin has been observed leveraging Amazon Web Services (AWS) Elastic Compute Cloud (EC2) instances to carry out illicit crypto mining operations. Cloud security company's Permiso P0 Labs, which first detected the group in November 2021, has assigned it the moniker GUI-vil (pronounced Goo-ee-vil). "The group displays a preference for Graphical

UK Councils Caught in Capita Unsecured AWS Bucket Data Leak

22 May 2023
The bad news train keeps rolling for Capita, with more local British councils surfacing to say their data was put on the line by an unsecured AWS bucket, and, separately, pension clients warning of possible data theft in March's mega breach.

DarkBERT could help automate dark web mining for cyber threat intelligence

22 May 2023
Researchers have developed DarkBERT, a language model pre-trained on dark web data, to help cybersecurity pros extract cyber threat intelligence (CTI) from the Internet’s virtual underbelly.

BlackCat Ransomware Deploys New Signed Kernel Driver

22 May 2023
Trend Micro researchers reported on an incident involving the BlackCat ransomware that took place in February 2023. The researchers highlighted a new capability, which involved the utilization of a signed kernel driver for evasion.

Facebook Parent Meta Hit With Record Fine for Transferring European User Data to US

22 May 2023
The European Union slapped Meta with a record $1.3 billion privacy fine Monday and ordered it to stop transferring user data across the Atlantic, the latest salvo in a decadelong case sparked by U.S. cyberespionage fears.

UK Man Sentenced to 13 Years for Running Multi-Million Fraud Website

22 May 2023
Tejay Fletcher, 35, from London, was found guilty of running a multi-million-pound fraud website that led to at least £100m ($124.2m) being stolen globally. Of this, £43m ($53.4m) was taken from UK victims.

Critical infrastructure security spending to grow 83% by 2027: ABI Research

22 May 2023
Critical infrastructure providers are poised to increase global spending on cybersecurity at a compound annual growth rate of 13%, according to projections ABI Research released Tuesday.

Update: Dish Ransomware Attack Impacted Nearly 300,000 People

22 May 2023
The company informed the Maine Attorney General about the data breach last week and shared a copy of the notification letter sent to impacted people. Dish told authorities that the incident impacted more than 296,000 individuals.

Bad Magic's Extended Reign in Cyber Espionage Goes Back Over a Decade

22 May 2023
New findings about a hacker group linked to cyber attacks targeting companies in the Russo-Ukrainian conflict area reveal that it may have been around for much longer than previously thought. The threat actor, tracked as Bad Magic (aka Red Stinger), has not only been linked to a fresh sophisticated campaign, but also to an activity cluster that first came to light in May 2016. "While the

Royal Gang Builds Its Own Malware Loader

22 May 2023
The Royal ransomware group is enhancing its downloader malware by adopting tactics and techniques that seem to be directly influenced by other post-Conti groups. The malware loader appears to be at its nascent stage and has a single purpose of deploying Cobalt Strike.  Organizations are urged to timely report TTPs of the threat so that other organizations can fend it off.

Europe: The DDoS battlefield

22 May 2023
DDoS attacks appear to reflect major geo-political challenges and social tensions and have become an increasingly significant part in the hybrid warfare arsenal, according to Arelion.

Cloned CapCut Websites Push Information Stealing Malware

22 May 2023
The malicious websites were discovered by Cyble, which reports seeing two campaigns distributing different malware strains. No specific information about how victims are directed on these sites was provided.

FIN7 Returns with Cl0p Ransomware Attacks

22 May 2023
The FIN7 gang has made a comeback with a new attack tactic involving Cl0p ransomware strains. It has previously utilized ransomware strains developed by various groups such as REvil and Maze. It uses Impacket and OpenSSH to infiltrate targeted networks and move laterally to deploy Cl0p ransomware. Organizations should use threat intelligence sharing platforms to stay updated on the latest global and internal events in real time..

Privacy Sandbox Initiative: Google to Phase Out Third-Party Cookies Starting 2024

22 May 2023
Google has announced plans to officially flip the switch on its twice-delayed Privacy Sandbox initiatives as it slowly works its way to deprecate support for third-party cookies in Chrome browser.

Are Your APIs Leaking Sensitive Data?

22 May 2023
It's no secret that data leaks have become a major concern for both citizens and institutions across the globe. They can cause serious damage to an organization's reputation, induce considerable financial losses, and even have serious legal repercussions. From the infamous Cambridge Analytica scandal to the Equifax data breach, there have been some pretty high-profile leaks resulting in massive