Latest Cybersecurity News and Articles
11 May 2023
Malicious actors are increasingly exploiting legitimate tools to accomplish their goals, which include disabling security measures, lateral movement, and transferring files. Using commonly available tools allows attackers to evade detection.
11 May 2023
Wired and wireless networking equipment maker Ruckus was targeted by a DDoS botnet threat named AndoryuBot that has been exploiting a recently patched bug in Ruckus access points (APs). Upon infection, the botnet rapidly propagates and initiates communication with its command-and-control (C2) server using the SOCKS protocol.
11 May 2023
The new funding, the company says, will enable it to expand its employee base and accelerate the development of privacy solutions, such as a cross-chain messaging system.
11 May 2023
To use Greatness, affiliates must deploy and configure a provided phishing kit with an API key that allows even unskilled threat actors to easily take advantage of the service’s more advanced features.
11 May 2023
MalwareHunterTeam took the wraps off of the Akira ransomware group that has been penetrating corporate networks globally and subsequently asking for up to millions of dollars in ransom payments. For those not willing to pay for decryptors, criminals suggest reducing the ransom amount just to avoid data leaks. The malware first surfaced in March.
11 May 2023
Threat actors encrypted data in three in four ransomware attacks last year, the highest rate of data encryption linked to ransomware in at least four years, according to research Sophos released Wednesday.
11 May 2023
A possibly Russian state hacking group has been deploying a novel backdoor against international governmental targets located in Kazakhstan and Afghanistan, reports Bitdefender.
11 May 2023
DEF CON’s AI Village will host the first public assessment of large language models (LLMs) at the 31st edition of the hacker convention this August, aimed at finding bugs in and uncovering the potential for misuse of AI models.
11 May 2023
A variety of different threats come in on a daily basis, but the U.S. needs to be able to build a system that can withstand malicious activity regardless of where the threat is coming from, according to Acting National Cyber Director Kemba Walden.
11 May 2023
According to Forrester, External Attack Surface Management (EASM) emerged as a market category in 2021 and gained popularity in 2022. In a different report, Gartner concluded that vulnerability management vendors are expanding their offerings to include Attack Surface Management (ASM) for a suite of comprehensive offensive security solutions.
Recognition from global analysts has officially put
11 May 2023
Multiple threat actors have capitalized on the leak of Babuk (aka Babak or Babyk) ransomware code in September 2021 to build as many as nine different ransomware families capable of targeting VMware ESXi systems.
"These variants emerged through H2 2022 and H1 2023, which shows an increasing trend of Babuk source code adoption," SentinelOne security researcher Alex Delamotte said in a report
11 May 2023
Push protection stops the leaking of secrets by scanning a code commit before it gets pushed. Developers get alerted directly in their integrated development environment (IDE) or command line interface (CLI).
11 May 2023
The industrial cybersecurity vendor said a known ransomware group breached its defenses and accessed threat intel reports, a SharePoint portal, and a customer support system but ultimately failed in an elaborate extortion scheme.
11 May 2023
Asked about the Board and C-Suite‘s understanding of cybersecurity across the organization, only 39% of respondents think their company’s leadership has a sound understanding of cybersecurity’s role as a business enabler, according to Delinea.
11 May 2023
A couple of Iranian state-sponsored groups were observed targeting a recently patched flaw in PaperCut MF/NG print management solutions. According to Microsoft, Mint Sandstorm and Mango Sandstorm modified their arsenal in accordance with publicly available PoC exploit codes. It is recommended defenders upgrade their PaperCut MF and PaperCut NG software to versions 20.1.7, 21.2.11, and 22.0.9 or newer, asap.
11 May 2023
The National Gallery of Canada first discovered the attack on April 23 and attempted to isolate the affected networks while hiring a cybersecurity company to conduct a forensic investigation.
11 May 2023
Another ransomware operation has been unveiled called Cactus. Operating since at least March 2023, its unique feature is to encrypt itself to stay under the radar. The malware strain exploits known vulnerabilities in Fortinet VPN appliances. Organizations are urged to adopt a proactive defense strategy that includes applying the latest software updates.
11 May 2023
According to CyberArk, which developed and published the 'White Phoenix' encryptor, this tactic introduces weaknesses to the encryption, as leaving parts of the original files unencrypted creates the potential for free data recovery.
11 May 2023
A nascent botnet called Andoryu has been found to exploit a now-patched critical security flaw in the Ruckus Wireless Admin panel to break into vulnerable devices.
The flaw, tracked as CVE-2023-25717 (CVSS score: 9.8), stems from improper handling of HTTP requests, leading to unauthenticated remote code execution and a complete compromise of wireless Access Point (AP) equipment.
Andoryu was
11 May 2023
Researchers have identified a fraudulent website designed to deceive users by posing as the popular Russian platform CryptoPro CSP. Attackers drop DarkWatchman RAT during the attack to steal data. This innovative tactic places it in the category of fileless malware and indicates that the operators are highly sophisticated.