Latest Cybersecurity News and Articles


Jonathan Hale joins Security Validation as Chief Technology Officer

19 May 2023
Security Validation has recently announced the appointment of Jonathan Hale as the new Chief Technology Officer.

Eye insurance firm agrees to $2.5 million settlement with state AGs after data breach

19 May 2023
EyeMed Vision Care, a major eye insurance provider, will pay a fine of $2.5 million after settling a lawsuit from four states about a 2020 data breach that exposed the personal information of about 2.1 million people.

LockBit Leaks 1.5TB of Data Stolen From Indonesia's BSI Bank

19 May 2023
The LockBit ransomware group on Tuesday published 1.5 terabytes of personal and financial information the group said it stole from Bank Syariah Indonesia after ransom negotiations broke down.

Dr. Active Directory vs. Mr. Exposed Attack Surface: Who'll Win This Fight?

19 May 2023
Active Directory (AD) is among the oldest pieces of software still used in the production environment and can be found in most organizations today. This is despite the fact that its historical security gaps have never been amended. For example, because of its inability to apply any security measures beyond checking for a password and username match, AD (as well the resources it manages) is

Google Announces New Rating System for Android and Device Vulnerability Reports

19 May 2023
The new quality rating system, the internet giant says, should encourage researchers to provide more details on the identified security defects and should also help address them faster.

Rust-Based Info Stealers Abuse GitHub Codespaces

19 May 2023
Analyzing the info-stealer with a decompiler, researchers noticed a number of interesting function names, including anti-debugging features and stealing data from web browsers, Discord, Steam, and cryptocurrency wallets, among others.

Developer Alert: NPM Packages for Node.js Hiding Dangerous TurkoRat Malware

19 May 2023
Two malicious packages discovered in the npm package repository have been found to conceal an open source information stealer malware called TurkoRat. The packages – named nodejs-encrypt-agent and nodejs-cookie-proxy-agent – were collectively downloaded approximately 1,200 times and were available for more than two months before they were identified and taken down. ReversingLabs, which broke

Identity Crimes Remain at All-Time High in 2022

19 May 2023
The volume of identity fraud incidents last year barely changed from an all-time high recorded in 2021, with Google Voice accounts the most popular target, according to the Identity Theft Resource Center (ITRC).

Russian IT worker jailed for participating in pro-Ukraine DDoS attacks

19 May 2023
Yevgeny Kotikov was found guilty of targeting the information resources of the Russian Ministry of Defence as well as the website of the president, according to state-owned news agency TASS.

BatLoader Impersonates Midjourney, ChatGPT in Drive-by Cyberattacks

19 May 2023
In its latest campaign, BatLoader is using MSIX Windows App Installer files to infect devices with Redline Stealer. This is not the first time BatLoader has targeted users searching for AI tools.

UMass Memorial agrees to pay $1.2M to settle FLSA claims stemming from Kronos attack

19 May 2023
UMass Memorial Health has agreed to pay $1.2 million to settle wage and hour claims stemming from a ransomware attack that took down its timekeeping system, according to court documents filed Friday.

Social Engineering Risks Found in Microsoft Teams

19 May 2023
“According to our findings, Microsoft Teams is one of the ten most targeted sign-in applications, with nearly 40% of targeted organizations having at least one unauthorized login attempt trying to gain access,” said researchers at Proofpoint.

FTC says fertility tracking app Premom shared sensitive health data with third parties

19 May 2023
Easy Healthcare will also be required to pay a $100,000 civil penalty for violating HBNR, as well as an additional $100,000 each to Connecticut, the District of Columbia, and Oregon for violating their respective laws.

House hearing details cyber resilience efforts for energy, water and healthcare

19 May 2023
Federal agencies have stepped up efforts to boost intelligence sharing and build industry resilience amid a wave of increased cyber threats against critical infrastructure providers.

Apple fixes three new zero-days exploited to hack iPhones, Macs

19 May 2023
Apple addressed the three zero-days in macOS Ventura 13.4, iOS and iPadOS 16.5, tvOS 16.5, watchOS 9.5, and Safari 16.5 with improved bounds checks, input validation, and memory management.

Searching for AI Tools? Watch Out for Rogue Sites Distributing RedLine Malware

19 May 2023
Malicious Google Search ads for generative AI services like OpenAI ChatGPT and Midjourney are being used to direct users to sketchy websites as part of a BATLOADER campaign designed to deliver RedLine Stealer malware. "Both AI services are extremely popular but lack first-party standalone apps (i.e., users interface with ChatGPT via their web interface while Midjourney uses Discord)," eSentire

WebKit Under Attack: Apple Issues Emergency Patches for 3 New Zero-Day Vulnerabilities

18 May 2023
Apple on Thursday rolled out security updates to iOS, iPadOS, macOS, tvOS, watchOS, and the Safari web browser to address three new zero-day flaws that it said are being actively exploited in the wild. The three security shortcomings are listed below - CVE-2023-32409 - A WebKit flaw that could be exploited by a malicious actor to break out of the Web Content sandbox. It was addressed with

12 new vulnerabilities have become associated with ransomware

18 May 2023
New research identified 12 vulnerabilities newly associated with ransomware in Q1 2023, indicating increasingly complicated ransomware attacks.

Qualys Discovers New Sotdas Malware Variant

18 May 2023
The latest iteration of the Sotdas malware has emerged, showcasing a variety of innovative features and advanced techniques for evading detection. This malware family is written in C++. After achieving persistence and collecting system information, Sotdas leverages this data for optimizing resource utilization and initiating cryptomining operations.

European Data Protection Board changes facial recognition guidelines

18 May 2023
The European Data Protection Board (EDPB) has updated its facial recognition guidelines for law enforcement to ensure compliance with privacy laws.