Latest Cybersecurity News and Articles


Lancefly APT Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors

16 May 2023
The custom backdoor called Merdoor is used very selectively, appearing on just a handful of networks and a small number of machines over the years, with its use appearing to be highly targeted.

Intel says its mystery microcode update isn't security fix

16 May 2023
Despite the patch notes suggesting otherwise, the mysterious blob of microcode released for many Intel microprocessors last week was not a security update, the x86 giant says.

Qilin's Dark Web Ransomware Targets Critical Sectors

16 May 2023
Employing Rust and Go programming languages, Qilin has been actively targeting companies in critical sectors with highly customized and evasive ransomware attacks, explained Nikolay Kichatov, threat intelligence analyst at Group-IB.

The new info-stealing malware operations to watch out for

16 May 2023
Although older strains like RedLine, Raccoon, and Vidar continue to have a significant presence, and newer families like Aurora, Mars, and Meta are still growing, new malware families are also trying to make a name for themselves this year.

Water Orthrus New Campaigns Deliver Rootkit and Phishing Modules

16 May 2023
According to Trend Micro researchers, they have been monitoring the activities of a threat actor referred to as Water Orthrus since 2021. The threat actor has been utilizing pay-per-install (PPI) networks to distribute CopperStealer malware.

Advantech’s industrial serial device servers open to attack

16 May 2023
Three vulnerabilities discovered by CyberDanube researchers in Advantech’s EKI series of serial device servers could be exploited to execute arbitrary commands at the operating system level.

Hackers Using Golang Variant of Cobalt Strike to Target Apple macOS Systems

16 May 2023
A Golang implementation of Cobalt Strike called Geacon is likely to garner the attention of threat actors looking to target Apple macOS systems. The findings come from SentinelOne, which observed an uptick in the number of Geacon payloads appearing on VirusTotal in recent months. "While some of these are likely red-team operations, others bear the characteristics of genuine malicious attacks,"

BPFDoor Backdoor Gets Stealthier with New Variant

15 May 2023
Cybersecurity experts took the wraps off of a newer variant of BPFDoor (BPF stands for Berkeley Packet Filter), which is capable of maintaining persistent access to breached systems for extended periods. The new variant has remained entirely undetected by all the virus-detection engines on VirusTotal.  To mitigate the risks associated with BPFDoor, admins should prioritize rigorous monitoring of network traffic and logs.

Rise in Attacks Against ESXi: Babuk Source Code Inspires Nine Different Ransomware Strains

15 May 2023
SentinelLabs detected 10 ransomware families employing VMware ESXi lockers, derived from the leaked 2021 Babuk source code. These variants emerged between H2 2022 and H1 2023. The report also highlights similarities between Babuk's source code and the ESXi encrypters used by Conti and REvil, indicating some connection between them.

90% of small business leaders underestimate cyber incident costs

15 May 2023
A new report reveals that 91% of SMEs with a cyber insurance policy say that their insurance provider helped them avoid potential incidents.

Newly identified RA Group compromises companies in U.S. and South Korea with leaked Babuk source code

15 May 2023
The group is swiftly expanding its operations. To date, it has compromised three organizations in the U.S. and one in South Korea across several business verticals, including manufacturing, wealth management, insurance providers, and pharmaceuticals.

Illinois Data Breach Exposes Private Information of Medicaid, SNAP, and TANF Recipients

15 May 2023
The Illinois Department of Healthcare and Family Services (HFS) and Department of Human Services (IDHS) have disclosed a data breach within the State of Illinois Application for Benefits Eligibility (ABE) system’s Manage My Case (MMC) portal.

New 'MichaelKors' Ransomware-as-a-Service Targeting Linux and VMware ESXi Systems

15 May 2023
The targeting of VMware ESXi hypervisors with ransomware to scale such campaigns is a technique known as hypervisor jackpotting. Over the years, the approach has been adopted by several ransomware groups, including Royal.

Insured companies more likely to be ransomware victims, sometimes more than once

15 May 2023
Although threat actors may not be directly correlating the insurance factor to find targets, a reason for this may be that as insurers require more from companies those able to pay for insurance are also likely to be able to afford bigger ransoms.

PharMerica Discloses Data Breach Impacting 5.8 Million Individuals

15 May 2023
PharMerica’s letter does not provide details on the type of cyberattack that it suffered, but it appears that the Money Message ransomware group is responsible for the incident the group started leaking PII and PHI allegedly stolen from PharMerica.

Update: Capita warns customers they should assume data was stolen

15 May 2023
Almost six weeks after the attack was disclosed, Capita warned Universities Superannuation Scheme (USS), the largest private pension scheme in the UK, to react to the incident under the assumption that their members' data was stolen.

CLR SqlShell Malware Targets MS SQL Servers for Cryptomining and Ransomware

15 May 2023
Poorly managed Microsoft SQL (MS SQL) servers are the target of a new campaign that's designed to propagate a category of malware called CLR SqlShell that ultimately facilitates the deployment of cryptocurrency miners and ransomware.

Financial sector has highest password reuse rate

15 May 2023
Employee exposure was measured in a report that observed a 62% password reuse rate among Fortune 1000 employees who have been exposed more than once. 

Russia-Affiliated CheckMate Ransomware Quietly Targets Popular File-Sharing Protocol

15 May 2023
After gaining access to SMB shares, threat actors behind CheckMate ransomware encrypt all files and leave a ransom note demanding payment in exchange for the decryption key.

CISA Warns of Several Old Linux Vulnerabilities Exploited in Attacks

15 May 2023
One aspect all the vulnerabilities appear to have in common is their connection to Linux, which indicates that they might have been leveraged in attacks on Linux systems.