Latest Cybersecurity News and Articles


Twitter Finally Rolling Out Encrypted Direct Messages — Starting with Verified Users

11 May 2023
Twitter is officially beginning to roll out support for encrypted direct messages (DMs) on the platform, more than six months after its chief executive Elon Musk confirmed plans for the feature in November 2022. The "Phase 1" of the initiative will appear as separate conversations alongside existing direct messages on users' inboxes. Encrypted chats carry a lock icon badge to visually

GitHub Extends Push Protection to Prevent Accidental Leaks of Keys and Other Secrets

11 May 2023
GitHub has announced the general availability of a new security feature called push protection, which aims to prevent developers from inadvertently leaking keys and other secrets in their code. The Microsoft-owned cloud-based repository hosting platform, which began testing the feature a year ago, said it's also extending push protection to all public repositories at no extra cost. The

Experts challenge myths around reporting cyber attacks to help break cycle of crime

10 May 2023
Blog post from the NCSC and ICO aims to dispel common misconceptions that can discourage organisations from reporting a cyber attack.

Researchers Find Bypass for a Fixed Bug; MSFT Patches Again

10 May 2023
Microsoft patched the modified attack - tracked as CVE-2023-29324 - during this month's dump of fixes, rating the bug as "important" but not "critical." Researchers from Akamai, which found and disclosed the bug, say it merits a critical rating.

Google Announces New Privacy, Safety, and Security Features Across Its Services

10 May 2023
Google unveiled a slew of new privacy, safety, and security features today at its annual developer conference, Google I/O. The tech giant's latest initiatives are aimed at protecting its users from cyber threats, including phishing attacks and malicious websites, while providing more control and transparency over their personal data. Here is a short list of the newly introduced features -

Mastermind Behind Twitter 2020 Hack Pleads Guilty and Faces up to 70 Years in Prison

10 May 2023
Joseph James O'Connor, who also went by the online alias PlugwalkJoe, admitted to "his role in cyberstalking and multiple schemes that involve computer hacking, including the July 2020 hack of Twitter," the U.S. Department of Justice (DoJ) said.

77% of organizations plan to migrate to updated frameworks

10 May 2023
A report looks at the changes compliance, detailing how security leaders address compliance investments, framework updates, tooling and automation.

Siemens, Schneider Electric Address Few Dozen ICS Vulnerabilities

10 May 2023
Siemens has published six new advisories describing 26 vulnerabilities in Siveillance Video products, Cloud Connect 7, and more. Schneider Electric has published four new advisories that describe half a dozen vulnerabilities.

Smashing Pumpkins frontman paid ransom to a hacker who threatened to leak the band’s songs

10 May 2023
The frontman of the alternative rock band Smashing Pumpkins, Billy Corgan, revealed that he paid a ransom after a hacker stole the band’s songs and threatened to leak them.

Adobe Patches 14 Vulnerabilities in Substance 3D Painter

10 May 2023
Adobe has announced security updates for its Substance 3D Painter product to address more than a dozen vulnerabilities. This is the only product for which the software giant released updates this Patch Tuesday.

Australia's TechnologyOne halts trading after being hit by cyberattack

10 May 2023
Australia's TechnologyOne Ltd said on Wednesday it had detected an unauthorised third-party access to its back-office systems, becoming the latest target in a series of cyberattacks that has bogged companies in the country since last year.

Intel, AMD Address Over 100 Vulnerabilities on Patch Tuesday

10 May 2023
Intel has released 38 advisories covering over 80 vulnerabilities. The company has addressed nearly two dozen issues rated ‘high severity’ — the remaining bugs have been rated ‘medium severity’ and one is ‘low severity’.

Fake Windows System Update Drops Aurora Stealer via Invalid Printer Loader

10 May 2023
Attackers are using malicious ads to redirect users to what looks like a Windows security update. The scheme is very well designed as it relies on the web browser to display a full-screen animation resembling what you'd expect from Microsoft.

Spanish Police Arrest 40 in Phishing Gang Bust

10 May 2023
Spanish police have arrested dozens of individuals on suspicion of their involvement in a serious organized crime gang said to have made over €700,000 ($767,000) from phishing victims.

More Than 45,000 Affected by December Cyberattack on Metropolitan Opera

10 May 2023
The organization notified that the names, financial account information, tax identification numbers, Social Security numbers, payment card information, and driver’s license numbers of 45,094 people were leaked during the cyberattack.

Experts Detail New Zero-Click Windows Vulnerability for NTLM Credential Theft

10 May 2023
Cybersecurity researchers have shared details about a now-patched security flaw in Windows MSHTML platform that could be abused to bypass integrity protections on targeted machines. The vulnerability, tracked as CVE-2023-29324 (CVSS score: 6.5), has been described as a security feature bypass. It was addressed by Microsoft as part of its Patch Tuesday updates for May 2023. Akamai security

Update: Capita says responding to ransomware attack will cost up to $25 million

10 May 2023
The expenses have been attributed to “specialist professional fees, recovery and remediation costs and investment to reinforce Capita’s cyber security environment,” according to a statement sent to The Record.

Sophisticated DownEx Malware Campaign Targeting Central Asian Governments

10 May 2023
Government organizations in Central Asia are the target of a sophisticated espionage campaign that leverages a previously undocumented strain of malware dubbed DownEx. Bitdefender, in a report shared with The Hacker News, said the activity remains active, with evidence likely pointing to the involvement of Russia-based threat actors. The Romanian cybersecurity firm said it first detected the

SAP Patches Critical Vulnerabilities With May 2023 Security Updates

10 May 2023
German enterprise software maker SAP this week announced the release of 18 new security notes on its May 2023 Security Patch Day, including two ‘hot news’ notes that deal with critical vulnerabilities.

Food Distribution Giant Sysco Warns of Data Breach After Cyberattack

10 May 2023
In an internal memo sent to employees on May 3rd and seen by BleepingComputer, Sysco revealed that customer and supplier data in the U.S. and Canada, as well as personal information belonging to U.S. employees, may have been impacted in the incident.