Latest Cybersecurity News and Articles
18 May 2023
Since .zip and .mov are both file extensions, security experts are concerned that a miscreant could employ these TLDs to confuse people by visiting a malicious website rather than opening a file, among other threat scenarios.
18 May 2023
Apple has announced that it prevented over $2 billion in potentially fraudulent transactions and rejected roughly 1.7 million app submissions for privacy and security violations in 2022.
18 May 2023
According to security researchers at BlackBerry, the cybercrime group known as Cuba Ransomware, which was previously linked to a malware strain known as RomCom RAT, is not a cybercrime group at all.
18 May 2023
The rising geopolitical tensions between China and Taiwan in recent months have sparked a noticeable uptick in cyber attacks on the East Asian island country.
"From malicious emails and URLs to malware, the strain between China's claim of Taiwan as part of its territory and Taiwan's maintained independence has evolved into a worrying surge in attacks," the Trellix Advanced Research Center said
18 May 2023
The notorious cryptojacking group tracked as 8220 Gang has been spotted weaponizing a six-year-old security flaw in Oracle WebLogic servers to ensnare vulnerable instances into a botnet and distribute cryptocurrency mining malware.
The flaw in question is CVE-2017-3506 (CVSS score: 7.4), which, when successfully exploited, could allow an unauthenticated attacker to execute arbitrary commands
18 May 2023
The number of organizations that experienced ransomware attacks over the past year has remained the same, but the average cost of data recovery has increased -- whether it is in ransomware payment or restoring lost data.
18 May 2023
Described in a report called “The Growing Threat From Infostealers,” the new findings from Secureworks shed light on the thriving infostealer market, which plays a pivotal role in facilitating cybercrime activities such as ransomware attacks.
18 May 2023
A hacking group known as OilAlpha has been identified in connection with a cyber espionage campaign that specifically targets development, humanitarian, media, and non-governmental organizations in the Arabian peninsula. The group employed remote access tools, such as SpyNote and SpyMax, to install mobile spyware.
18 May 2023
A vulnerability (CVE-2023-32784) in the open-source password manager KeePass can be exploited to retrieve the master password from the software’s memory, says the researcher who unearthed the flaw.
18 May 2023
Patient information left exposed in the MedEvolve incident included names, billing addresses, telephone numbers, primary health insurer and doctor's office account numbers, and some Social Security numbers, HHS OCR said.
18 May 2023
"These vulnerabilities are due to improper validation of requests that are sent to the web interface," Cisco said, crediting an unnamed external researcher for reporting the issues.
18 May 2023
Staying ahead of adversaries essentially comes down to three elements: visibility, capabilities, and governance, and all are tied to the impact of TI on your security posture.
18 May 2023
H2 2022 marked a turning point in the security landscape. In several high-profile incidents, APIs emerged as a primary attack vector, posing a new and significant threat to organizations’ security posture, according to Cequence Security.
18 May 2023
A U.S. national has pleaded guilty in a Missouri court to operating a darknet carding site and selling financial information belonging to tens of thousands of victims in the country.
Michael D. Mihalo, aka Dale Michael Mihalo Jr. and ggmccloud1, has been accused of setting up a carding site called Skynet Market that specialized in the trafficking of credit and debit card data.
Mihalo and his
18 May 2023
Apple has announced that it prevented over $2 billion in potentially fraudulent transactions and rejected roughly 1.7 million app submissions for privacy and security violations in 2022.
The computing giant said it terminated 428,000 developer accounts for potential fraudulent activity, blocked 105,000 fake developer account creations, and deactivated 282 million bogus customer accounts. It
18 May 2023
Cisco has released updates to address a set of nine security flaws in its Small Business Series Switches that could be exploited by an unauthenticated, remote attacker to run arbitrary code or cause a denial-of-service (DoS) condition.
"These vulnerabilities are due to improper validation of requests that are sent to the web interface," Cisco said, crediting an unnamed external researcher for
17 May 2023
A report found identity thieves are better at using social engineering to convince people to share personal, financial and business information.
17 May 2023
A report reveals an increase in cyberattacks and evolving threat landscape are resulting in more organizations building long-term cyber resilience.
17 May 2023
Group-IB infiltrated the infrastructure of MichaelKors RaaS to divulge never-before-heard secrets of its affiliate nexus, which would often target critical sector entities. For instance, affiliates take back 80-85% of the ransomware payments. The common attack tactics used by MichaelKors include phishing emails having malicious links embedded in them.
17 May 2023
A new report released by Corero Network Security reveals carpet bomb distributed denial of service (DDoS) attacks increased 300% in 2022.