Latest Cybersecurity News and Articles


CISA warns of critical Ruckus bug used to infect Wi-Fi access points

13 May 2023
While this security bug (CVE-2023-25717) was addressed in early February, many owners are likely yet to patch their Wi-Fi access points. Furthermore, no patch is available for those who own end-of-life models affected by this issue.

WordPress Plugin Vulnerability Exposed Ferrari Website to Hackers

13 May 2023
Security researchers noticed that the ‘media.ferrari.com’ domain is powered by WordPress and it was running a very old version of W3 Total Cache, a plugin installed on more than a million websites.

Discord discloses data breach after support agent got hacked

13 May 2023
The security breach exposed a third-party support agent's ticket queue, which contained user email addresses, messages exchanged with Discord support, and any attachments sent as part of the tickets.

XWorm Malware Exploits Follina Vulnerability in New Wave of Attacks

13 May 2023
Securonix, which is tracking the activity cluster under the name MEME#4CHAN, said some of the attacks have primarily targeted manufacturing firms and healthcare clinics located in Germany.

New Phishing-as-a-Service Platform Lets Cybercriminals Generate Convincing Phishing Pages

13 May 2023
A new phishing-as-a-service (PhaaS or PaaS) platform named Greatness has been leveraged by cybercriminals to target business users of the Microsoft 365 cloud service since at least mid-2022, effectively lowering the bar to entry for phishing attacks. "Greatness, for now, is only focused on Microsoft 365 phishing pages, providing its affiliates with an attachment and link builder that creates

Data of 237,000 US government employees breached

13 May 2023
The personal information of 237,000 current and former federal government employees has been exposed in a data breach at the U.S. Transportation Department (USDOT), sources briefed on the matter said on Friday.

Car location data of 2 million Toyota customers exposed for ten years

13 May 2023
Toyota Motor Corporation disclosed a data breach on its cloud environment that exposed the car-location information of 2,150,000 customers for ten years, between November 6, 2013, and April 17, 2023.

XWorm Malware Exploits Follina Vulnerability in New Wave of Attacks

12 May 2023
Cybersecurity researchers have discovered an ongoing phishing campaign that makes use of a unique attack chain to deliver the XWorm malware on targeted systems. Securonix, which is tracking the activity cluster under the name MEME#4CHAN, said some of the attacks have primarily targeted manufacturing firms and healthcare clinics located in Germany. "The attack campaign has been leveraging rather

Andrew Rallis hired as Executive VP and Chief Risk Officer

12 May 2023
Andrew Rallis was hired as Executive VP & Chief Risk Officer for Lincoln Financial Group. Rallis has more than 40 years of risk management experience.

Amtel, LLC dba Connectivity Source Notifies 17,835 Current and Former Employees of Recent Data Breach

12 May 2023
On May 10, the firm filed a notice of data breach with the Maine Attorney General after learning that an unauthorized party had gained access to the company’s IT network and accessed sensitive information belonging to current and former employees.

Organizations Informed of Over a Dozen Vulnerabilities in Rockwell Automation Products

12 May 2023
Rockwell Automation published six new security advisories this week and four of them have also been distributed by the US Cybersecurity and Infrastructure Security Agency (CISA). The advisories describe a total of more than a dozen vulnerabilities.

Tennessee, Georgia colleges respond to cyberattacks as school year wraps up

12 May 2023
Tennessee’s Chattanooga State Community College has been responding to a cyberattack since Saturday, forcing the school to cancel classes on Monday and modify schedules for staff members. The school serves more than 11,000 students.

Rural hospital cybersecurity legislation introduced to Senate

12 May 2023
New legislation addresses the need for skilled cybersecurity professionals and digital security enhancement protocols in rural healthcare settings.

Israeli Threat Group Uses Fake Company Acquisitions in CEO Fraud Schemes

12 May 2023
A group of cybercriminals based in Israel has launched more than 350 business email compromise (BEC) campaigns over the past two years, targeting large multinational companies from around the world.

Millions of mobile phones come pre-infected with malware

12 May 2023
The malware turns the devices into proxies which are used to steal and sell SMS messages, take over social media and online messaging accounts, and used as monetization opportunities via adverts and click fraud.

Multinational Technology Firm ABB Hit by Black Basta Ransomware Attack

12 May 2023
BleepingComputer has learned from multiple employees that the ransomware attack has affected its Active Directory, affecting hundreds of devices. Consequently, ABB terminated VPN connections with its customers to prevent the spread of the ransomware.

Stealthier version of Linux BPFDoor malware spotted in the wild

12 May 2023
By incorporating the encryption within a static library, the malware developers achieve better stealth and obfuscation, as the reliance on external libraries like one featuring the RC4 cipher algorithm is removed.

Brightly Software Warns of SchoolDude Data Breach Exposing Credentials

12 May 2023
The company believes the threat actors have stolen customer account information, including names, email addresses, account passwords, phone numbers (where available), and school district names.

Netgear Routers' Flaws Expose Users to Malware, Remote Attacks, and Surveillance

12 May 2023
As many as five security flaws have been disclosed in Netgear RAX30 routers that could be chained to bypass authentication and achieve remote code execution. "Successful exploits could allow attackers to monitor users' internet activity, hijack internet connections, and redirect traffic to malicious websites or inject malware into network traffic," Claroty security researcher Uri Katz said in a

Manual processes dominate TPRM as security incidents increase

12 May 2023
A new study shows 48% of companies still depend on spreadsheets, while 41% report experiencing an impactful third-party breach in the last year.