Latest Cybersecurity News and Articles


Report: Carpet bomb DDoS attacks rise 300% in 2022

17 May 2023
A new report released by Corero Network Security reveals carpet bomb distributed denial of service (DDoS) attacks increased 300% in 2022.

Lancefly APT Group Uses 'Merdoor' In Espionage Campaign

17 May 2023
The Lancefly APT group is targeting government, aviation, education, and telecom sectors in South and Southeast Asia using a powerful backdoor called Merdoor for intelligence gathering. The exact initial intrusion vector is not clear at present, though attackers are believed to have used SSH brute-forcing or phishing lures.

Serious Unpatched Vulnerability Uncovered in Popular Belkin Wemo Smart Plugs

17 May 2023
The issue, assigned the identifier CVE-2023-27217, was discovered and reported to Belkin on January 9, 2023, by Israeli IoT security company Sternum, which reverse-engineered the device and gained firmware access.

Justice and Commerce Department 'strike force' target theft of quantum, autonomous technologies

17 May 2023
The newly formed Justice and Commerce Department’s joint Disruptive Technology Strike Force announced five coordinated enforcement actions taking aim at individuals seeking to help China, Russia and Iran gain access to sensitive U.S. technologies.

Chrome 113 Security Update Patches Critical Vulnerability

17 May 2023
Google this week announced the release of a Chrome 113 security update that resolves a total of 12 vulnerabilities, including one rated ‘critical’. Six of the flaws were reported by external researchers.

Skynet Carder Market Founder Pleads Guilty

17 May 2023
An Illinois man pleaded guilty Monday to eight criminal counts stemming from the three years he spent leading a conspiracy to sell stolen financial information on darknet markets.

CISA, FBI, and ACSC Confirm BianLian Ransomware's Switch to Extortion-Only Attacks

17 May 2023
A joint Cybersecurity Advisory from government agencies in the U.S. and Australia, and published by the CISA, is warning organizations of the latest tactics, techniques, and procedures (TTPs) used by the BianLian ransomware group.

Transportation Needs to Improve Cyber Policy Implementation, Watchdog Finds

17 May 2023
The Department of Transportation should better implement its policies for established cyber roles, including improving training and role expectations, according to a recent GAO report.

Franklin County Public Schools Hit by Ransomware Attack

17 May 2023
According to a statement from schools Superintendent Bernice Cobbs, the decision was made to cancel classes Monday in the interest of on-campus security as the impact of the cyberattack was being reviewed.

IBM snags Polar Security to boost cloud data practice

17 May 2023
In an effort to grow its hybrid cloud and artificial intelligence capabilities, IBM announced on Tuesday that it was acquiring Polar Security, an Israel-based company specializing in data security posture management.

The Africa factor: A history of geopolitical investment & colonization

17 May 2023
In this Cybersecurity & Geopolitical Discussion episode, Phillip Ingram and Ian Thornton-Trump discuss the background and recent events in Africa with guest Lisa Forte from Red Goat Cybersecurity.

State-Sponsored Sidewinder Hacker Group's Covert Attack Infrastructure Uncovered

17 May 2023
Cybersecurity researchers have unearthed previously undocumented attack infrastructure used by the prolific state-sponsored group SideWinder to strike entities located in Pakistan and China.

OilAlpha: Emerging Houthi-linked Cyber Threat Targets Arabian Android Users

17 May 2023
A hacking group dubbed OilAlpha with suspected ties to Yemen's Houthi movement has been linked to a cyber espionage campaign targeting development, humanitarian, media, and non-governmental organizations in the Arabian peninsula. "OilAlpha used encrypted chat messengers like WhatsApp to launch social engineering attacks against its targets," cybersecurity company Recorded Future said in a

US Offering $10M Reward for Russian Man Charged With Ransomware Attacks

17 May 2023
Mikhail Pavlovich Matveev, a 30-year-old Russian national, has been charged by the US Justice Department for his alleged role in numerous ransomware attacks, including ones targeting critical infrastructure.

Lea Kissner appointed as Lacework Chief Information Security Officer

17 May 2023
With more than 20 years of security industry experience, Lea Kissner has been named the new Chief Information Security Officer (CISO) at Lacework.

University Admission Platform Leverage EDU Exposed Student Passports, Applications

17 May 2023
Among the leaked data were degree certificates, student report cards, exam results, CVs, and filled application forms, along with phone numbers, emails, and home addresses.

NextGen Facing a Dozen Lawsuits So Far Following Breach

17 May 2023
Cloud-based EHR vendor NextGen Healthcare is facing a dozen proposed class action lawsuits filed during the last week in the same Georgia federal court following the company's disclosure this month of a data breach affecting one million individuals.

RecordBreaker Info-stealer Propagates Via Fake Keygens and Cracks

17 May 2023
AhnLab has uncovered yet another campaign dropping RecordBreaker Stealer, aka Raccoon Stealer V2, disguised as illegal software, such as cracks and keygens. It utilizes various channels, including websites and YouTube, as the means of distribution. Users should double-check the legitimacy of the website before downloading any software. 

Lacroix Shuts Three Factories For a Week After Cyberattack

17 May 2023
International electronics manufacturer Lacroix has reportedly intercepted a targeted cyberattack on its activity sites in France (Beaupréau), Germany (Willich), and Tunisia (Zriba).

Identifying a Patch Management Solution: Overview of Key Criteria

17 May 2023
Software is rarely a one-and-done proposition. In fact, any application available today will likely need to be updated – or patched – to fix bugs, address vulnerabilities, and update key features at multiple points in the future. With the typical enterprise relying on a multitude of applications, servers, and end-point devices in their day-to-day operations, the acquisition of a robust patch