Latest Cybersecurity News and Articles
12 May 2023
By incorporating the encryption within a static library, the malware developers achieve better stealth and obfuscation, as the reliance on external libraries like one featuring the RC4 cipher algorithm is removed.
12 May 2023
The company believes the threat actors have stolen customer account information, including names, email addresses, account passwords, phone numbers (where available), and school district names.
12 May 2023
As many as five security flaws have been disclosed in Netgear RAX30 routers that could be chained to bypass authentication and achieve remote code execution.
"Successful exploits could allow attackers to monitor users' internet activity, hijack internet connections, and redirect traffic to malicious websites or inject malware into network traffic," Claroty security researcher Uri Katz said in a
12 May 2023
A new study shows 48% of companies still depend on spreadsheets, while 41% report experiencing an impactful third-party breach in the last year.
12 May 2023
A previously undocumented and mostly undetected variant of a Linux backdoor called BPFDoor has been spotted in the wild, cybersecurity firm Deep Instinct said in a technical report published this week.
"BPFDoor retains its reputation as an extremely stealthy and difficult-to-detect malware with this latest iteration," security researchers Shaul Vilkomir-Preisman and Eliran Nissan said.
BPFDoor (
12 May 2023
The attacks took place in early May 2023, the Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) said in a joint cybersecurity advisory issued Thursday.
12 May 2023
The exploitation of a critical vulnerability in the Essential Addons for Elementor WordPress plugin began immediately after a patch was released, WordPress security firm Defiant warns.
12 May 2023
Recently, researchers have observed malicious advertisement campaigns in Google’s search engine with themes that are related to AI tools. For example, malicious ads are served when a user searches for the keyword "midjourney" in Google.
12 May 2023
In today's interconnected world, where organisations regularly exchange sensitive information with customers, partners and employees, secure collaboration has become increasingly vital. However, collaboration can pose a security risk if not managed properly. To ensure that collaboration remains secure, organisations need to take steps to protect their data.
Since collaborating is essential for
12 May 2023
The vulnerability, tracked as CVE-2023-27532, exposes encrypted credentials stored in Veeam Backup & Replication. It could lead to unauthorized access to backup infrastructure hosts, says the HHS' HC3 in an alert.
12 May 2023
In 76% of the ransomware attacks targeting surveyed organizations, the adversaries successfully encrypted the data. Those who paid a ransom for a decryption key ended up doubling their recovery costs. The highest payment rate was observed among organizations with revenue over $5 billion.
12 May 2023
Senators are pushing to improve the cybersecurity of the national 988 Suicide & Crisis Lifeline and election infrastructure, after passing a bill to upgrade the resiliency of the aviation sector’s notification system for flight hazards.
12 May 2023
A cyberattack campaign was observed against foreign government institutions in Kazakhstan and Afghanistan using decoy documents that impersonate real diplomats. Attackers used a new malware family dubbed DownEx by Bitdefender Labs. It can move laterally to traverse local and network drives to extract a wide range of files from various formats, including Word, Excel, and PowerPoint documents, videos, images, PDFs, and compressed files.
12 May 2023
In recent GULoader campaigns, researchers witnessed a rise in NSIS-based installers delivered via email as malspam that use plugin libraries to execute the GU shellcode on the victim system.
12 May 2023
The tech giant's latest initiatives are aimed at protecting its users from cyber threats, including phishing attacks and malicious websites, while providing more control and transparency over their personal data.
12 May 2023
CERT-UA has issued a cautionary statement regarding an ongoing phishing operation that employs invoice-related tactics to spread the SmokeLoader malware. The attached ZIP archive is a polyglot file, meaning it is a single file that can be interpreted as multiple file formats.
12 May 2023
By the end of March 2023, Sucuri researchers started noticing a new wave of SocGholish injections that used the intermediary xjquery[.]com domain. It appeared to be another evolution of the same malware.
12 May 2023
Founded in 2020 and hosted by the Linux Foundation, OpenSSF is a cross-industry organization focused on improving the security of the open-source software supply chain through collaboration between tech companies.
12 May 2023
Industrial and IoT cybersecurity firm Claroty on Thursday disclosed the details of five vulnerabilities that can be chained in an exploit potentially allowing threat actors to hack certain Netgear routers.
12 May 2023
U.S. cybersecurity and intelligence agencies have warned of attacks carried out by a threat actor known as the Bl00dy Ransomware Gang that attempt to exploit vulnerable PaperCut servers against the education facilities sector in the country.
The attacks took place in early May 2023, the Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) said in a