Latest Cybersecurity News and Articles


China's Mustang Panda Hackers Exploit TP-Link Routers for Persistent Attacks

16 May 2023
The Chinese nation-state actor known as Mustang Panda has been linked to a new set of sophisticated and targeted attacks aimed at European foreign affairs entities since January 2023.

8220 Gang Evolves With New Strategies

16 May 2023
Trend Micro researchers observed a recent attack from the 8220 Gang exploiting the Oracle WebLogic vulnerability CVE-2017-3506 (CVSS score of 7.4) captured by one of their honeypots.

Parental control app with 5 million downloads vulnerable to attacks

16 May 2023
Researchers at SEC Consult have found that the Kids Place app versions 3.8.49 and older are vulnerable to five flaws that could impact the safety and privacy of its users.

BEC Attackers Spoof CC'd Execs to Force Payment

16 May 2023
Dubbed “VIP Invoice Authentication Fraud” by Armorblox, the tactic is used in classic fake emails designed to impersonate trusted vendors or other third parties that the victim organization regularly pays.

Huntress Closes $60M Series C for MDR Expansion

16 May 2023
The $60 million Series C was led by Sapphire Ventures and brings the total raised by Huntress to a whopping $118 million. Existing investors JMI Equity and Forgepoint Capital expanded their equity stake.

China's Mustang Panda Hackers Exploit TP-Link Routers for Persistent Attacks

16 May 2023
The Chinese nation-state actor known as Mustang Panda has been linked to a new set of sophisticated and targeted attacks aimed at European foreign affairs entities since January 2023. An analysis of these intrusions, per Check Point researchers Itay Cohen and Radoslaw Madej, has revealed a custom firmware implant designed explicitly for TP-Link routers. "The implant features several malicious

Update: Dallas says it 'will likely take weeks to get back to full functionality' after ransomware attack

16 May 2023
For the last two weeks, the city has been engulfed in a massive recovery effort after the Royal ransomware gang caused significant damage to systems that manage the city’s police, fire department, courts, critical infrastructure, and more.

Industrial Cellular Routers at Risk: 11 New Vulnerabilities Expose OT Networks

16 May 2023
Several security vulnerabilities have been disclosed in cloud management platforms associated with three industrial cellular router vendors that could expose operational technology (OT) networks to external attacks.

Water Orthrus APT Re-Emerges with Two New Malware Families

16 May 2023
The threat actor known as Water Orthrus was spotted with two new campaigns in March and April 2023 that intended to deliver CopperStealth and CopperPhish payloads. The new malware have been upgraded for different purposes, such as injecting network advertisements, acquiring personal information, and stealing crypto assets. Organizations must leverage the updated IOCs associated with the malware families to better understand the attack campaign

Is human threat hunting a fool’s errand?

16 May 2023
As the rate of cyberattacks steadily increases, automated threat hunting processes are being integrated to help stem the tide by providing quicker security insights, more efficient operations, and human error reductions.

More Supply Chain Attacks Propagating Through Malicious Python Packages

16 May 2023
The FortiGuard Labs team discovered over 30 new zero-day attacks in PyPI packages (Python Package Index). These were found between late March and late April by monitoring an open-source ecosystem.

DangerousPassword Campaign: A Multi-Faceted Approach Exploiting Cryptocurrency Exchanges

16 May 2023
DangerousPassword initiated an attack campaign on cryptocurrency exchanges that infect their targets with malware, employing four distinct attack patterns. It distributes malicious CHM files from LinkedIn, uses OneNote and virtual hard disk files, and deploys an Applescript to target Mac users. Organizations must watch out for these threats and deploy the right security measures.

Geacon Brings Cobalt Strike Capabilities to macOS Threat Actors

16 May 2023
According to SentinelOne researchers, Geacon was a project that first surfaced on GitHub four years ago as a Go implementation of Cobalt Strike Beacon. Despite being widely forked, it was not being deployed against macOS targets until recently.

Western Digital cyberattack not expected to have material impact on future earnings

16 May 2023
The majority of Western Digital’s impacted systems and services are back online following a March cyberattack where hackers stole a database used in the company’s online store, the company said in a quarterly report filed with the SEC last week.

Re-Victimization from Police-Auctioned Cell Phones

16 May 2023
Countless smartphones seized in arrests and searches by police forces across the United States are being auctioned online without first having the data on them erased, a practice that can lead to crime victims being re-victimized, a new study found. In response, the largest online marketplace for items seized in U.S. law enforcement investigations says it now ensures that all phones sold through its platform will be data-wiped prior to auction.

Inside Qilin Ransomware: Affiliates Take Home 85% of Ransom Payouts

16 May 2023
Ransomware affiliates associated with the Qilin ransomware-as-a-service (RaaS) scheme earn anywhere between 80% to 85% of the ransom payments, according to new findings from Group-IB. The cybersecurity firm said it was able to infiltrate the group in March 2023, uncovering details about the affiliates' payment structure and the inner workings of the RaaS program following a private conversation

Cyolo Product Overview: Secure Remote Access to All Environments

16 May 2023
Operational technology (OT) cybersecurity is a challenging but critical aspect of protecting organizations' essential systems and resources. Cybercriminals no longer break into systems, but instead log in – making access security more complex and also more important to manage and control than ever before. In an effort to solve the access-related challenges facing OT and critical infrastructure

CopperStealer Malware Crew Resurfaces with New Rootkit and Phishing Kit Modules

16 May 2023
The threat actors behind the CopperStealer malware resurfaced with two new campaigns in March and April 2023 that are designed to deliver two novel payloads dubbed CopperStealth and CopperPhish. Trend Micro is tracking the financially motivated group under the name Water Orthrus. The adversary is also assessed to be behind another campaign known as Scranos, which was detailed by Bitdefender in

Lancefly APT Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors

16 May 2023
The custom backdoor called Merdoor is used very selectively, appearing on just a handful of networks and a small number of machines over the years, with its use appearing to be highly targeted.

Intel says its mystery microcode update isn't security fix

16 May 2023
Despite the patch notes suggesting otherwise, the mysterious blob of microcode released for many Intel microprocessors last week was not a security update, the x86 giant says.